
DigitalOcean Create
CertifiedCreate a DigitalOcean firewall
DigitalOcean Create
Create a DigitalOcean firewall
Creates a new cloud firewall with inbound and outbound rules, optionally applied to a set of droplets.
type: io.kestra.plugin.digitalocean.firewall.CreateExamples
Create a firewall allowing inbound SSH and HTTP, and all outbound traffic
id: digitalocean_create_firewall
namespace: company.team
tasks:
- id: create_firewall
type: io.kestra.plugin.digitalocean.firewall.Create
apiToken: "{{ secret('DIGITALOCEAN_TOKEN') }}"
name: "web-firewall"
inboundRules:
- protocol: "tcp"
ports: "22"
sources:
addresses: ["0.0.0.0/0", "::/0"]
- protocol: "tcp"
ports: "80"
sources:
addresses: ["0.0.0.0/0", "::/0"]
outboundRules:
- protocol: "tcp"
ports: "1-65535"
destinations:
addresses: ["0.0.0.0/0", "::/0"]
dropletIds:
- 3164444
Properties
apiToken *Requiredstring
DigitalOcean API token
Personal access token used to authenticate against the DigitalOcean API v2, sent as Authorization: Bearer <token>. Create one (prefixed dop_v1_) in the DigitalOcean control panel under API > Tokens, and store it as a Kestra secret.
inboundRules *Requiredarray
Inbound rules
Inbound rules, each with protocol (tcp, udp, or icmp), ports, and a sources object (addresses, droplet_ids, tags, or load_balancer_uids).
name *Requiredstring
Firewall name
Human-readable name for the firewall, must be unique on the account.
outboundRules *Requiredarray
Outbound rules
Outbound rules, each with protocol (tcp, udp, or icmp), ports, and a destinations object (addresses, droplet_ids, tags, or load_balancer_uids).
baseUrl string
https://api.digitalocean.comDigitalOcean API base URL
Base endpoint for all DigitalOcean API calls. Defaults to https://api.digitalocean.com.
dropletIds array
Droplet IDs
Numeric IDs of the droplets to apply the firewall to.
options Non-dynamic
HTTP client options
Optional HTTP configuration (timeouts, proxy, SSL) applied to every DigitalOcean API call.
io.kestra.core.http.client.configurations.HttpConfiguration
falseIf true, allow a failed response code (response code >= 400)
List of response code allowed for this request
The authentication to use.
io.kestra.core.http.client.configurations.BasicAuthConfiguration
The password for HTTP basic authentication.
The username for HTTP basic authentication.
io.kestra.core.http.client.configurations.BearerAuthConfiguration
The token for bearer token authentication.
io.kestra.core.http.client.configurations.DigestAuthConfiguration
The password for HTTP Digest authentication.
The username for HTTP Digest authentication.
The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
durationThe time allowed to establish a connection to the server before failing.
durationThe time an idle connection can remain in the client's connection pool before being closed.
UTF-8The default charset for the request.
java.nio.charset.Charset
trueWhether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).
Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.
trueWhether redirects should be followed automatically.
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIEDThe log level for the HTTP client.
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODYThe enabled log.
The maximum content length of the response.
The proxy configuration.
io.kestra.core.http.client.configurations.ProxyConfiguration
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTDIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
durationThe time allowed for a read connection to remain idle before closing it.
durationThe maximum time allowed for reading data from the server before failing.
The SSL request options
io.kestra.core.http.client.configurations.SslOptions
Whether to disable checking of the remote SSL certificate.
Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.
The timeout configuration.
io.kestra.core.http.client.configurations.TimeoutConfiguration
The time allowed to establish a connection to the server before failing.
PT5MThe time allowed for a read connection to remain idle before closing it.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
Outputs
createdAt string
date-timeCreation timestamp
id string
Firewall ID
UUID assigned by DigitalOcean.
name string
Firewall name
status string
Firewall status
One of waiting, succeeded, or failed.