Skip to content


Properties for defining a SecurityGroupIngress.



import { SecurityGroupIngressProps } from '@alicloud/ros-cdk-ecs'
const securityGroupIngressProps: SecurityGroupIngressProps = { ... }


Name Type Description
ipProtocol string | @alicloud/ros-cdk-core.IResolvable Property ipProtocol: Ip protocol for in rule.
portRange string | @alicloud/ros-cdk-core.IResolvable Property portRange: Ip protocol relative port range.
description string | @alicloud/ros-cdk-core.IResolvable Property description: Description of the security group rule, [1, 512] characters.
ipv6SourceCidrIp string | @alicloud/ros-cdk-core.IResolvable Property ipv6SourceCidrIp: Source IPv6 CIDR address segment.
nicType string | @alicloud/ros-cdk-core.IResolvable Property nicType: Network type, could be 'internet' or 'intranet'.
policy string | @alicloud/ros-cdk-core.IResolvable Property policy: Authorization policies, parameter values can be: accept (accepted access), drop (denied access).
priority number | @alicloud/ros-cdk-core.IResolvable Property priority: Authorization policies priority range[1, 100].
securityGroupId string | @alicloud/ros-cdk-core.IResolvable Property securityGroupId: Id of the security group.
sourceCidrIp string | @alicloud/ros-cdk-core.IResolvable Property sourceCidrIp: The source IPv4 CIDR block to which you want to control access.
sourceGroupId string | @alicloud/ros-cdk-core.IResolvable Property sourceGroupId: Source Group Id.
sourceGroupOwnerId string | @alicloud/ros-cdk-core.IResolvable Property sourceGroupOwnerId: Source Group Owner Account ID.
sourcePortRange string | @alicloud/ros-cdk-core.IResolvable Property sourcePortRange: The range of the ports enabled by the source security group for the transport layer protocol.
sourcePrefixListId string | @alicloud/ros-cdk-core.IResolvable Property sourcePrefixListId: The ID of the source prefix list to which you want to control access.


public readonly ipProtocol: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property ipProtocol: Ip protocol for in rule.


public readonly portRange: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property portRange: Ip protocol relative port range.

For tcp and udp, the port rang is [1,65535], using format '1\/200'For icmp|gre|all protocel, the port range should be '-1\/-1'


public readonly description: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property description: Description of the security group rule, [1, 512] characters.

The default is empty.


public readonly ipv6SourceCidrIp: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property ipv6SourceCidrIp: Source IPv6 CIDR address segment.

Supports IP address ranges in CIDR format and IPv6 format. Note Only VPC type IP addresses are supported.


public readonly nicType: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property nicType: Network type, could be 'internet' or 'intranet'.

Default value is internet.


public readonly policy: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property policy: Authorization policies, parameter values can be: accept (accepted access), drop (denied access).

Default value is accept.


public readonly priority: number | IResolvable;
  • Type: number | @alicloud/ros-cdk-core.IResolvable

Property priority: Authorization policies priority range[1, 100].


public readonly securityGroupId: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property securityGroupId: Id of the security group.


public readonly sourceCidrIp: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property sourceCidrIp: The source IPv4 CIDR block to which you want to control access.

CIDR blocks and IPv4 addresses are supported.


public readonly sourceGroupId: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property sourceGroupId: Source Group Id.


public readonly sourceGroupOwnerId: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property sourceGroupOwnerId: Source Group Owner Account ID.


public readonly sourcePortRange: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property sourcePortRange: The range of the ports enabled by the source security group for the transport layer protocol.

Valid values: TCP\/UDP: Value range: 1 to 65535. The start port and the end port are separated by a slash (\/). Correct example: 1\/200. Incorrect example: 200\/1.ICMP: -1\/-1.GRE: -1\/-1.ALL: -1\/-1.


public readonly sourcePrefixListId: string | IResolvable;
  • Type: string | @alicloud/ros-cdk-core.IResolvable

Property sourcePrefixListId: The ID of the source prefix list to which you want to control access.

You can call the DescribePrefixLists operation to query the IDs of available prefix lists. Take note of the following items: - If a security group is in the classic network, you cannot configure prefix lists in the security group rules. - If you specify the SourceCidrIp, Ipv6SourceCidrIp, or SourceGroupId parameter, this parameter is ignored.