gcloud alpha network-security server-tls-policies update

INFORMATION
gcloud alpha network-security server-tls-policies update is not available in universe domain universe.
NAME
gcloud alpha network-security server-tls-policies update - update a ServerTlsPolicy
SYNOPSIS
gcloud alpha network-security server-tls-policies update (SERVER_TLS_POLICY : --location=LOCATION) [--async] [--description=DESCRIPTION] [--update-labels=[KEY=VALUE,…]] [--clear-labels     | --remove-labels=[KEY,…]] [--client-validation-mode=CLIENT_VALIDATION_MODE --clear-client-validation-relaxations     | --client-validation-relaxations=[CLIENT_VALIDATION_RELAXATIONS,…]     | --[no-]allow-open --client-validation-ca-grpc-endpoint=[TARGET_URI,…]     | --client-validation-ca-plugin-instance=[PLUGIN_INSTANCE,…] --server-certificate-grpc-endpoint=SERVER_CERTIFICATE_GRPC_ENDPOINT     | --server-certificate-plugin-instance=SERVER_CERTIFICATE_PLUGIN_INSTANCE] [GCLOUD_WIDE_FLAG …]
DESCRIPTION
(ALPHA) Update the details of a ServerTlsPolicy.
EXAMPLES
To update the client validation mode of a ServerTlsPolicy named my-tls-policy to reject-invalid, run:
gcloud alpha network-security server-tls-policies update my-tls-policy --location=global --client-validation-mode=reject-invalid

To update the client validation mode and relaxations of a ServerTlsPolicy named my-tls-policy, run:

gcloud alpha network-security server-tls-policies update my-tls-policy --location=global --client-validation-mode=allow-validation-relaxations --client-validation-relaxations=allow-missing-eku,allow-expired-leaf-certificate

To clear all client validation relaxations on a ServerTlsPolicy named my-tls-policy, run:

gcloud alpha network-security server-tls-policies update my-tls-policy --location=global --clear-client-validation-relaxations
POSITIONAL ARGUMENTS
Server TLS policy resource - Name of the ServerTlsPolicy to be updated. The arguments in this group can be used to specify the attributes of this resource. (NOTE) Some attributes are not given arguments in this group but can be set in other ways.

To set the project attribute:

  • provide the argument server_tls_policy on the command line with a fully specified name;
  • provide the argument --project on the command line;
  • set the property core/project.

This must be specified.

SERVER_TLS_POLICY
ID of the server TLS policy or fully qualified identifier for the server TLS policy.

To set the server_tls_policy attribute:

  • provide the argument server_tls_policy on the command line.

This positional argument must be specified if any of the other arguments in this group are specified.

--location=LOCATION
The location Id. To set the location attribute:
  • provide the argument server_tls_policy on the command line with a fully specified name;
  • provide the argument --location on the command line.
FLAGS
--async
Return immediately, without waiting for the operation in progress to complete.
--description=DESCRIPTION
Free-text description of the resource.
--update-labels=[KEY=VALUE,…]
List of label KEY=VALUE pairs to update. If a label exists, its value is modified. Otherwise, a new label is created.

Keys must start with a lowercase character and contain only hyphens (-), underscores (_), lowercase characters, and numbers. Values must contain only hyphens (-), underscores (_), lowercase characters, and numbers.

At most one of these can be specified:
--clear-labels
Remove all labels. If --update-labels is also specified then --clear-labels is applied first.

For example, to remove all labels:

gcloud alpha network-security server-tls-policies update --clear-labels

To remove all existing labels and create two new labels, foo and baz:

gcloud alpha network-security server-tls-policies update --clear-labels --update-labels foo=bar,baz=qux
--remove-labels=[KEY,…]
List of label keys to remove. If a label does not exist it is silently ignored. If --update-labels is also specified then --update-labels is applied first.
Configuration for a ServerTlsPolicy configured for frontend mTLS on Application Load Balancers or a ServerTlsPolicy configured for Traffic Director. At most one of these can be specified:
Options for a ServerTlsPolicy configured for frontend mTLS on Application Load Balancers.
--client-validation-mode=CLIENT_VALIDATION_MODE
Determines how the server handles connections when the client presents an invalid certificate or no certificate at all. CLIENT_VALIDATION_MODE must be one of:
allow-invalid-or-missing-client-cert
Allow connection to the backend even if client certificate is missing or failed validation.
allow-validation-relaxations
Require a client certificate that chains to the TrustConfig, while allowing configured validation relaxations.
reject-invalid
Require a valid client certificate that chains to the TrustConfig and passes all validation checks.
Modify or clear X.509 client certificate validation relaxations. At most one of these can be specified:
--clear-client-validation-relaxations
Clear all configured client validation relaxations.
--client-validation-relaxations=[CLIENT_VALIDATION_RELAXATIONS,…]
List of X.509 certificate validation relaxations to apply when --client-validation-mode=allow-validation-relaxations.
Options for a ServerTlsPolicy configured for Traffic Director.
--[no-]allow-open
Determines if server allows plaintext connections. If set to true, server allows plain text connections. Default is false. Use --allow-open to enable and --no-allow-open to disable.
Client validation CA configuration for a ServerTlsPolicy configured for Traffic Director. At most one of these can be specified:
--client-validation-ca-grpc-endpoint=[TARGET_URI,…]
List of gRPC endpoint target URIs used to obtain the Certificate Authority certificates to validate peer certificates for a ServerTlsPolicy configured for Traffic Director.
--client-validation-ca-plugin-instance=[PLUGIN_INSTANCE,…]
List of certificate provider plugin instance names used to obtain the Certificate Authority certificates to validate peer certificates for a ServerTlsPolicy configured for Traffic Director.
Server certificate configuration for a ServerTlsPolicy configured for Traffic Director. At most one of these can be specified:
--server-certificate-grpc-endpoint=SERVER_CERTIFICATE_GRPC_ENDPOINT
Target URI of the gRPC endpoint that provides the server certificate and private key (must start with unix:).
--server-certificate-plugin-instance=SERVER_CERTIFICATE_PLUGIN_INSTANCE
Plugin instance name, used to locate and load CertificateProvider instance configuration to obtain the server certificate and private key.
GCLOUD WIDE FLAGS
These flags are available to all commands: --access-token-file, --account, --billing-project, --configuration, --flags-file, --flatten, --format, --help, --impersonate-service-account, --log-http, --project, --quiet, --trace-token, --user-output-enabled, --verbosity.

Run $ gcloud help for details.

API REFERENCE
This command uses the networksecurity/v1alpha1 API. The full documentation for this API can be found at: https://cloud.google.com/networking
NOTES
This command is currently in alpha and might change without notice. If this command fails with API permission errors despite specifying the correct project, you might be trying to access an API with an invitation-only early access allowlist. This variant is also available:
gcloud beta network-security server-tls-policies update