Close httplib2 connections.
create(parent, body=None, rateLimitPolicyId=None, requestId=None, x__xgafv=None)
Creates a new `RateLimitPolicy` in a given project and location.
delete(name, requestId=None, x__xgafv=None)
Deletes a single `RateLimitPolicy`.
Gets details of a single `RateLimitPolicy`.
list(parent, filter=None, orderBy=None, pageSize=None, pageToken=None, x__xgafv=None)
Lists `RateLimitPolicy` resources in a given project and location.
list_next(previous_request, previous_response)
Retrieves the next page of results.
patch(name, body=None, requestId=None, updateMask=None, x__xgafv=None)
Updates the parameters of a single `RateLimitPolicy`.
close()
Close httplib2 connections.
create(parent, body=None, rateLimitPolicyId=None, requestId=None, x__xgafv=None)
Creates a new `RateLimitPolicy` in a given project and location.
Args:
parent: string, Required. Specifies the value for parent. (required)
body: object, The request body.
The object takes the form of:
{ # Describes a `RateLimitPolicy` object.
"createTime": "A String", # Output only. Represents the create timestamp.
"description": "A String", # Optional. Provides a human-readable description of the resource.
"httpRules": [ # Optional. Specifies a list of rate limit HTTP rules to match against the incoming request.
{ # Specifies conditions to match against the incoming request.
"from": { # Describes properties of the sources of a request. # Optional. Describes properties of a source of a request.
"notSource": { # Describes the properties of a request source. # Optional. Describes the negated properties of request source. Matches requests from source that does not match the criteria specified in this field. At least one of source or not_source must be specified.
"principals": [ # Required. Contains a list of identities derived from the client's certificate. This field does not match on a request unless frontend mutual TLS is enabled for the Gateway and the client certificate is successfully validated by mTLS. Each identity is a string whose value is matched against a list of URI SANs, DNS Name SANs, or the common name in the client's certificate. A match happens when any principal matches with the rule.
{ # Describes the properties of a principal for matching.
"principal": { # Determines how a string value is matched. # Required. Matches a non-empty string against the principal value based on the principal_selector.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
"principalSelector": "A String", # Optional. Decides what principal value the principal rule will match against. If not specified, defaults to CLIENT_CERT_URI_SAN.
},
],
},
"source": { # Describes the properties of a request source. # Optional. Describes the properties of a request's source. At least one of source or not_source must be specified. A match occurs when ANY fields in either source or not_source matches the request. Within a single source, the match follows OR semantics across fields and AND semantics within a single field.
"principals": [ # Required. Contains a list of identities derived from the client's certificate. This field does not match on a request unless frontend mutual TLS is enabled for the Gateway and the client certificate is successfully validated by mTLS. Each identity is a string whose value is matched against a list of URI SANs, DNS Name SANs, or the common name in the client's certificate. A match happens when any principal matches with the rule.
{ # Describes the properties of a principal for matching.
"principal": { # Determines how a string value is matched. # Required. Matches a non-empty string against the principal value based on the principal_selector.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
"principalSelector": "A String", # Optional. Decides what principal value the principal rule will match against. If not specified, defaults to CLIENT_CERT_URI_SAN.
},
],
},
},
"rateLimitActions": [ # Optional. Specifies the actions to take when this rule is matched.
{ # Describes the action to take when the rate limit rule is matched.
"rateLimitBucket": "A String", # Required. Specifies the name of the rate limit bucket to apply when this rule is matched.
},
],
"to": { # Describes properties of the targets of a request. # Optional. Describes properties of a target of a request.
"destination": { # Describes properties of a request target. # Optional. Describes properties of a request's destination. At least one of destination or not_destination must be specified. A match occurs when ANY fields in either destination or not_destination matches the request. Within a destination, the match follows OR semantics across fields and AND semantics within a single field.
"headerSet": { # Describes a set of HTTP headers to match against. # Optional. Specifies a list of headers to match against in http header.
"headers": [ # Required. Contains a list of headers to match against in http header. The match can be one of exact, prefix, suffix, or contains (substring match). The match follows AND semantics which means all the headers must match. Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how an HTTP header is matched.
"name": "A String", # Optional. Specifies the name of the header in the request.
"value": { # Determines how a string value is matched. # Optional. Specifies how the header match is performed.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
},
],
},
"hosts": [ # Optional. Specifies a list of HTTP Hosts to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the hosts match, the operation is considered to be matched.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
"mcp": { # Describes a set of MCP protocol attributes to match against for a given MCP request. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it. # Optional. Specifies the MCP protocol attributes to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"baseProtocolMethodsOption": "A String", # Optional. If specified, matches on the MCP protocol’s non-access specific methods namely: * initialize * completion/ * logging/ * notifications/ * ping Defaults to SKIP_BASE_PROTOCOL_METHODS if not specified.
"methods": [ # Optional. A list of MCP methods and associated parameter names to match on. It is recommended to use this field to match on tools, prompts and resource accesses while setting the baseProtocolMethodsOption to MATCH_BASE_PROTOCOL_METHODS to match on all the other MCP protocol methods. Limited to 10 MCP methods per Rate Limit Policy.
{ # Describes a set of MCP methods to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"name": "A String", # Required. Specifies the MCP method to match against. Allowed values are as follows: 1. `tools`, `prompts`, `resources` - these will match against all sub methods under the respective methods. 2. `prompts/list`, `tools/list`, `resources/list`, `resources/templates/list` 3. `prompts/get`, `tools/call`, `resources/subscribe`, `resources/unsubscribe`, `resources/read` Params cannot be specified for categories 1 and 2.
"params": [ # Optional. Specifies a list of MCP method parameter names to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
],
},
"methods": [ # Optional. Specifies a list of HTTP methods to match against. Each entry must be a valid HTTP method name (GET, PUT, POST, HEAD, PATCH, DELETE, OPTIONS). It only allows exact match and is always case sensitive. The match follows OR semantics which means that if any of the methods match, the operation is considered to be matched.
"A String",
],
"paths": [ # Optional. Specifies a list of paths to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the paths match, the operation is considered to be matched. Note that this path match includes the query parameters. For gRPC services, this should be a fully-qualified name of the form /package.service/method.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
"notDestination": { # Describes properties of a request target. # Optional. Describes the negated properties of a request's destination. Matches requests for destination that does not match the criteria specified in this field. At least one of destination or not_destination must be specified.
"headerSet": { # Describes a set of HTTP headers to match against. # Optional. Specifies a list of headers to match against in http header.
"headers": [ # Required. Contains a list of headers to match against in http header. The match can be one of exact, prefix, suffix, or contains (substring match). The match follows AND semantics which means all the headers must match. Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how an HTTP header is matched.
"name": "A String", # Optional. Specifies the name of the header in the request.
"value": { # Determines how a string value is matched. # Optional. Specifies how the header match is performed.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
},
],
},
"hosts": [ # Optional. Specifies a list of HTTP Hosts to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the hosts match, the operation is considered to be matched.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
"mcp": { # Describes a set of MCP protocol attributes to match against for a given MCP request. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it. # Optional. Specifies the MCP protocol attributes to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"baseProtocolMethodsOption": "A String", # Optional. If specified, matches on the MCP protocol’s non-access specific methods namely: * initialize * completion/ * logging/ * notifications/ * ping Defaults to SKIP_BASE_PROTOCOL_METHODS if not specified.
