Skip to content

network_containment_allowlist_rule

Manages a network containment allowlist rule. Contained hosts can always communicate with the IP ranges, DNS servers, and FQDNs on the allowlist. fqdn rules require at least one ip_dns rule: the API rejects creating an fqdn rule when no ip_dns rule exists, and rejects deleting the last ip_dns rule while any fqdn rule remains. When both are managed in the same configuration, add depends_on from each fqdn rule to an ip_dns rule so Terraform creates the DNS rule first and destroys it last.

The following API scopes are required:

  • Network Containment Allowlist: READ
  • Network Containment Allowlist: WRITE
terraform {
required_providers {
crowdstrike = {
source = "registry.terraform.io/crowdstrike/crowdstrike"
}
}
}
provider "crowdstrike" {
cloud = "us-2"
}
# Allow contained hosts to reach an internal remediation subnet.
resource "crowdstrike_network_containment_allowlist_rule" "remediation_subnet" {
type = "ip_range"
rule = "10.20.0.0/16"
name = "Remediation subnet"
}
# FQDN rules need a DNS server rule so contained hosts can resolve the domain.
resource "crowdstrike_network_containment_allowlist_rule" "dns" {
type = "ip_dns"
rule = "10.0.0.53"
name = "Corporate DNS"
}
resource "crowdstrike_network_containment_allowlist_rule" "updates" {
type = "fqdn"
rule = "updates.example.com"
name = "Patch server"
allow_subdomains = true
# Create the DNS rule first and destroy it last; the API rejects an fqdn
# rule when no ip_dns rule exists.
depends_on = [crowdstrike_network_containment_allowlist_rule.dns]
}
  • name (String) Name of the allowlist rule.
  • rule (String) Value to allow: an IPv4 or IPv6 address or CIDR block for ip_range, an IPv4 or IPv6 address for ip_dns, or a domain such as updates.example.com for fqdn. The value is stored exactly as given. Changing this value forces a new resource.
  • type (String) Rule type. One of ip_range (an IP address or CIDR block), ip_dns (a DNS server contained hosts may use for domain resolution, shown as DNS in the Falcon console), or fqdn (a domain contained hosts may reach). Changing this value forces a new resource.
  • allow_subdomains (Boolean) Also allow one level of subdomains beyond the domain. For example, allowing subdomains for example.com allows calendar.example.com and mail.example.com, but not my.maps.example.com. Only valid for fqdn rules. Defaults to false. Some services let anyone register a subdomain, which then resolves to infrastructure that subdomain’s owner controls. Changing this value forces a new resource.
  • id (String) Identifier of the allowlist rule, derived from the rule: containment|<rule> for ip_range and fqdn rules, and containment|dns|<rule> for ip_dns rules.

Import is supported using the following syntax:

Terminal window
# Network containment allowlist rules can be imported by their id: containment|<rule>
# for ip_range and fqdn rules, or containment|dns|<rule> for ip_dns rules.
terraform import crowdstrike_network_containment_allowlist_rule.example 'containment|10.20.0.0/16'
terraform import crowdstrike_network_containment_allowlist_rule.dns 'containment|dns|10.0.0.53'