public final class BackendServiceTlsSettings extends GeneratedMessage implements BackendServiceTlsSettingsOrBuilder
Protobuf type google.cloud.compute.v1.BackendServiceTlsSettings
Inherited Members
com.google.protobuf.GeneratedMessage.<ContainingT,T>newFileScopedGeneratedExtension(java.lang.Class<?>,com.google.protobuf.Message)
com.google.protobuf.GeneratedMessage.<ContainingT,T>newMessageScopedGeneratedExtension(com.google.protobuf.Message,int,java.lang.Class<?>,com.google.protobuf.Message)
com.google.protobuf.GeneratedMessage.<ListT>makeMutableCopy(ListT)
com.google.protobuf.GeneratedMessage.<ListT>makeMutableCopy(ListT,int)
com.google.protobuf.GeneratedMessage.<T>emptyList(java.lang.Class<T>)
com.google.protobuf.GeneratedMessage.<V>serializeBooleanMapTo(com.google.protobuf.CodedOutputStream,com.google.protobuf.MapField<java.lang.Boolean,V>,com.google.protobuf.MapEntry<java.lang.Boolean,V>,int)
com.google.protobuf.GeneratedMessage.<V>serializeIntegerMapTo(com.google.protobuf.CodedOutputStream,com.google.protobuf.MapField<java.lang.Integer,V>,com.google.protobuf.MapEntry<java.lang.Integer,V>,int)
com.google.protobuf.GeneratedMessage.<V>serializeLongMapTo(com.google.protobuf.CodedOutputStream,com.google.protobuf.MapField<java.lang.Long,V>,com.google.protobuf.MapEntry<java.lang.Long,V>,int)
com.google.protobuf.GeneratedMessage.<V>serializeStringMapTo(com.google.protobuf.CodedOutputStream,com.google.protobuf.MapField<java.lang.String,V>,com.google.protobuf.MapEntry<java.lang.String,V>,int)
com.google.protobuf.GeneratedMessage.canUseUnsafe()
com.google.protobuf.GeneratedMessage.emptyBooleanList()
com.google.protobuf.GeneratedMessage.emptyDoubleList()
com.google.protobuf.GeneratedMessage.emptyFloatList()
com.google.protobuf.GeneratedMessage.emptyIntList()
com.google.protobuf.GeneratedMessage.emptyLongList()
com.google.protobuf.GeneratedMessage.internalGetMapFieldReflection(int)
com.google.protobuf.GeneratedMessage.isStringEmpty(java.lang.Object)
com.google.protobuf.GeneratedMessage.mergeFromAndMakeImmutableInternal(com.google.protobuf.CodedInputStream,com.google.protobuf.ExtensionRegistryLite)
com.google.protobuf.GeneratedMessage.newInstance(com.google.protobuf.GeneratedMessage.UnusedPrivateParameter)
com.google.protobuf.GeneratedMessage.parseUnknownFieldProto3(com.google.protobuf.CodedInputStream,com.google.protobuf.UnknownFieldSet.Builder,com.google.protobuf.ExtensionRegistryLite,int)
Static Fields
AUTHENTICATION_CONFIG_FIELD_NUMBER
public static final int AUTHENTICATION_CONFIG_FIELD_NUMBER
| Field Value |
| Type |
Description |
int |
|
IDENTITY_FIELD_NUMBER
public static final int IDENTITY_FIELD_NUMBER
| Field Value |
| Type |
Description |
int |
|
SNI_FIELD_NUMBER
public static final int SNI_FIELD_NUMBER
| Field Value |
| Type |
Description |
int |
|
SUBJECT_ALT_NAMES_FIELD_NUMBER
public static final int SUBJECT_ALT_NAMES_FIELD_NUMBER
| Field Value |
| Type |
Description |
int |
|
Static Methods
getDefaultInstance()
public static BackendServiceTlsSettings getDefaultInstance()
getDescriptor()
public static final Descriptors.Descriptor getDescriptor()
newBuilder()
public static BackendServiceTlsSettings.Builder newBuilder()
newBuilder(BackendServiceTlsSettings prototype)
public static BackendServiceTlsSettings.Builder newBuilder(BackendServiceTlsSettings prototype)
public static BackendServiceTlsSettings parseDelimitedFrom(InputStream input)
public static BackendServiceTlsSettings parseDelimitedFrom(InputStream input, ExtensionRegistryLite extensionRegistry)
parseFrom(byte[] data)
public static BackendServiceTlsSettings parseFrom(byte[] data)
| Parameter |
| Name |
Description |
data |
byte[]
|
parseFrom(byte[] data, ExtensionRegistryLite extensionRegistry)
public static BackendServiceTlsSettings parseFrom(byte[] data, ExtensionRegistryLite extensionRegistry)
parseFrom(ByteString data)