"methods": [ # Optional. A list of MCP methods and associated parameter names to match on. It is recommended to use this field to match on tools, prompts and resource accesses while setting the baseProtocolMethodsOption to MATCH_BASE_PROTOCOL_METHODS to match on all the other MCP protocol methods. Limited to 10 MCP methods per Rate Limit Policy.
{ # Describes a set of MCP methods to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"name": "A String", # Required. Specifies the MCP method to match against. Allowed values are as follows: 1. `tools`, `prompts`, `resources` - these will match against all sub methods under the respective methods. 2. `prompts/list`, `tools/list`, `resources/list`, `resources/templates/list` 3. `prompts/get`, `tools/call`, `resources/subscribe`, `resources/unsubscribe`, `resources/read` Params cannot be specified for categories 1 and 2.
"params": [ # Optional. Specifies a list of MCP method parameter names to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
],
},
"methods": [ # Optional. Specifies a list of HTTP methods to match against. Each entry must be a valid HTTP method name (GET, PUT, POST, HEAD, PATCH, DELETE, OPTIONS). It only allows exact match and is always case sensitive. The match follows OR semantics which means that if any of the methods match, the operation is considered to be matched.
"A String",
],
"paths": [ # Optional. Specifies a list of paths to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the paths match, the operation is considered to be matched. Note that this path match includes the query parameters. For gRPC services, this should be a fully-qualified name of the form /package.service/method.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
},
},
],
"labels": { # Optional. Stores labels as key value pairs.
"a_key": "A String",
},
"name": "A String", # Identifier. Specifies the name of the `RateLimitPolicy` resource.
"rateLimitBuckets": [ # Optional. Specifies a list of rate limit buckets to be used for rate limiting. Rate limit buckets will be referenced by the rate limit actions by name.
{ # Describes properties of a rate limit bucket.
"defaultLimit": { # Describes a limit for enforcement. # Required. Specifies the default limit to apply for this rate limit bucket.
"countLimit": { # Describes the count limit for enforcement. # Required. Defines the count limit to enforce.
"count": "A String", # Required. Specifies the maximum number of costs allowed in the specified interval. Must be non-negative.
"interval": "A String", # Required. Specifies the interval in units for which the count limit is enforced. Must be positive.
"intervalUnit": "A String", # Required. Specifies the unit of the interval. Defaults to MINUTES.
},
},
"dryRun": True or False, # Optional. Specifies whether the rate limit bucket is in dry-run mode.
"keys": [ # Required. Specifies the keys to use for rate limiting. At least one key is required. If multiple keys are specified, the keys will be combined and used as a single key.
{ # Describes properties of a key to use for rate limiting.
"header": "A String", # Optional. Specifies the header name if key_type is HTTP_HEADER.
"keyType": "A String", # Required. Specifies the type of key to use for rate limiting.
"principalType": "A String", # Optional. Specifies the principal type if key_type is PRINCIPAL.
},
],
"name": "A String", # Required. Specifies the name of the rate limit bucket. Name will be used to reference the bucket in the RateLimitAction.
"userOverrides": [ # Optional. Specifies a list of user overrides to apply to the rate limit bucket.
{ # Describes properties of a user override for the rate limit bucket.
"limit": { # Describes a limit for enforcement. # Required. Specifies the limit to apply for this specific key.
"countLimit": { # Describes the count limit for enforcement. # Required. Defines the count limit to enforce.
"count": "A String", # Required. Specifies the maximum number of costs allowed in the specified interval. Must be non-negative.
"interval": "A String", # Required. Specifies the interval in units for which the count limit is enforced. Must be positive.
"intervalUnit": "A String", # Required. Specifies the unit of the interval. Defaults to MINUTES.
},
},
"overrideKey": { # Specifies the key to override. Key fields must match the key types specified in the rate limit bucket. Key type ALL does not support overrides. # Required. Specifies the key to override.
"httpHeaders": [ # Optional. Specifies the HTTP headers if the rate limit bucket keys contain keys of type HTTP_HEADER. Number of headers and header names must match the rate limit bucket key.
{ # Specifies the key in the type HTTP header to override.
"header": "A String", # Required. Specifies the header name of the key.
"value": "A String", # Required. Specifies the header value of the key.
},
],
"httpPath": "A String", # Optional. Specifies the HTTP path if the rate limit bucket keys contain a key of type HTTP_PATH.
"mcpTool": "A String", # Optional. Specifies the MCP tool if the rate limit bucket keys contain a key of type MCP_TOOL.
"principals": [ # Optional. Specifies the principals if the rate limit bucket keys contain keys of PRINCIPAL. Number of principals and principal types must match the rate limit bucket key.
{ # Specifies the key in the type PRINCIPAL to override.
"principal": "A String", # Required. Specifies the principal value of the key.
"principalType": "A String", # Required. Specifies the principal type of the key.
},
],
"sourceIp": "A String", # Optional. Specifies the source IP if the rate limit bucket keys contain a key of type SOURCE_IP.
},
},
],
},
],
"targets": [ # Required. Specifies a list of targets to which this policy applies.
{ # Specifies the target to which this policy applies.
"resource": "A String", # Required. Reference to a Gateway or Forwarding Rule resource on which this policy will be applied.
},
],
"updateTime": "A String", # Output only. Represents the update timestamp.
}
rateLimitPolicyId: string, Required. Specifies the ID of the requesting object. If auto-generating Id server-side, remove this field and rate_limit_policy_id from the method_signature of Create RPC
requestId: string, Optional. Specifies an optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).
x__xgafv: string, V1 error format.
Allowed values
1 - v1 error format
2 - v2 error format
Returns:
An object of the form:
{ # This resource represents a long-running operation that is the result of a network API call.
"done": True or False, # If the value is `false`, it means the operation is still in progress. If `true`, the operation is completed, and either `error` or `response` is available.
"error": { # The `Status` type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by [gRPC](https://github.com/grpc). Each `Status` message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the [API Design Guide](https://cloud.google.com/apis/design/errors). # The error result of the operation in case of failure or cancellation.
"code": 42, # The status code, which should be an enum value of google.rpc.Code.
"details": [ # A list of messages that carry the error details. There is a common set of message types for APIs to use.
{
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
],
"message": "A String", # A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the google.rpc.Status.details field, or localized by the client.
},
"metadata": { # Service-specific metadata associated with the operation. It typically contains progress information and common metadata such as create time. Some services might not provide such metadata. Any method that returns a long-running operation should document the metadata type, if any.
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
"name": "A String", # The server-assigned name, which is only unique within the same service that originally returns it. If you use the default HTTP mapping, the `name` should be a resource name ending with `operations/{unique_id}`.
