Scaleway logo
Instance API

A security group is a set of firewall rules on a set of Instances. Security groups enable you to create rules that either drop or allow incoming traffic from certain ports of your Instances.

Security groups are stateful by default, which means that return traffic is automatically allowed, regardless of any rules. You can switch to a stateless mode if you want to only allow explicitly defined traffic. That mode may be difficult to use when filtering outgoing flows.


Set all rules of a security group

PUT
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-group-rules

Replace all rules of a specified security group with the provided rules.

Set all rules of a security group › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2

Set all rules of a security group › Request Body

security_group_id
​string

ID of the security group to set rules for.

List of rules to set.

Set all rules of a security group › Responses

200
id
​string

Unique ID of the security group.

srn
​string

The SRN of the security group.

name
​string

Name of the security group.

description
​string

Description of the security group.

project_id
​string

Project ID the security group belongs to.

tags
​string[]

Tags associated with the security group.

disable_default_rules
​boolean

True if default rules are disabled.

project_default
​boolean

True if this is the default security group for the project.

inbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for inbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
outbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for outbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
stateless
​boolean

True if the security group is stateless.

created_at
​string | null · date-time

Creation timestamp of the security group. (RFC 3339 format)

updated_at
​string | null · date-time

Last update timestamp of the security group. (RFC 3339 format)

List of default rules applied to the security group.

List of custom rules applied to the security group.

zone
​string

Zone in which the security group is located.


Add rules to a security group

POST
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-group-rules

Add one or more rules to a security group.

Add rules to a security group › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2

Add rules to a security group › Request Body

security_group_id
​string

ID of the security group to add rules to.

List of rules to add.

Add rules to a security group › Responses

200

Delete rules from a security group

DELETE
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-group-rules

Delete specified security groups.

Delete rules from a security group › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2

Delete rules from a security group › Request Body

security_group_rule_ids
​string[]

List of rule IDs to delete.

Delete rules from a security group › Responses

No data returned

Update a security group rule

PATCH
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-group-rules/{security_group_rule_id}

Update the properties of a rule from a specified security group.

Update a security group rule › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2
security_group_rule_id
​string · required

ID of the rule to update.

Update a security group rule › Request Body

New protocol for the rule.

Enum values:
unknown_protocol
tcp
udp
icmp
any
Default: unknown_protocol

New direction for the rule.

Enum values:
unknown_direction
inbound
outbound
both
Default: unknown_direction

New action for the rule.

Enum values:
unknown_action
accept
drop
Default: unknown_action
source_ip_range
​string | null

New source IP range for the rule. (IP network)

destination_ip_range
​string | null

New destination IP range for the rule. (IP network)

New source port range for the rule.

New destination port range for the rule.

position
​integer | null · int32

New position for the rule.

Update a security group rule › Responses

200
id
​string

Unique ID of the security group.

srn
​string

The SRN of the security group.

name
​string

Name of the security group.

description
​string

Description of the security group.

project_id
​string

Project ID the security group belongs to.

tags
​string[]

Tags associated with the security group.

disable_default_rules
​boolean

True if default rules are disabled.

project_default
​boolean

True if this is the default security group for the project.

inbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for inbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
outbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for outbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
stateless
​boolean

True if the security group is stateless.

created_at
​string | null · date-time

Creation timestamp of the security group. (RFC 3339 format)

updated_at
​string | null · date-time

Last update timestamp of the security group. (RFC 3339 format)

List of default rules applied to the security group.

List of custom rules applied to the security group.

zone
​string

Zone in which the security group is located.


List security groups

GET
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-groups

List all security groups.

List security groups › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2

List security groups › query Parameters

project_id
​string · required

Filter by Project ID.

page_token
​string

Token for pagination.

page_size
​integer · uint32

Number of items to return per page.

Field and direction to sort by.

Enum values:
created_at_desc
created_at_asc
updated_at_desc
updated_at_asc
Default: created_at_desc
name
​string

Filter by name.

tags
​string[]

Filter by tags.

security_group_ids
​string[]

Filter by specific security group IDs.

List security groups › Responses

200

List of security groups.

next_page_token
​string | null

Token for the next page.

total_count
​integer · uint64

Total number of items.


