network_containment_allowlist_rule
Manages a network containment allowlist rule. Contained hosts can always communicate with the IP ranges, DNS servers, and FQDNs on the allowlist. fqdn rules require at least one ip_dns rule: the API rejects creating an fqdn rule when no ip_dns rule exists, and rejects deleting the last ip_dns rule while any fqdn rule remains. When both are managed in the same configuration, add depends_on from each fqdn rule to an ip_dns rule so Terraform creates the DNS rule first and destroys it last.
API Scopes
Section titled “API Scopes”The following API scopes are required:
- Network Containment Allowlist: READ
- Network Containment Allowlist: WRITE
Example Usage
Section titled “Example Usage”terraform { required_providers { crowdstrike = { source = "registry.terraform.io/crowdstrike/crowdstrike" } }}
provider "crowdstrike" { cloud = "us-2"}
# Allow contained hosts to reach an internal remediation subnet.resource "crowdstrike_network_containment_allowlist_rule" "remediation_subnet" { type = "ip_range" rule = "10.20.0.0/16" name = "Remediation subnet"}
# FQDN rules need a DNS server rule so contained hosts can resolve the domain.resource "crowdstrike_network_containment_allowlist_rule" "dns" { type = "ip_dns" rule = "10.0.0.53" name = "Corporate DNS"}
resource "crowdstrike_network_containment_allowlist_rule" "updates" { type = "fqdn" rule = "updates.example.com" name = "Patch server" allow_subdomains = true
# Create the DNS rule first and destroy it last; the API rejects an fqdn # rule when no ip_dns rule exists. depends_on = [crowdstrike_network_containment_allowlist_rule.dns]}Schema
Section titled “Schema”Required
Section titled “Required”name(String) Name of the allowlist rule.rule(String) Value to allow: an IPv4 or IPv6 address or CIDR block forip_range, an IPv4 or IPv6 address forip_dns, or a domain such asupdates.example.comforfqdn. The value is stored exactly as given. Changing this value forces a new resource.type(String) Rule type. One ofip_range(an IP address or CIDR block),ip_dns(a DNS server contained hosts may use for domain resolution, shown as DNS in the Falcon console), orfqdn(a domain contained hosts may reach). Changing this value forces a new resource.
Optional
Section titled “Optional”allow_subdomains(Boolean) Also allow one level of subdomains beyond the domain. For example, allowing subdomains forexample.comallowscalendar.example.comandmail.example.com, but notmy.maps.example.com. Only valid forfqdnrules. Defaults tofalse. Some services let anyone register a subdomain, which then resolves to infrastructure that subdomain’s owner controls. Changing this value forces a new resource.
Read-Only
Section titled “Read-Only”id(String) Identifier of the allowlist rule, derived from the rule:containment|<rule>forip_rangeandfqdnrules, andcontainment|dns|<rule>forip_dnsrules.
Import
Section titled “Import”Import is supported using the following syntax:
# Network containment allowlist rules can be imported by their id: containment|<rule># for ip_range and fqdn rules, or containment|dns|<rule> for ip_dns rules.terraform import crowdstrike_network_containment_allowlist_rule.example 'containment|10.20.0.0/16'terraform import crowdstrike_network_containment_allowlist_rule.dns 'containment|dns|10.0.0.53'