"response": { # The normal, successful response of the operation. If the original method returns no data on success, such as `Delete`, the response is `google.protobuf.Empty`. If the original method is standard `Get`/`Create`/`Update`, the response should be the resource. For other methods, the response should have the type `XxxResponse`, where `Xxx` is the original method name. For example, if the original method name is `TakeSnapshot()`, the inferred response type is `TakeSnapshotResponse`.
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
}
delete(name, requestId=None, x__xgafv=None)
Deletes a single `RateLimitPolicy`.
Args:
name: string, Required. Specifies the name of the resource. (required)
requestId: string, Optional. Specifies an optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes after the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).
x__xgafv: string, V1 error format.
Allowed values
1 - v1 error format
2 - v2 error format
Returns:
An object of the form:
{ # This resource represents a long-running operation that is the result of a network API call.
"done": True or False, # If the value is `false`, it means the operation is still in progress. If `true`, the operation is completed, and either `error` or `response` is available.
"error": { # The `Status` type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by [gRPC](https://github.com/grpc). Each `Status` message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the [API Design Guide](https://cloud.google.com/apis/design/errors). # The error result of the operation in case of failure or cancellation.
"code": 42, # The status code, which should be an enum value of google.rpc.Code.
"details": [ # A list of messages that carry the error details. There is a common set of message types for APIs to use.
{
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
],
"message": "A String", # A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the google.rpc.Status.details field, or localized by the client.
},
"metadata": { # Service-specific metadata associated with the operation. It typically contains progress information and common metadata such as create time. Some services might not provide such metadata. Any method that returns a long-running operation should document the metadata type, if any.
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
"name": "A String", # The server-assigned name, which is only unique within the same service that originally returns it. If you use the default HTTP mapping, the `name` should be a resource name ending with `operations/{unique_id}`.
"response": { # The normal, successful response of the operation. If the original method returns no data on success, such as `Delete`, the response is `google.protobuf.Empty`. If the original method is standard `Get`/`Create`/`Update`, the response should be the resource. For other methods, the response should have the type `XxxResponse`, where `Xxx` is the original method name. For example, if the original method name is `TakeSnapshot()`, the inferred response type is `TakeSnapshotResponse`.
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
}
get(name, x__xgafv=None)
Gets details of a single `RateLimitPolicy`.
Args:
name: string, Required. Specifies the name of the resource. (required)
x__xgafv: string, V1 error format.
Allowed values
1 - v1 error format
2 - v2 error format
Returns:
An object of the form:
{ # Describes a `RateLimitPolicy` object.
"createTime": "A String", # Output only. Represents the create timestamp.
"description": "A String", # Optional. Provides a human-readable description of the resource.
"httpRules": [ # Optional. Specifies a list of rate limit HTTP rules to match against the incoming request.
{ # Specifies conditions to match against the incoming request.
"from": { # Describes properties of the sources of a request. # Optional. Describes properties of a source of a request.
"notSource": { # Describes the properties of a request source. # Optional. Describes the negated properties of request source. Matches requests from source that does not match the criteria specified in this field. At least one of source or not_source must be specified.
"principals": [ # Required. Contains a list of identities derived from the client's certificate. This field does not match on a request unless frontend mutual TLS is enabled for the Gateway and the client certificate is successfully validated by mTLS. Each identity is a string whose value is matched against a list of URI SANs, DNS Name SANs, or the common name in the client's certificate. A match happens when any principal matches with the rule.
{ # Describes the properties of a principal for matching.
"principal": { # Determines how a string value is matched. # Required. Matches a non-empty string against the principal value based on the principal_selector.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
"principalSelector": "A String", # Optional. Decides what principal value the principal rule will match against. If not specified, defaults to CLIENT_CERT_URI_SAN.
},
],
},
"source": { # Describes the properties of a request source. # Optional. Describes the properties of a request's source. At least one of source or not_source must be specified. A match occurs when ANY fields in either source or not_source matches the request. Within a single source, the match follows OR semantics across fields and AND semantics within a single field.
"principals": [ # Required. Contains a list of identities derived from the client's certificate. This field does not match on a request unless frontend mutual TLS is enabled for the Gateway and the client certificate is successfully validated by mTLS. Each identity is a string whose value is matched against a list of URI SANs, DNS Name SANs, or the common name in the client's certificate. A match happens when any principal matches with the rule.
{ # Describes the properties of a principal for matching.
"principal": { # Determines how a string value is matched. # Required. Matches a non-empty string against the principal value based on the principal_selector.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
"principalSelector": "A String", # Optional. Decides what principal value the principal rule will match against. If not specified, defaults to CLIENT_CERT_URI_SAN.
},
],
},
},
"rateLimitActions": [ # Optional. Specifies the actions to take when this rule is matched.
{ # Describes the action to take when the rate limit rule is matched.
"rateLimitBucket": "A String", # Required. Specifies the name of the rate limit bucket to apply when this rule is matched.
},
],
"to": { # Describes properties of the targets of a request. # Optional. Describes properties of a target of a request.
"destination": { # Describes properties of a request target. # Optional. Describes properties of a request's destination. At least one of destination or not_destination must be specified. A match occurs when ANY fields in either destination or not_destination matches the request. Within a destination, the match follows OR semantics across fields and AND semantics within a single field.
"headerSet": { # Describes a set of HTTP headers to match against. # Optional. Specifies a list of headers to match against in http header.
"headers": [ # Required. Contains a list of headers to match against in http header. The match can be one of exact, prefix, suffix, or contains (substring match). The match follows AND semantics which means all the headers must match. Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how an HTTP header is matched.
"name": "A String", # Optional. Specifies the name of the header in the request.
"value": { # Determines how a string value is matched. # Optional. Specifies how the header match is performed.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
},
],
},
"hosts": [ # Optional. Specifies a list of HTTP Hosts to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the hosts match, the operation is considered to be matched.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
"mcp": { # Describes a set of MCP protocol attributes to match against for a given MCP request. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it. # Optional. Specifies the MCP protocol attributes to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"baseProtocolMethodsOption": "A String", # Optional. If specified, matches on the MCP protocol’s non-access specific methods namely: * initialize * completion/ * logging/ * notifications/ * ping Defaults to SKIP_BASE_PROTOCOL_METHODS if not specified.
"methods": [ # Optional. A list of MCP methods and associated parameter names to match on. It is recommended to use this field to match on tools, prompts and resource accesses while setting the baseProtocolMethodsOption to MATCH_BASE_PROTOCOL_METHODS to match on all the other MCP protocol methods. Limited to 10 MCP methods per Rate Limit Policy.
{ # Describes a set of MCP methods to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"name": "A String", # Required. Specifies the MCP method to match against. Allowed values are as follows: 1. `tools`, `prompts`, `resources` - these will match against all sub methods under the respective methods. 2. `prompts/list`, `tools/list`, `resources/list`, `resources/templates/list` 3. `prompts/get`, `tools/call`, `resources/subscribe`, `resources/unsubscribe`, `resources/read` Params cannot be specified for categories 1 and 2.