public static BackendServiceTlsSettings parseFrom(ByteString data)
parseFrom(ByteString data, ExtensionRegistryLite extensionRegistry)
public static BackendServiceTlsSettings parseFrom(ByteString data, ExtensionRegistryLite extensionRegistry)
public static BackendServiceTlsSettings parseFrom(CodedInputStream input)
public static BackendServiceTlsSettings parseFrom(CodedInputStream input, ExtensionRegistryLite extensionRegistry)
public static BackendServiceTlsSettings parseFrom(InputStream input)
public static BackendServiceTlsSettings parseFrom(InputStream input, ExtensionRegistryLite extensionRegistry)
parseFrom(ByteBuffer data)
public static BackendServiceTlsSettings parseFrom(ByteBuffer data)
parseFrom(ByteBuffer data, ExtensionRegistryLite extensionRegistry)
public static BackendServiceTlsSettings parseFrom(ByteBuffer data, ExtensionRegistryLite extensionRegistry)
parser()
public static Parser<BackendServiceTlsSettings> parser()
Methods
equals(Object obj)
public boolean equals(Object obj)
| Parameter |
| Name |
Description |
obj |
Object
|
Overrides
getAuthenticationConfig()
public String getAuthenticationConfig()
Reference to the BackendAuthenticationConfig resource from the
networksecurity.googleapis.com namespace. Can be used in authenticating
TLS connections to the backend, as specified by the authenticationMode
field. Can only be specified if authenticationMode is not NONE.
optional string authentication_config = 408053481;
| Returns |
| Type |
Description |
String |
The authenticationConfig.
|
getAuthenticationConfigBytes()
public ByteString getAuthenticationConfigBytes()
Reference to the BackendAuthenticationConfig resource from the
networksecurity.googleapis.com namespace. Can be used in authenticating
TLS connections to the backend, as specified by the authenticationMode
field. Can only be specified if authenticationMode is not NONE.
optional string authentication_config = 408053481;
| Returns |
| Type |
Description |
ByteString |
The bytes for authenticationConfig.
|
getDefaultInstanceForType()
public BackendServiceTlsSettings getDefaultInstanceForType()
getIdentity()
public String getIdentity()
Assigns the Managed Identity for the BackendService Workload.
Use this property to configure the load balancer back-end to use
certificates and roots of trust provisioned by the Managed Workload
Identity system.
The identity property is the
fully-specified SPIFFE ID to use in the SVID presented by the Load
Balancer Workload.
The SPIFFE ID must be a resource starting with the
trustDomain property value, followed by the path to the Managed
Workload Identity.
Supported SPIFFE ID format:
- //<trust_domain>/ns/<namespace>/sa/<subject>
The Trust Domain within the Managed Identity must refer to a valid
Workload Identity Pool. The TrustConfig and CertificateIssuanceConfig
will be inherited from the Workload Identity Pool.
Restrictions:
- If you set the
identity property, you cannot manually set
the following fields:
- tlsSettings.sni
- tlsSettings.subjectAltNames
- tlsSettings.authenticationConfig
When defining a identity for a RegionBackendServices, the
corresponding Workload Identity Pool must have a ca_pool
configured in the same region.
The system will set up a read-onlytlsSettings.authenticationConfig for the Managed Identity.
optional string identity = 401109182;
| Returns |
| Type |
Description |
String |
The identity.
|
getIdentityBytes()
public ByteString getIdentityBytes()
Assigns the Managed Identity for the BackendService Workload.
Use this property to configure the load balancer back-end to use
certificates and roots of trust provisioned by the Managed Workload
Identity system.
The identity property is the
fully-specified SPIFFE ID to use in the SVID presented by the Load
Balancer Workload.
The SPIFFE ID must be a resource starting with the
trustDomain property value, followed by the path to the Managed
Workload Identity.