Create a security group

POST
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-groups

Create a security group with a specified name and description.

Create a security group › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2

Create a security group › Request Body

name
​string

Name of the security group.

description
​string

Description of the security group.

disable_default_rules
​boolean

Whether to disable default rules.

project_id
​string

Project ID the security group belongs to.

tags
​string[]

Tags for the security group.

project_default
​boolean

Whether this should be the default security group for the project.

inbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for inbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
outbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for outbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
stateless
​boolean

Whether the security group should be stateless.

Create a security group › Responses

200
id
​string

Unique ID of the security group.

srn
​string

The SRN of the security group.

name
​string

Name of the security group.

description
​string

Description of the security group.

project_id
​string

Project ID the security group belongs to.

tags
​string[]

Tags associated with the security group.

disable_default_rules
​boolean

True if default rules are disabled.

project_default
​boolean

True if this is the default security group for the project.

inbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for inbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
outbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for outbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
stateless
​boolean

True if the security group is stateless.

created_at
​string | null · date-time

Creation timestamp of the security group. (RFC 3339 format)

updated_at
​string | null · date-time

Last update timestamp of the security group. (RFC 3339 format)

List of default rules applied to the security group.

List of custom rules applied to the security group.

zone
​string

Zone in which the security group is located.


Get a security group

GET
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-groups/{security_group_id}

Get the details of a specified security group.

Get a security group › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2
security_group_id
​string · required

ID of the security group to retrieve.

Get a security group › Responses

200
id
​string

Unique ID of the security group.

srn
​string

The SRN of the security group.

name
​string

Name of the security group.

description
​string

Description of the security group.

project_id
​string

Project ID the security group belongs to.

tags
​string[]

Tags associated with the security group.

disable_default_rules
​boolean

True if default rules are disabled.

project_default
​boolean

True if this is the default security group for the project.

inbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for inbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
outbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for outbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
stateless
​boolean

True if the security group is stateless.

created_at
​string | null · date-time

Creation timestamp of the security group. (RFC 3339 format)

updated_at
​string | null · date-time

Last update timestamp of the security group. (RFC 3339 format)

List of default rules applied to the security group.

List of custom rules applied to the security group.

zone
​string

Zone in which the security group is located.


Delete a security group

DELETE
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-groups/{security_group_id}

Delete a specified security group.

Delete a security group › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2
security_group_id
​string · required

ID of the security group to delete.

Delete a security group › Responses

No data returned

Update a security group

PATCH
https://api.scaleway.com
/instance/v2alpha1/zones/{zone}/security-groups/{security_group_id}

Update the properties of a security group.

Update a security group › path Parameters

zone
​string · enum · required

The zone you want to target

Enum values:
fr-par-1
fr-par-2
fr-par-3
nl-ams-1
nl-ams-2
nl-ams-3
pl-waw-1
pl-waw-2
security_group_id
​string · required

ID of the security group to update.

Update a security group › Request Body

name
​string | null

New name for the security group.

description
​string | null

New description for the security group.

disable_default_rules
​boolean | null

Whether to disable default rules.

tags
​array | null

New tags for the security group.

project_default
​boolean | null

Whether this should be the default security group for the project.

inbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

New default action for inbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
outbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

New default action for outbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
stateless
​boolean | null

Whether the security group should be stateless.

Update a security group › Responses

200
id
​string

Unique ID of the security group.

srn
​string

The SRN of the security group.

name
​string

Name of the security group.

description
​string

Description of the security group.

project_id
​string

Project ID the security group belongs to.

tags
​string[]

Tags associated with the security group.

disable_default_rules
​boolean

True if default rules are disabled.

project_default
​boolean

True if this is the default security group for the project.

inbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for inbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
outbound_default_action
​scaleway.instance.v2alpha1.SecurityGroup.Action · enum

Default action for outbound rules.

Enum values:
unknown_action
accept
drop
Default: unknown_action
stateless
​boolean

True if the security group is stateless.

created_at
​string | null · date-time

Creation timestamp of the security group. (RFC 3339 format)

updated_at
​string | null · date-time

Last update timestamp of the security group. (RFC 3339 format)

List of default rules applied to the security group.

List of custom rules applied to the security group.

zone
​string

Zone in which the security group is located.