Skip to content
Proud to collaborate with Microsoft for Startups

gcp.compute.firewall_rule.ensure ​

Create a GCP firewall rule idempotently

Creates a GCP firewall rule if it does not exist. When an identically-named rule already exists, returns without modification (idempotent).

Inputs:

  • connection_uuid: Cloud connection UUID (required)
  • name: Firewall rule name (required)
  • network: VPC network name (required)
  • direction: "INGRESS" | "EGRESS" (default "EGRESS")
  • protocols: Protocols to allow (required). Accepts three shapes: (a) list of protocol names — ["tcp"] or ["tcp", "udp"]; (b) GCP-native "allowed" dicts — [{"IPProtocol": "tcp", "ports": ["8080"]}, {"IPProtocol": "udp"}]; (c) combined strings — ["tcp:8080", "udp:53"]. Ports carried in the dict/combined forms are unioned with the top-level ports input.
  • ports: List of port strings, e.g. ["443"] (optional)
  • source_ranges: List of CIDRs (optional — required for INGRESS)
  • destination_ranges: List of CIDRs (optional — required for EGRESS)
  • description: Free-text description (optional)
  • project_id: Explicit project_id (optional; defaults to connection)

Outputs:

  • name
  • project_id
  • existed: bool

Overview ​

PropertyValue
Workflow typeAtomic
LibraryBase-gcp
Version1.0

Input Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidYes——
namestringYes——
networkstringYes——
directionstringNo——
protocolsjsonYes—Protocols to allow. Accepts (a) protocol-name strings ["tcp", "udp"], (b) GCP-native allowed dicts [{"IPProtocol": "tcp", "ports": ["8080"]}], or (c) combined "tcp:8080" strings. Ports from the dict/combined forms are unioned with the top-level 'ports' input.
portsjsonNo——
source_rangesjsonNo——
destination_rangesjsonNo——
descriptionstringNo——
project_idstringNo——

Output Schema ​

FieldTypeRequiredDefaultDescription
connection_uuiduuidNo——
namestringNo——
networkstringNo——
directionstringNo——
protocolsjsonNo——
portsjsonNo——
source_rangesjsonNo——
destination_rangesjsonNo——
descriptionstringNo——
project_idstringNo——
existedbooleanNo——
failure_reasonstringNo——
failure_typestringNo——
failed_actionstringNo——
failed_at_statestringNo——
failed_stepstringNo——
failed_layerstringNo——
errorstringNo——
error_typestringNo——

States ​

StateInitialTerminalSuccessAuto-advanceDescription
pendingYesNo—execute—
completedNoYesYes——
failedNoYesNo——

State Diagram ​

Transitions ​

FromActionToDescription
pendingexecutecompleted—
* (any state)failfailed—

API Usage ​

bash
POST /api/workflows/start
Content-Type: application/json

{
  "workflow_type": "gcp.compute.firewall_rule.ensure",
  "initial_data": {
    "connection_uuid": "value",
    "name": "value",
    "network": "value",
    "protocols": "value"
  }
}