"params": [ # Optional. Specifies a list of MCP method parameter names to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
],
},
"methods": [ # Optional. Specifies a list of HTTP methods to match against. Each entry must be a valid HTTP method name (GET, PUT, POST, HEAD, PATCH, DELETE, OPTIONS). It only allows exact match and is always case sensitive. The match follows OR semantics which means that if any of the methods match, the operation is considered to be matched.
"A String",
],
"paths": [ # Optional. Specifies a list of paths to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the paths match, the operation is considered to be matched. Note that this path match includes the query parameters. For gRPC services, this should be a fully-qualified name of the form /package.service/method.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
"notDestination": { # Describes properties of a request target. # Optional. Describes the negated properties of a request's destination. Matches requests for destination that does not match the criteria specified in this field. At least one of destination or not_destination must be specified.
"headerSet": { # Describes a set of HTTP headers to match against. # Optional. Specifies a list of headers to match against in http header.
"headers": [ # Required. Contains a list of headers to match against in http header. The match can be one of exact, prefix, suffix, or contains (substring match). The match follows AND semantics which means all the headers must match. Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how an HTTP header is matched.
"name": "A String", # Optional. Specifies the name of the header in the request.
"value": { # Determines how a string value is matched. # Optional. Specifies how the header match is performed.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
},
],
},
"hosts": [ # Optional. Specifies a list of HTTP Hosts to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the hosts match, the operation is considered to be matched.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
"mcp": { # Describes a set of MCP protocol attributes to match against for a given MCP request. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it. # Optional. Specifies the MCP protocol attributes to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"baseProtocolMethodsOption": "A String", # Optional. If specified, matches on the MCP protocol’s non-access specific methods namely: * initialize * completion/ * logging/ * notifications/ * ping Defaults to SKIP_BASE_PROTOCOL_METHODS if not specified.
"methods": [ # Optional. A list of MCP methods and associated parameter names to match on. It is recommended to use this field to match on tools, prompts and resource accesses while setting the baseProtocolMethodsOption to MATCH_BASE_PROTOCOL_METHODS to match on all the other MCP protocol methods. Limited to 10 MCP methods per Rate Limit Policy.
{ # Describes a set of MCP methods to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"name": "A String", # Required. Specifies the MCP method to match against. Allowed values are as follows: 1. `tools`, `prompts`, `resources` - these will match against all sub methods under the respective methods. 2. `prompts/list`, `tools/list`, `resources/list`, `resources/templates/list` 3. `prompts/get`, `tools/call`, `resources/subscribe`, `resources/unsubscribe`, `resources/read` Params cannot be specified for categories 1 and 2.
"params": [ # Optional. Specifies a list of MCP method parameter names to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
],
},
"methods": [ # Optional. Specifies a list of HTTP methods to match against. Each entry must be a valid HTTP method name (GET, PUT, POST, HEAD, PATCH, DELETE, OPTIONS). It only allows exact match and is always case sensitive. The match follows OR semantics which means that if any of the methods match, the operation is considered to be matched.
"A String",
],
"paths": [ # Optional. Specifies a list of paths to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the paths match, the operation is considered to be matched. Note that this path match includes the query parameters. For gRPC services, this should be a fully-qualified name of the form /package.service/method.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
},
},
],
"labels": { # Optional. Stores labels as key value pairs.
"a_key": "A String",
},
"name": "A String", # Identifier. Specifies the name of the `RateLimitPolicy` resource.
"rateLimitBuckets": [ # Optional. Specifies a list of rate limit buckets to be used for rate limiting. Rate limit buckets will be referenced by the rate limit actions by name.
{ # Describes properties of a rate limit bucket.
"defaultLimit": { # Describes a limit for enforcement. # Required. Specifies the default limit to apply for this rate limit bucket.
"countLimit": { # Describes the count limit for enforcement. # Required. Defines the count limit to enforce.
"count": "A String", # Required. Specifies the maximum number of costs allowed in the specified interval. Must be non-negative.
"interval": "A String", # Required. Specifies the interval in units for which the count limit is enforced. Must be positive.
"intervalUnit": "A String", # Required. Specifies the unit of the interval. Defaults to MINUTES.
},
},
"dryRun": True or False, # Optional. Specifies whether the rate limit bucket is in dry-run mode.
"keys": [ # Required. Specifies the keys to use for rate limiting. At least one key is required. If multiple keys are specified, the keys will be combined and used as a single key.
{ # Describes properties of a key to use for rate limiting.
"header": "A String", # Optional. Specifies the header name if key_type is HTTP_HEADER.
"keyType": "A String", # Required. Specifies the type of key to use for rate limiting.
"principalType": "A String", # Optional. Specifies the principal type if key_type is PRINCIPAL.
},
],
"name": "A String", # Required. Specifies the name of the rate limit bucket. Name will be used to reference the bucket in the RateLimitAction.
"userOverrides": [ # Optional. Specifies a list of user overrides to apply to the rate limit bucket.
{ # Describes properties of a user override for the rate limit bucket.
"limit": { # Describes a limit for enforcement. # Required. Specifies the limit to apply for this specific key.
"countLimit": { # Describes the count limit for enforcement. # Required. Defines the count limit to enforce.
"count": "A String", # Required. Specifies the maximum number of costs allowed in the specified interval. Must be non-negative.
"interval": "A String", # Required. Specifies the interval in units for which the count limit is enforced. Must be positive.
"intervalUnit": "A String", # Required. Specifies the unit of the interval. Defaults to MINUTES.
},
},
"overrideKey": { # Specifies the key to override. Key fields must match the key types specified in the rate limit bucket. Key type ALL does not support overrides. # Required. Specifies the key to override.
"httpHeaders": [ # Optional. Specifies the HTTP headers if the rate limit bucket keys contain keys of type HTTP_HEADER. Number of headers and header names must match the rate limit bucket key.
{ # Specifies the key in the type HTTP header to override.
"header": "A String", # Required. Specifies the header name of the key.
"value": "A String", # Required. Specifies the header value of the key.
},
],
"httpPath": "A String", # Optional. Specifies the HTTP path if the rate limit bucket keys contain a key of type HTTP_PATH.
"mcpTool": "A String", # Optional. Specifies the MCP tool if the rate limit bucket keys contain a key of type MCP_TOOL.
"principals": [ # Optional. Specifies the principals if the rate limit bucket keys contain keys of PRINCIPAL. Number of principals and principal types must match the rate limit bucket key.
{ # Specifies the key in the type PRINCIPAL to override.
"principal": "A String", # Required. Specifies the principal value of the key.
"principalType": "A String", # Required. Specifies the principal type of the key.
},
],
"sourceIp": "A String", # Optional. Specifies the source IP if the rate limit bucket keys contain a key of type SOURCE_IP.
},
},
],
},
],
"targets": [ # Required. Specifies a list of targets to which this policy applies.
{ # Specifies the target to which this policy applies.
"resource": "A String", # Required. Reference to a Gateway or Forwarding Rule resource on which this policy will be applied.
},
],
"updateTime": "A String", # Output only. Represents the update timestamp.
}
list(parent, filter=None, orderBy=None, pageSize=None, pageToken=None, x__xgafv=None)
Lists `RateLimitPolicy` resources in a given project and location.
