Help Center/ TaurusDB/ API Reference/ APIs (Recommended)/ Database Proxy/ Configuring Access Control Rules
Updated on 2025-10-21 GMT+08:00

Configuring Access Control Rules

Function

This API is used to configure access control rules. Before calling this API:

Calling Method

For details, see Calling APIs.

Authorization Information

Each account has all the permissions required to call all APIs, but IAM users must be assigned the required permissions.

  • If you are using role/policy-based authorization, see Permissions Policies and Supported Actions for details on the required permissions.
  • If you are using identity policy-based authorization, the following identity policy-based permissions are required.

    Action

    Access Level

    Resource Type (*: required)

    Condition Key

    Alias

    Dependency

    gaussdbformysql:proxy:modifyAccess

    Permission_management

    instance *

    • g:EnterpriseProjectId

    • g:ResourceTag/<tag-key>

    • gaussdb:instance:modifyProxy
    • gaussdb:proxy:modifyAccess

    -

URI

POST /v3/{project_id}/instances/{instance_id}/proxy/{proxy_id}/access-control

Table 1 URI parameters

Parameter

Mandatory

Type

Description

project_id

Yes

String

Definition

Project ID of a tenant in a region.

To obtain this value, see Obtaining a Project ID.

Constraints

N/A

Range

The value contains 32 characters. Only letters and digits are allowed.

Default Value

N/A

instance_id

Yes

String

Definition

Instance ID, which uniquely identifies an instance.

Constraints

N/A

Range

The value contains 36 characters with a suffix of in07. Only letters and digits are allowed.

Default Value

N/A

proxy_id

Yes

String

Definition

Proxy instance ID, which is compliant with the UUID format.

Constraints

N/A

Range

The value contains 36 characters with a suffix of po01. Only letters and digits are allowed.

Default Value

N/A

Request Parameters

Table 2 Request header parameters

Parameter

Mandatory

Type

Description

X-Auth-Token

Yes

String

Definition

User token. To obtain this value, call the IAM API for obtaining a user token.

The value of X-Subject-Token in the response header is the token value.

Constraints

N/A

Range

N/A

Default Value

N/A

X-Language

No

String

Definition

Request language type.

Constraints

N/A

Range

  • en-us

  • zh-cn

Default Value

en-us

Table 3 Request body parameters

Parameter

Mandatory

Type

Description

type

Yes

String

Definition

Access control method.

Constraints

N/A

Range

  • white: whitelist

  • black: blacklist

Default Value

N/A

ip_list

Yes

Array of AccessControlRule objects

Definition

Array of IP addresses that control access.

Constraints

A maximum of 300 IP addresses or CIDR blocks can be added.

Range

N/A

Default Value

N/A

Table 4 AccessControlRule

Parameter

Mandatory

Type

Description

ip

Yes

String

Definition

IP address or CIDR block.

Default Value

N/A

description

No

String

Definition

Remarks.

Range

Character length: 0–50. Angle brackets (<>) are not allowed.

Response Parameters

Status code: 200

Table 5 Response body parameter

Parameter

Type

Description

open_access_control

Boolean

Definition

Whether access control is enabled.

Range

  • true: enabled

  • false: disabled

Status code: 400

Table 6 Response body parameters

Parameter

Type

Description

error_code

String

Error code.

error_msg

String

Error message.

Status code: 500

Table 7 Response body parameters

Parameter

Type

Description

error_code

String

Error code.

error_msg

String

Error message.

Example Request

Configuring access control rules

POST https://{endpoint}/v3/0483b6b16e954cb88930a360d2c4e663/instances/61a4ea66210545909d74a05c27a7179ein07/proxy/e87088f0b6a345e79db19d57c41fde15po01/access-control

{
  "type" : "black",
  "ip_list" : [ {
    "ip" : "192.107.0.1",
    "description" : "black01"
  } ]
}

Example Response

Status code: 200

Success.

{
  "open_access_control" : false
}

Status Code

For details, see Status Codes.

Error Code

For details, see Error Codes.