- INFORMATION
-
gcloud alpha network-security server-tls-policies createis not available in universe domainuniverse. - NAME
-
- gcloud alpha network-security server-tls-policies create - create a ServerTlsPolicy
- SYNOPSIS
-
-
gcloud alpha network-security server-tls-policies create(SERVER_TLS_POLICY:--location=LOCATION) ([--client-validation-mode=CLIENT_VALIDATION_MODE:--client-validation-relaxations=[CLIENT_VALIDATION_RELAXATIONS,…]--client-validation-trust-config=CLIENT_VALIDATION_TRUST_CONFIG] |--allow-open--client-validation-ca-grpc-endpoint=[TARGET_URI,…] |--client-validation-ca-plugin-instance=[PLUGIN_INSTANCE,…]--server-certificate-grpc-endpoint=SERVER_CERTIFICATE_GRPC_ENDPOINT|--server-certificate-plugin-instance=SERVER_CERTIFICATE_PLUGIN_INSTANCE) [--async] [--description=DESCRIPTION] [--labels=[KEY=VALUE,…]] [GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
-
(ALPHA)Create a new ServerTlsPolicy. - EXAMPLES
-
To create a ServerTlsPolicy configured for frontend mTLS on Application Load
Balancers, run:
gcloud alpha network-security server-tls-policies create my-server-tls-policy --location=global --client-validation-mode=reject-invalid --client-validation-trust-config=projects/my-project/locations/global/trustConfigs/my-trust-configTo create a ServerTlsPolicy configured for frontend mTLS on Application Load Balancers with validation relaxations, run:
gcloud alpha network-security server-tls-policies create my-server-tls-policy --location=global --client-validation-mode=allow-validation-relaxations --client-validation-trust-config=projects/my-project/locations/global/trustConfigs/my-trust-config --client-validation-relaxations=allow-missing-eku,allow-expired-leaf-certificateTo create a ServerTlsPolicy configured for Traffic Director, run:
gcloud alpha network-security server-tls-policies create my-td-policy --location=global --allow-open --client-validation-ca-plugin-instance=google_cloud_private_spiffe - POSITIONAL ARGUMENTS
-
-
Server TLS policy resource - Name of the ServerTlsPolicy to create. The
arguments in this group can be used to specify the attributes of this resource.
(NOTE) Some attributes are not given arguments in this group but can be set in
other ways.
To set the
projectattribute:-
provide the argument
server_tls_policyon the command line with a fully specified name; -
provide the argument
--projecton the command line; -
set the property
core/project.
This must be specified.
SERVER_TLS_POLICY-
ID of the server TLS policy or fully qualified identifier for the server TLS
policy.
To set the
server_tls_policyattribute:-
provide the argument
server_tls_policyon the command line.
This positional argument must be specified if any of the other arguments in this group are specified.
-
provide the argument
--location=LOCATION-
The location Id.
To set the
locationattribute:-
provide the argument
server_tls_policyon the command line with a fully specified name; -
provide the argument
--locationon the command line.
-
provide the argument
-
provide the argument
-
Server TLS policy resource - Name of the ServerTlsPolicy to create. The
arguments in this group can be used to specify the attributes of this resource.
(NOTE) Some attributes are not given arguments in this group but can be set in
other ways.
- REQUIRED FLAGS
-
-
Configuration for a ServerTlsPolicy configured for frontend mTLS on Application
Load Balancers or for Traffic Director.
Exactly one of these must be specified:
- ServerTlsPolicy configured for frontend mTLS on Application Load Balancers.
--client-validation-mode=CLIENT_VALIDATION_MODE-
Specifies how the client connection is handled when the client presents an
invalid certificate or no certificate to the load balancer.
CLIENT_VALIDATION_MODEmust be one of:allow-invalid-or-missing-client-cert- Allow connection even if certificate chain validation of the client certificate failed or no client certificate was presented.
allow-validation-relaxations-
Require a client certificate, but apply the specific validation relaxations
requested in
--client-validation-relaxations. reject-invalid- Require a client certificate and allow connection to the backend only if validation of the client certificate passed.
--client-validation-relaxations=[CLIENT_VALIDATION_RELAXATIONS,…]-
List of validation relaxations to apply when
--client-validation-modeis set toallow-validation-relaxations.CLIENT_VALIDATION_RELAXATIONSmust be one of:allow-expired-leaf-certificate-
Allows validation of an expired client leaf certificate. The certificate will be
validated as if the current time was one second before the end of its validity
period (the
notAftertimestamp). allow-missing-eku-
Allows the client certificate to completely omit the Extended Key Usage (EKU)
extension. If the EKU extension is present, it must permit the
clientAuthkey purpose (OID 1.3.6.1.5.5.7.3.2). allow-sha1-hashing- Allows validation of client certificate chains signed using legacy SHA-1 message digests.
--client-validation-trust-config=CLIENT_VALIDATION_TRUST_CONFIG-
Reference to the Certificate Manager TrustConfig resource
(
projects/*/locations/*/trustConfigs/*or TrustConfig ID in the same project and location) used to validate client certificates. - ServerTlsPolicy configured for Traffic Director.
--allow-open- Determines if the server allows plaintext connections when configured for Traffic Director.
-
Client validation CA configuration for Traffic Director.
At most one of these can be specified:
--client-validation-ca-grpc-endpoint=[TARGET_URI,…]- List of gRPC endpoint target URIs used to obtain the Certificate Authority certificates to validate peer certificates for Traffic Director.
--client-validation-ca-plugin-instance=[PLUGIN_INSTANCE,…]- List of certificate provider plugin instance names used to obtain the Certificate Authority certificates to validate peer certificates for Traffic Director.
-
Server certificate configuration for Traffic Director.
At most one of these can be specified:
--server-certificate-grpc-endpoint=SERVER_CERTIFICATE_GRPC_ENDPOINT-
Target URI of the gRPC endpoint that provides the server certificate and private
key (must start with
unix:). --server-certificate-plugin-instance=SERVER_CERTIFICATE_PLUGIN_INSTANCE- Plugin instance name that will be passed to the data plane to load server identity credentials.
-
Configuration for a ServerTlsPolicy configured for frontend mTLS on Application
Load Balancers or for Traffic Director.
Exactly one of these must be specified:
- OPTIONAL FLAGS
-
--async- Return immediately, without waiting for the operation in progress to complete.
--description=DESCRIPTION- Free-text description of the resource.
--labels=[KEY=VALUE,…]-
List of label KEY=VALUE pairs to add.
Keys must start with a lowercase character and contain only hyphens (
-), underscores (_), lowercase characters, and numbers. Values must contain only hyphens (-), underscores (_), lowercase characters, and numbers.
- GCLOUD WIDE FLAGS
-
These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$ gcloud helpfor details. - API REFERENCE
-
This command uses the
networksecurity/v1alpha1API. The full documentation for this API can be found at: https://cloud.google.com/networking - NOTES
-
This command is currently in alpha and might change without notice. If this
command fails with API permission errors despite specifying the correct project,
you might be trying to access an API with an invitation-only early access
allowlist. This variant is also available:
gcloud beta network-security server-tls-policies create
gcloud alpha network-security server-tls-policies create
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-10-06 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-10-06 UTC."],[],[]]