Supported SPIFFE ID format:
- //<trust_domain>/ns/<namespace>/sa/<subject>
The Trust Domain within the Managed Identity must refer to a valid
Workload Identity Pool. The TrustConfig and CertificateIssuanceConfig
will be inherited from the Workload Identity Pool.
Restrictions:
- If you set the
identity property, you cannot manually set
the following fields:
- tlsSettings.sni
- tlsSettings.subjectAltNames
- tlsSettings.authenticationConfig
When defining a identity for a RegionBackendServices, the
corresponding Workload Identity Pool must have a ca_pool
configured in the same region.
The system will set up a read-onlytlsSettings.authenticationConfig for the Managed Identity.
optional string identity = 401109182;
| Returns |
| Type |
Description |
ByteString |
The bytes for identity.
|
getParserForType()
public Parser<BackendServiceTlsSettings> getParserForType()
Overrides
getSerializedSize()
public int getSerializedSize()
| Returns |
| Type |
Description |
int |
|
Overrides
getSni()
Server Name Indication - see RFC3546 section 3.1. If set, the load
balancer sends this string as the SNI hostname in the TLS connection to
the backend, and requires that this string match a Subject Alternative
Name (SAN) in the backend's server certificate. With a Regional Internet
NEG backend, if the SNI is specified here, the load balancer uses it
regardless of whether the Regional Internet NEG is specified with FQDN or
IP address and port. When both sni and subjectAltNames[] are specified,
the load balancer matches the backend certificate's SAN only to
subjectAltNames[].
optional string sni = 114030;
| Returns |
| Type |
Description |
String |
The sni.
|
getSniBytes()
public ByteString getSniBytes()
Server Name Indication - see RFC3546 section 3.1. If set, the load
balancer sends this string as the SNI hostname in the TLS connection to
the backend, and requires that this string match a Subject Alternative
Name (SAN) in the backend's server certificate. With a Regional Internet
NEG backend, if the SNI is specified here, the load balancer uses it
regardless of whether the Regional Internet NEG is specified with FQDN or
IP address and port. When both sni and subjectAltNames[] are specified,
the load balancer matches the backend certificate's SAN only to
subjectAltNames[].
optional string sni = 114030;
| Returns |
| Type |
Description |
ByteString |
The bytes for sni.
|
getSubjectAltNames(int index)
public BackendServiceTlsSettingsSubjectAltName getSubjectAltNames(int index)
A list of Subject Alternative Names (SANs) that the Load Balancer
verifies during a TLS handshake with the backend. When the server
presents its X.509 certificate to the Load Balancer, the Load Balancer
inspects the certificate's SAN field, and requires that at least one SAN
match one of the subjectAltNames in the list. This field is limited to 5
entries. When both sni and subjectAltNames[] are specified, the load
balancer matches the backend certificate's SAN only to subjectAltNames[].
repeated .google.cloud.compute.v1.BackendServiceTlsSettingsSubjectAltName subject_alt_names = 330029535;
| Parameter |
| Name |
Description |
index |
int
|
getSubjectAltNamesCount()
public int getSubjectAltNamesCount()
A list of Subject Alternative Names (SANs) that the Load Balancer
verifies during a TLS handshake with the backend. When the server
presents its X.509 certificate to the Load Balancer, the Load Balancer
inspects the certificate's SAN field, and requires that at least one SAN
match one of the subjectAltNames in the list. This field is limited to 5
entries. When both sni and subjectAltNames[] are specified, the load
balancer matches the backend certificate's SAN only to subjectAltNames[].
repeated .google.cloud.compute.v1.BackendServiceTlsSettingsSubjectAltName subject_alt_names = 330029535;
| Returns |
| Type |
Description |
int |
|
getSubjectAltNamesList()
public List<BackendServiceTlsSettingsSubjectAltName> getSubjectAltNamesList()
A list of Subject Alternative Names (SANs) that the Load Balancer
verifies during a TLS handshake with the backend. When the server
presents its X.509 certificate to the Load Balancer, the Load Balancer
inspects the certificate's SAN field, and requires that at least one SAN
match one of the subjectAltNames in the list. This field is limited to 5
entries. When both sni and subjectAltNames[] are specified, the load
balancer matches the backend certificate's SAN only to subjectAltNames[].