Args:
parent: string, Required. Specifies the parent value for `ListRateLimitPoliciesRequest`. (required)
filter: string, Optional. Filters results.
orderBy: string, Optional. Provides a hint for how to order the results.
pageSize: integer, Optional. Specifies the requested page size. Server may return fewer items than requested. If unspecified, server will pick an appropriate default.
pageToken: string, Optional. Identifies a token for a page of results the server should return.
x__xgafv: string, V1 error format.
Allowed values
1 - v1 error format
2 - v2 error format
Returns:
An object of the form:
{ # Contains a response to listing `RateLimitPolicy` resources.
"nextPageToken": "A String", # Identifies a token for a page of results the server should return.
"rateLimitPolicies": [ # Contains a list of `RateLimitPolicy` resources.
{ # Describes a `RateLimitPolicy` object.
"createTime": "A String", # Output only. Represents the create timestamp.
"description": "A String", # Optional. Provides a human-readable description of the resource.
"httpRules": [ # Optional. Specifies a list of rate limit HTTP rules to match against the incoming request.
{ # Specifies conditions to match against the incoming request.
"from": { # Describes properties of the sources of a request. # Optional. Describes properties of a source of a request.
"notSource": { # Describes the properties of a request source. # Optional. Describes the negated properties of request source. Matches requests from source that does not match the criteria specified in this field. At least one of source or not_source must be specified.
"principals": [ # Required. Contains a list of identities derived from the client's certificate. This field does not match on a request unless frontend mutual TLS is enabled for the Gateway and the client certificate is successfully validated by mTLS. Each identity is a string whose value is matched against a list of URI SANs, DNS Name SANs, or the common name in the client's certificate. A match happens when any principal matches with the rule.
{ # Describes the properties of a principal for matching.
"principal": { # Determines how a string value is matched. # Required. Matches a non-empty string against the principal value based on the principal_selector.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
"principalSelector": "A String", # Optional. Decides what principal value the principal rule will match against. If not specified, defaults to CLIENT_CERT_URI_SAN.
},
],
},
"source": { # Describes the properties of a request source. # Optional. Describes the properties of a request's source. At least one of source or not_source must be specified. A match occurs when ANY fields in either source or not_source matches the request. Within a single source, the match follows OR semantics across fields and AND semantics within a single field.
"principals": [ # Required. Contains a list of identities derived from the client's certificate. This field does not match on a request unless frontend mutual TLS is enabled for the Gateway and the client certificate is successfully validated by mTLS. Each identity is a string whose value is matched against a list of URI SANs, DNS Name SANs, or the common name in the client's certificate. A match happens when any principal matches with the rule.
{ # Describes the properties of a principal for matching.
"principal": { # Determines how a string value is matched. # Required. Matches a non-empty string against the principal value based on the principal_selector.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
"principalSelector": "A String", # Optional. Decides what principal value the principal rule will match against. If not specified, defaults to CLIENT_CERT_URI_SAN.
},
],
},
},
"rateLimitActions": [ # Optional. Specifies the actions to take when this rule is matched.
{ # Describes the action to take when the rate limit rule is matched.
"rateLimitBucket": "A String", # Required. Specifies the name of the rate limit bucket to apply when this rule is matched.
},
],
"to": { # Describes properties of the targets of a request. # Optional. Describes properties of a target of a request.
"destination": { # Describes properties of a request target. # Optional. Describes properties of a request's destination. At least one of destination or not_destination must be specified. A match occurs when ANY fields in either destination or not_destination matches the request. Within a destination, the match follows OR semantics across fields and AND semantics within a single field.
"headerSet": { # Describes a set of HTTP headers to match against. # Optional. Specifies a list of headers to match against in http header.
"headers": [ # Required. Contains a list of headers to match against in http header. The match can be one of exact, prefix, suffix, or contains (substring match). The match follows AND semantics which means all the headers must match. Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how an HTTP header is matched.
"name": "A String", # Optional. Specifies the name of the header in the request.
"value": { # Determines how a string value is matched. # Optional. Specifies how the header match is performed.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
},
],
},
"hosts": [ # Optional. Specifies a list of HTTP Hosts to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the hosts match, the operation is considered to be matched.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
"mcp": { # Describes a set of MCP protocol attributes to match against for a given MCP request. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it. # Optional. Specifies the MCP protocol attributes to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"baseProtocolMethodsOption": "A String", # Optional. If specified, matches on the MCP protocol’s non-access specific methods namely: * initialize * completion/ * logging/ * notifications/ * ping Defaults to SKIP_BASE_PROTOCOL_METHODS if not specified.
"methods": [ # Optional. A list of MCP methods and associated parameter names to match on. It is recommended to use this field to match on tools, prompts and resource accesses while setting the baseProtocolMethodsOption to MATCH_BASE_PROTOCOL_METHODS to match on all the other MCP protocol methods. Limited to 10 MCP methods per Rate Limit Policy.
{ # Describes a set of MCP methods to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"name": "A String", # Required. Specifies the MCP method to match against. Allowed values are as follows: 1. `tools`, `prompts`, `resources` - these will match against all sub methods under the respective methods. 2. `prompts/list`, `tools/list`, `resources/list`, `resources/templates/list` 3. `prompts/get`, `tools/call`, `resources/subscribe`, `resources/unsubscribe`, `resources/read` Params cannot be specified for categories 1 and 2.
"params": [ # Optional. Specifies a list of MCP method parameter names to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
],
},
"methods": [ # Optional. Specifies a list of HTTP methods to match against. Each entry must be a valid HTTP method name (GET, PUT, POST, HEAD, PATCH, DELETE, OPTIONS). It only allows exact match and is always case sensitive. The match follows OR semantics which means that if any of the methods match, the operation is considered to be matched.
"A String",
],
"paths": [ # Optional. Specifies a list of paths to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the paths match, the operation is considered to be matched. Note that this path match includes the query parameters. For gRPC services, this should be a fully-qualified name of the form /package.service/method.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
"notDestination": { # Describes properties of a request target. # Optional. Describes the negated properties of a request's destination. Matches requests for destination that does not match the criteria specified in this field. At least one of destination or not_destination must be specified.
"headerSet": { # Describes a set of HTTP headers to match against. # Optional. Specifies a list of headers to match against in http header.
"headers": [ # Required. Contains a list of headers to match against in http header. The match can be one of exact, prefix, suffix, or contains (substring match). The match follows AND semantics which means all the headers must match. Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how an HTTP header is matched.
"name": "A String", # Optional. Specifies the name of the header in the request.
"value": { # Determines how a string value is matched. # Optional. Specifies how the header match is performed.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
},
],
},
"hosts": [ # Optional. Specifies a list of HTTP Hosts to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the hosts match, the operation is considered to be matched.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
"mcp": { # Describes a set of MCP protocol attributes to match against for a given MCP request. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it. # Optional. Specifies the MCP protocol attributes to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"baseProtocolMethodsOption": "A String", # Optional. If specified, matches on the MCP protocol’s non-access specific methods namely: * initialize * completion/ * logging/ * notifications/ * ping Defaults to SKIP_BASE_PROTOCOL_METHODS if not specified.
