- INFORMATION
-
gcloud alpha network-security server-tls-policies updateis not available in universe domainuniverse. - NAME
-
- gcloud alpha network-security server-tls-policies update - update a ServerTlsPolicy
- SYNOPSIS
-
-
gcloud alpha network-security server-tls-policies update(SERVER_TLS_POLICY:--location=LOCATION) [--async] [--description=DESCRIPTION] [--update-labels=[KEY=VALUE,…]] [--clear-labels|--remove-labels=[KEY,…]] [--client-validation-mode=CLIENT_VALIDATION_MODE--clear-client-validation-relaxations|--client-validation-relaxations=[CLIENT_VALIDATION_RELAXATIONS,…] |--[no-]allow-open--client-validation-ca-grpc-endpoint=[TARGET_URI,…] |--client-validation-ca-plugin-instance=[PLUGIN_INSTANCE,…]--server-certificate-grpc-endpoint=SERVER_CERTIFICATE_GRPC_ENDPOINT|--server-certificate-plugin-instance=SERVER_CERTIFICATE_PLUGIN_INSTANCE] [GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
-
(ALPHA)Update the details of a ServerTlsPolicy. - EXAMPLES
-
To update the client validation mode of a ServerTlsPolicy named
my-tls-policytoreject-invalid, run:gcloud alpha network-security server-tls-policies update my-tls-policy --location=global --client-validation-mode=reject-invalidTo update the client validation mode and relaxations of a ServerTlsPolicy named
my-tls-policy, run:gcloud alpha network-security server-tls-policies update my-tls-policy --location=global --client-validation-mode=allow-validation-relaxations --client-validation-relaxations=allow-missing-eku,allow-expired-leaf-certificateTo clear all client validation relaxations on a ServerTlsPolicy named
my-tls-policy, run:gcloud alpha network-security server-tls-policies update my-tls-policy --location=global --clear-client-validation-relaxations - POSITIONAL ARGUMENTS
-
-
Server TLS policy resource - Name of the ServerTlsPolicy to be updated. The
arguments in this group can be used to specify the attributes of this resource.
(NOTE) Some attributes are not given arguments in this group but can be set in
other ways.
To set the
projectattribute:-
provide the argument
server_tls_policyon the command line with a fully specified name; -
provide the argument
--projecton the command line; -
set the property
core/project.
This must be specified.
SERVER_TLS_POLICY-
ID of the server TLS policy or fully qualified identifier for the server TLS
policy.
To set the
server_tls_policyattribute:-
provide the argument
server_tls_policyon the command line.
This positional argument must be specified if any of the other arguments in this group are specified.
-
provide the argument
--location=LOCATION-
The location Id.
To set the
locationattribute:-
provide the argument
server_tls_policyon the command line with a fully specified name; -
provide the argument
--locationon the command line.
-
provide the argument
-
provide the argument
-
Server TLS policy resource - Name of the ServerTlsPolicy to be updated. The
arguments in this group can be used to specify the attributes of this resource.
(NOTE) Some attributes are not given arguments in this group but can be set in
other ways.
- FLAGS
-
--async- Return immediately, without waiting for the operation in progress to complete.
--description=DESCRIPTION- Free-text description of the resource.
--update-labels=[KEY=VALUE,…]-
List of label KEY=VALUE pairs to update. If a label exists, its value is
modified. Otherwise, a new label is created.
Keys must start with a lowercase character and contain only hyphens (
-), underscores (_), lowercase characters, and numbers. Values must contain only hyphens (-), underscores (_), lowercase characters, and numbers. -
At most one of these can be specified:
--clear-labels-
Remove all labels. If
--update-labelsis also specified then--clear-labelsis applied first.For example, to remove all labels:
gcloud alpha network-security server-tls-policies update --clear-labelsTo remove all existing labels and create two new labels,
andfoo:bazgcloud alpha network-security server-tls-policies update --clear-labels --update-labels foo=bar,baz=qux --remove-labels=[KEY,…]-
List of label keys to remove. If a label does not exist it is silently ignored.
If
--update-labelsis also specified then--update-labelsis applied first.
-
Configuration for a ServerTlsPolicy configured for frontend mTLS on Application
Load Balancers or a ServerTlsPolicy configured for Traffic Director.
At most one of these can be specified:
- Options for a ServerTlsPolicy configured for frontend mTLS on Application Load Balancers.
--client-validation-mode=CLIENT_VALIDATION_MODE-
Determines how the server handles connections when the client presents an
invalid certificate or no certificate at all.
CLIENT_VALIDATION_MODEmust be one of:allow-invalid-or-missing-client-cert- Allow connection to the backend even if client certificate is missing or failed validation.
allow-validation-relaxations- Require a client certificate that chains to the TrustConfig, while allowing configured validation relaxations.
reject-invalid- Require a valid client certificate that chains to the TrustConfig and passes all validation checks.
-
Modify or clear X.509 client certificate validation relaxations.
At most one of these can be specified:
--clear-client-validation-relaxations- Clear all configured client validation relaxations.
--client-validation-relaxations=[CLIENT_VALIDATION_RELAXATIONS,…]-
List of X.509 certificate validation relaxations to apply when
--client-validation-mode=allow-validation-relaxations.
- Options for a ServerTlsPolicy configured for Traffic Director.
--[no-]allow-open-
Determines if server allows plaintext connections. If set to true, server allows
plain text connections. Default is false. Use
--allow-opento enable and--no-allow-opento disable. -
Client validation CA configuration for a ServerTlsPolicy configured for Traffic
Director.
At most one of these can be specified:
--client-validation-ca-grpc-endpoint=[TARGET_URI,…]- List of gRPC endpoint target URIs used to obtain the Certificate Authority certificates to validate peer certificates for a ServerTlsPolicy configured for Traffic Director.
--client-validation-ca-plugin-instance=[PLUGIN_INSTANCE,…]- List of certificate provider plugin instance names used to obtain the Certificate Authority certificates to validate peer certificates for a ServerTlsPolicy configured for Traffic Director.
-
Server certificate configuration for a ServerTlsPolicy configured for Traffic
Director.
At most one of these can be specified:
--server-certificate-grpc-endpoint=SERVER_CERTIFICATE_GRPC_ENDPOINT-
Target URI of the gRPC endpoint that provides the server certificate and private
key (must start with
unix:). --server-certificate-plugin-instance=SERVER_CERTIFICATE_PLUGIN_INSTANCE- Plugin instance name, used to locate and load CertificateProvider instance configuration to obtain the server certificate and private key.
- GCLOUD WIDE FLAGS
-
These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$ gcloud helpfor details. - API REFERENCE
-
This command uses the
networksecurity/v1alpha1API. The full documentation for this API can be found at: https://cloud.google.com/networking - NOTES
-
This command is currently in alpha and might change without notice. If this
command fails with API permission errors despite specifying the correct project,
you might be trying to access an API with an invitation-only early access
allowlist. This variant is also available:
gcloud beta network-security server-tls-policies update
gcloud alpha network-security server-tls-policies update
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-10-06 UTC.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-10-06 UTC."],[],[]]