"methods": [ # Optional. A list of MCP methods and associated parameter names to match on. It is recommended to use this field to match on tools, prompts and resource accesses while setting the baseProtocolMethodsOption to MATCH_BASE_PROTOCOL_METHODS to match on all the other MCP protocol methods. Limited to 10 MCP methods per Rate Limit Policy.
{ # Describes a set of MCP methods to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"name": "A String", # Required. Specifies the MCP method to match against. Allowed values are as follows: 1. `tools`, `prompts`, `resources` - these will match against all sub methods under the respective methods. 2. `prompts/list`, `tools/list`, `resources/list`, `resources/templates/list` 3. `prompts/get`, `tools/call`, `resources/subscribe`, `resources/unsubscribe`, `resources/read` Params cannot be specified for categories 1 and 2.
"params": [ # Optional. Specifies a list of MCP method parameter names to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
],
},
"methods": [ # Optional. Specifies a list of HTTP methods to match against. Each entry must be a valid HTTP method name (GET, PUT, POST, HEAD, PATCH, DELETE, OPTIONS). It only allows exact match and is always case sensitive. The match follows OR semantics which means that if any of the methods match, the operation is considered to be matched.
"A String",
],
"paths": [ # Optional. Specifies a list of paths to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the paths match, the operation is considered to be matched. Note that this path match includes the query parameters. For gRPC services, this should be a fully-qualified name of the form /package.service/method.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
},
},
],
"labels": { # Optional. Stores labels as key value pairs.
"a_key": "A String",
},
"name": "A String", # Identifier. Specifies the name of the `RateLimitPolicy` resource.
"rateLimitBuckets": [ # Optional. Specifies a list of rate limit buckets to be used for rate limiting. Rate limit buckets will be referenced by the rate limit actions by name.
{ # Describes properties of a rate limit bucket.
"defaultLimit": { # Describes a limit for enforcement. # Required. Specifies the default limit to apply for this rate limit bucket.
"countLimit": { # Describes the count limit for enforcement. # Required. Defines the count limit to enforce.
"count": "A String", # Required. Specifies the maximum number of costs allowed in the specified interval. Must be non-negative.
"interval": "A String", # Required. Specifies the interval in units for which the count limit is enforced. Must be positive.
"intervalUnit": "A String", # Required. Specifies the unit of the interval. Defaults to MINUTES.
},
},
"dryRun": True or False, # Optional. Specifies whether the rate limit bucket is in dry-run mode.
"keys": [ # Required. Specifies the keys to use for rate limiting. At least one key is required. If multiple keys are specified, the keys will be combined and used as a single key.
{ # Describes properties of a key to use for rate limiting.
"header": "A String", # Optional. Specifies the header name if key_type is HTTP_HEADER.
"keyType": "A String", # Required. Specifies the type of key to use for rate limiting.
"principalType": "A String", # Optional. Specifies the principal type if key_type is PRINCIPAL.
},
],
"name": "A String", # Required. Specifies the name of the rate limit bucket. Name will be used to reference the bucket in the RateLimitAction.
"userOverrides": [ # Optional. Specifies a list of user overrides to apply to the rate limit bucket.
{ # Describes properties of a user override for the rate limit bucket.
"limit": { # Describes a limit for enforcement. # Required. Specifies the limit to apply for this specific key.
"countLimit": { # Describes the count limit for enforcement. # Required. Defines the count limit to enforce.
"count": "A String", # Required. Specifies the maximum number of costs allowed in the specified interval. Must be non-negative.
"interval": "A String", # Required. Specifies the interval in units for which the count limit is enforced. Must be positive.
"intervalUnit": "A String", # Required. Specifies the unit of the interval. Defaults to MINUTES.
},
},
"overrideKey": { # Specifies the key to override. Key fields must match the key types specified in the rate limit bucket. Key type ALL does not support overrides. # Required. Specifies the key to override.
"httpHeaders": [ # Optional. Specifies the HTTP headers if the rate limit bucket keys contain keys of type HTTP_HEADER. Number of headers and header names must match the rate limit bucket key.
{ # Specifies the key in the type HTTP header to override.
"header": "A String", # Required. Specifies the header name of the key.
"value": "A String", # Required. Specifies the header value of the key.
},
],
"httpPath": "A String", # Optional. Specifies the HTTP path if the rate limit bucket keys contain a key of type HTTP_PATH.
"mcpTool": "A String", # Optional. Specifies the MCP tool if the rate limit bucket keys contain a key of type MCP_TOOL.
"principals": [ # Optional. Specifies the principals if the rate limit bucket keys contain keys of PRINCIPAL. Number of principals and principal types must match the rate limit bucket key.
{ # Specifies the key in the type PRINCIPAL to override.
"principal": "A String", # Required. Specifies the principal value of the key.
"principalType": "A String", # Required. Specifies the principal type of the key.
},
],
"sourceIp": "A String", # Optional. Specifies the source IP if the rate limit bucket keys contain a key of type SOURCE_IP.
},
},
],
},
],
"targets": [ # Required. Specifies a list of targets to which this policy applies.
{ # Specifies the target to which this policy applies.
"resource": "A String", # Required. Reference to a Gateway or Forwarding Rule resource on which this policy will be applied.
},
],
"updateTime": "A String", # Output only. Represents the update timestamp.
},
],
"unreachable": [ # Unordered list. Lists locations that could not be reached.
"A String",
],
}
list_next(previous_request, previous_response)
Retrieves the next page of results. Args: previous_request: The request for the previous page. (required) previous_response: The response from the request for the previous page. (required) Returns: A request object that you can call 'execute()' on to request the next page. Returns None if there are no more items in the collection.
patch(name, body=None, requestId=None, updateMask=None, x__xgafv=None)
Updates the parameters of a single `RateLimitPolicy`.
Args:
name: string, Identifier. Specifies the name of the `RateLimitPolicy` resource. (required)
body: object, The request body.
The object takes the form of:
{ # Describes a `RateLimitPolicy` object.
"createTime": "A String", # Output only. Represents the create timestamp.
"description": "A String", # Optional. Provides a human-readable description of the resource.
"httpRules": [ # Optional. Specifies a list of rate limit HTTP rules to match against the incoming request.
{ # Specifies conditions to match against the incoming request.
"from": { # Describes properties of the sources of a request. # Optional. Describes properties of a source of a request.
"notSource": { # Describes the properties of a request source. # Optional. Describes the negated properties of request source. Matches requests from source that does not match the criteria specified in this field. At least one of source or not_source must be specified.
"principals": [ # Required. Contains a list of identities derived from the client's certificate. This field does not match on a request unless frontend mutual TLS is enabled for the Gateway and the client certificate is successfully validated by mTLS. Each identity is a string whose value is matched against a list of URI SANs, DNS Name SANs, or the common name in the client's certificate. A match happens when any principal matches with the rule.
{ # Describes the properties of a principal for matching.
"principal": { # Determines how a string value is matched. # Required. Matches a non-empty string against the principal value based on the principal_selector.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
"principalSelector": "A String", # Optional. Decides what principal value the principal rule will match against. If not specified, defaults to CLIENT_CERT_URI_SAN.
},
],
},
"source": { # Describes the properties of a request source. # Optional. Describes the properties of a request's source. At least one of source or not_source must be specified. A match occurs when ANY fields in either source or not_source matches the request. Within a single source, the match follows OR semantics across fields and AND semantics within a single field.
"principals": [ # Required. Contains a list of identities derived from the client's certificate. This field does not match on a request unless frontend mutual TLS is enabled for the Gateway and the client certificate is successfully validated by mTLS. Each identity is a string whose value is matched against a list of URI SANs, DNS Name SANs, or the common name in the client's certificate. A match happens when any principal matches with the rule.
{ # Describes the properties of a principal for matching.
"principal": { # Determines how a string value is matched. # Required. Matches a non-empty string against the principal value based on the principal_selector.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
"principalSelector": "A String", # Optional. Decides what principal value the principal rule will match against. If not specified, defaults to CLIENT_CERT_URI_SAN.
},
],
},
},
"rateLimitActions": [ # Optional. Specifies the actions to take when this rule is matched.
{ # Describes the action to take when the rate limit rule is matched.
"rateLimitBucket": "A String", # Required. Specifies the name of the rate limit bucket to apply when this rule is matched.
},
],
"to": { # Describes properties of the targets of a request. # Optional. Describes properties of a target of a request.
"destination": { # Describes properties of a request target. # Optional. Describes properties of a request's destination. At least one of destination or not_destination must be specified. A match occurs when ANY fields in either destination or not_destination matches the request. Within a destination, the match follows OR semantics across fields and AND semantics within a single field.
"headerSet": { # Describes a set of HTTP headers to match against. # Optional. Specifies a list of headers to match against in http header.
"headers": [ # Required. Contains a list of headers to match against in http header. The match can be one of exact, prefix, suffix, or contains (substring match). The match follows AND semantics which means all the headers must match. Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how an HTTP header is matched.
"name": "A String", # Optional. Specifies the name of the header in the request.
"value": { # Determines how a string value is matched. # Optional. Specifies how the header match is performed.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
},
],
},
"hosts": [ # Optional. Specifies a list of HTTP Hosts to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the hosts match, the operation is considered to be matched.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
"mcp": { # Describes a set of MCP protocol attributes to match against for a given MCP request. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it. # Optional. Specifies the MCP protocol attributes to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"baseProtocolMethodsOption": "A String", # Optional. If specified, matches on the MCP protocol’s non-access specific methods namely: * initialize * completion/ * logging/ * notifications/ * ping Defaults to SKIP_BASE_PROTOCOL_METHODS if not specified.
"methods": [ # Optional. A list of MCP methods and associated parameter names to match on. It is recommended to use this field to match on tools, prompts and resource accesses while setting the baseProtocolMethodsOption to MATCH_BASE_PROTOCOL_METHODS to match on all the other MCP protocol methods. Limited to 10 MCP methods per Rate Limit Policy.
{ # Describes a set of MCP methods to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"name": "A String", # Required. Specifies the MCP method to match against. Allowed values are as follows: 1. `tools`, `prompts`, `resources` - these will match against all sub methods under the respective methods. 2. `prompts/list`, `tools/list`, `resources/list`, `resources/templates/list` 3. `prompts/get`, `tools/call`, `resources/subscribe`, `resources/unsubscribe`, `resources/read` Params cannot be specified for categories 1 and 2.
"params": [ # Optional. Specifies a list of MCP method parameter names to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
],
},
"methods": [ # Optional. Specifies a list of HTTP methods to match against. Each entry must be a valid HTTP method name (GET, PUT, POST, HEAD, PATCH, DELETE, OPTIONS). It only allows exact match and is always case sensitive. The match follows OR semantics which means that if any of the methods match, the operation is considered to be matched.
"A String",
],
"paths": [ # Optional. Specifies a list of paths to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the paths match, the operation is considered to be matched. Note that this path match includes the query parameters. For gRPC services, this should be a fully-qualified name of the form /package.service/method.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
"notDestination": { # Describes properties of a request target. # Optional. Describes the negated properties of a request's destination. Matches requests for destination that does not match the criteria specified in this field. At least one of destination or not_destination must be specified.
"headerSet": { # Describes a set of HTTP headers to match against. # Optional. Specifies a list of headers to match against in http header.
"headers": [ # Required. Contains a list of headers to match against in http header. The match can be one of exact, prefix, suffix, or contains (substring match). The match follows AND semantics which means all the headers must match. Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how an HTTP header is matched.
"name": "A String", # Optional. Specifies the name of the header in the request.
"value": { # Determines how a string value is matched. # Optional. Specifies how the header match is performed.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
},
],
},
"hosts": [ # Optional. Specifies a list of HTTP Hosts to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the hosts match, the operation is considered to be matched.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
"mcp": { # Describes a set of MCP protocol attributes to match against for a given MCP request. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it. # Optional. Specifies the MCP protocol attributes to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"baseProtocolMethodsOption": "A String", # Optional. If specified, matches on the MCP protocol’s non-access specific methods namely: * initialize * completion/ * logging/ * notifications/ * ping Defaults to SKIP_BASE_PROTOCOL_METHODS if not specified.
"methods": [ # Optional. A list of MCP methods and associated parameter names to match on. It is recommended to use this field to match on tools, prompts and resource accesses while setting the baseProtocolMethodsOption to MATCH_BASE_PROTOCOL_METHODS to match on all the other MCP protocol methods. Limited to 10 MCP methods per Rate Limit Policy.
{ # Describes a set of MCP methods to match against. This field is only valid if the targeted Gateway or Forwarding Rule has an Agent Gateway attached to it.
"name": "A String", # Required. Specifies the MCP method to match against. Allowed values are as follows: 1. `tools`, `prompts`, `resources` - these will match against all sub methods under the respective methods. 2. `prompts/list`, `tools/list`, `resources/list`, `resources/templates/list` 3. `prompts/get`, `tools/call`, `resources/subscribe`, `resources/unsubscribe`, `resources/read` Params cannot be specified for categories 1 and 2.
"params": [ # Optional. Specifies a list of MCP method parameter names to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
],
},
"methods": [ # Optional. Specifies a list of HTTP methods to match against. Each entry must be a valid HTTP method name (GET, PUT, POST, HEAD, PATCH, DELETE, OPTIONS). It only allows exact match and is always case sensitive. The match follows OR semantics which means that if any of the methods match, the operation is considered to be matched.
"A String",
],
"paths": [ # Optional. Specifies a list of paths to match against. The match can be one of exact, prefix, suffix, or contains (substring match). Matches are always case sensitive unless the ignoreCase is set. The match follows OR semantics which means that if any of the paths match, the operation is considered to be matched. Note that this path match includes the query parameters. For gRPC services, this should be a fully-qualified name of the form /package.service/method.
{ # Determines how a string value is matched.
"contains": "A String", # Checks if the input string contains the substring specified here. Note: empty contains match is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc.def``
"exact": "A String", # Matches the input string exactly to the string specified here. Examples: * ``abc`` only matches the value ``abc``.
"ignoreCase": True or False, # Optional. Indicates if the exact/prefix/suffix/contains matching should be case insensitive. For example, when true, the matcher ``data`` matches both input strings ``Data`` and ``data``.
"prefix": "A String", # Checks if the input string has the prefix specified here. Note: empty prefix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``abc.xyz``
"suffix": "A String", # Checks if the input string has the suffix specified here. Note: empty suffix is not allowed, please use regex instead. Examples: * ``abc`` matches the value ``xyz.abc``
},
],
},
},
},
],
"labels": { # Optional. Stores labels as key value pairs.
"a_key": "A String",
},
"name": "A String", # Identifier. Specifies the name of the `RateLimitPolicy` resource.
"rateLimitBuckets": [ # Optional. Specifies a list of rate limit buckets to be used for rate limiting. Rate limit buckets will be referenced by the rate limit actions by name.
{ # Describes properties of a rate limit bucket.
"defaultLimit": { # Describes a limit for enforcement. # Required. Specifies the default limit to apply for this rate limit bucket.
"countLimit": { # Describes the count limit for enforcement. # Required. Defines the count limit to enforce.
"count": "A String", # Required. Specifies the maximum number of costs allowed in the specified interval. Must be non-negative.
"interval": "A String", # Required. Specifies the interval in units for which the count limit is enforced. Must be positive.
"intervalUnit": "A String", # Required. Specifies the unit of the interval. Defaults to MINUTES.
},
},
"dryRun": True or False, # Optional. Specifies whether the rate limit bucket is in dry-run mode.
"keys": [ # Required. Specifies the keys to use for rate limiting. At least one key is required. If multiple keys are specified, the keys will be combined and used as a single key.
{ # Describes properties of a key to use for rate limiting.
"header": "A String", # Optional. Specifies the header name if key_type is HTTP_HEADER.
"keyType": "A String", # Required. Specifies the type of key to use for rate limiting.
"principalType": "A String", # Optional. Specifies the principal type if key_type is PRINCIPAL.
},
],
"name": "A String", # Required. Specifies the name of the rate limit bucket. Name will be used to reference the bucket in the RateLimitAction.
"userOverrides": [ # Optional. Specifies a list of user overrides to apply to the rate limit bucket.
{ # Describes properties of a user override for the rate limit bucket.
"limit": { # Describes a limit for enforcement. # Required. Specifies the limit to apply for this specific key.
"countLimit": { # Describes the count limit for enforcement. # Required. Defines the count limit to enforce.
"count": "A String", # Required. Specifies the maximum number of costs allowed in the specified interval. Must be non-negative.
"interval": "A String", # Required. Specifies the interval in units for which the count limit is enforced. Must be positive.
"intervalUnit": "A String", # Required. Specifies the unit of the interval. Defaults to MINUTES.
},
},
"overrideKey": { # Specifies the key to override. Key fields must match the key types specified in the rate limit bucket. Key type ALL does not support overrides. # Required. Specifies the key to override.
"httpHeaders": [ # Optional. Specifies the HTTP headers if the rate limit bucket keys contain keys of type HTTP_HEADER. Number of headers and header names must match the rate limit bucket key.
{ # Specifies the key in the type HTTP header to override.
"header": "A String", # Required. Specifies the header name of the key.
"value": "A String", # Required. Specifies the header value of the key.
},
],
"httpPath": "A String", # Optional. Specifies the HTTP path if the rate limit bucket keys contain a key of type HTTP_PATH.
"mcpTool": "A String", # Optional. Specifies the MCP tool if the rate limit bucket keys contain a key of type MCP_TOOL.
"principals": [ # Optional. Specifies the principals if the rate limit bucket keys contain keys of PRINCIPAL. Number of principals and principal types must match the rate limit bucket key.
{ # Specifies the key in the type PRINCIPAL to override.
"principal": "A String", # Required. Specifies the principal value of the key.
"principalType": "A String", # Required. Specifies the principal type of the key.
},
],
"sourceIp": "A String", # Optional. Specifies the source IP if the rate limit bucket keys contain a key of type SOURCE_IP.
},
},
],
},
],
"targets": [ # Required. Specifies a list of targets to which this policy applies.
{ # Specifies the target to which this policy applies.
"resource": "A String", # Required. Reference to a Gateway or Forwarding Rule resource on which this policy will be applied.
},
],
"updateTime": "A String", # Output only. Represents the update timestamp.
}
requestId: string, Optional. Specifies an optional request ID to identify requests. Specify a unique request ID so that if you must retry your request, the server will know to ignore the request if it has already been completed. The server will guarantee that for at least 60 minutes since the first request. For example, consider a situation where you make an initial request and the request times out. If you make the request again with the same request ID, the server can check if original operation with the same request ID was received, and if so, will ignore the second request. This prevents clients from accidentally creating duplicate commitments. The request ID must be a valid UUID with the exception that zero UUID is not supported (00000000-0000-0000-0000-000000000000).
updateMask: string, Optional. Specifies the fields to be overwritten in the `RateLimitPolicy` resource by the update. The fields specified in the update_mask are relative to the resource, not the full request. A field will be overwritten if it is in the mask. If the user does not provide a mask then all fields present in the request will be overwritten.
x__xgafv: string, V1 error format.
Allowed values
1 - v1 error format
2 - v2 error format
Returns:
An object of the form:
{ # This resource represents a long-running operation that is the result of a network API call.
"done": True or False, # If the value is `false`, it means the operation is still in progress. If `true`, the operation is completed, and either `error` or `response` is available.
"error": { # The `Status` type defines a logical error model that is suitable for different programming environments, including REST APIs and RPC APIs. It is used by [gRPC](https://github.com/grpc). Each `Status` message contains three pieces of data: error code, error message, and error details. You can find out more about this error model and how to work with it in the [API Design Guide](https://cloud.google.com/apis/design/errors). # The error result of the operation in case of failure or cancellation.
"code": 42, # The status code, which should be an enum value of google.rpc.Code.
"details": [ # A list of messages that carry the error details. There is a common set of message types for APIs to use.
{
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
],
"message": "A String", # A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the google.rpc.Status.details field, or localized by the client.
},
"metadata": { # Service-specific metadata associated with the operation. It typically contains progress information and common metadata such as create time. Some services might not provide such metadata. Any method that returns a long-running operation should document the metadata type, if any.
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
"name": "A String", # The server-assigned name, which is only unique within the same service that originally returns it. If you use the default HTTP mapping, the `name` should be a resource name ending with `operations/{unique_id}`.
"response": { # The normal, successful response of the operation. If the original method returns no data on success, such as `Delete`, the response is `google.protobuf.Empty`. If the original method is standard `Get`/`Create`/`Update`, the response should be the resource. For other methods, the response should have the type `XxxResponse`, where `Xxx` is the original method name. For example, if the original method name is `TakeSnapshot()`, the inferred response type is `TakeSnapshotResponse`.
"a_key": "", # Properties of the object. Contains field @type with type URL.
},
}