repeated .google.cloud.compute.v1.BackendServiceTlsSettingsSubjectAltName subject_alt_names = 330029535;
getSubjectAltNamesOrBuilder(int index)
public BackendServiceTlsSettingsSubjectAltNameOrBuilder getSubjectAltNamesOrBuilder(int index)
A list of Subject Alternative Names (SANs) that the Load Balancer
verifies during a TLS handshake with the backend. When the server
presents its X.509 certificate to the Load Balancer, the Load Balancer
inspects the certificate's SAN field, and requires that at least one SAN
match one of the subjectAltNames in the list. This field is limited to 5
entries. When both sni and subjectAltNames[] are specified, the load
balancer matches the backend certificate's SAN only to subjectAltNames[].
repeated .google.cloud.compute.v1.BackendServiceTlsSettingsSubjectAltName subject_alt_names = 330029535;
| Parameter |
| Name |
Description |
index |
int
|
getSubjectAltNamesOrBuilderList()
public List<? extends BackendServiceTlsSettingsSubjectAltNameOrBuilder> getSubjectAltNamesOrBuilderList()
A list of Subject Alternative Names (SANs) that the Load Balancer
verifies during a TLS handshake with the backend. When the server
presents its X.509 certificate to the Load Balancer, the Load Balancer
inspects the certificate's SAN field, and requires that at least one SAN
match one of the subjectAltNames in the list. This field is limited to 5
entries. When both sni and subjectAltNames[] are specified, the load
balancer matches the backend certificate's SAN only to subjectAltNames[].
repeated .google.cloud.compute.v1.BackendServiceTlsSettingsSubjectAltName subject_alt_names = 330029535;
| Returns |
| Type |
Description |
List<? extends com.google.cloud.compute.v1.BackendServiceTlsSettingsSubjectAltNameOrBuilder> |
|
hasAuthenticationConfig()
public boolean hasAuthenticationConfig()
Reference to the BackendAuthenticationConfig resource from the
networksecurity.googleapis.com namespace. Can be used in authenticating
TLS connections to the backend, as specified by the authenticationMode
field. Can only be specified if authenticationMode is not NONE.
optional string authentication_config = 408053481;
| Returns |
| Type |
Description |
boolean |
Whether the authenticationConfig field is set.
|
hasIdentity()
public boolean hasIdentity()
Assigns the Managed Identity for the BackendService Workload.
Use this property to configure the load balancer back-end to use
certificates and roots of trust provisioned by the Managed Workload
Identity system.
The identity property is the
fully-specified SPIFFE ID to use in the SVID presented by the Load
Balancer Workload.
The SPIFFE ID must be a resource starting with the
trustDomain property value, followed by the path to the Managed
Workload Identity.
Supported SPIFFE ID format:
- //<trust_domain>/ns/<namespace>/sa/<subject>
The Trust Domain within the Managed Identity must refer to a valid
Workload Identity Pool. The TrustConfig and CertificateIssuanceConfig
will be inherited from the Workload Identity Pool.
Restrictions:
- If you set the
identity property, you cannot manually set
the following fields:
- tlsSettings.sni
- tlsSettings.subjectAltNames
- tlsSettings.authenticationConfig
When defining a identity for a RegionBackendServices, the
corresponding Workload Identity Pool must have a ca_pool
configured in the same region.
The system will set up a read-onlytlsSettings.authenticationConfig for the Managed Identity.
optional string identity = 401109182;
| Returns |
| Type |
Description |
boolean |
Whether the identity field is set.
|
hasSni()
Server Name Indication - see RFC3546 section 3.1. If set, the load
balancer sends this string as the SNI hostname in the TLS connection to
the backend, and requires that this string match a Subject Alternative
Name (SAN) in the backend's server certificate. With a Regional Internet
NEG backend, if the SNI is specified here, the load balancer uses it
regardless of whether the Regional Internet NEG is specified with FQDN or
IP address and port. When both sni and subjectAltNames[] are specified,
the load balancer matches the backend certificate's SAN only to
subjectAltNames[].
optional string sni = 114030;
| Returns |
| Type |
Description |
boolean |
Whether the sni field is set.
|
hashCode()
| Returns |
| Type |
Description |
int |
|
Overrides
internalGetFieldAccessorTable()
protected GeneratedMessage.FieldAccessorTable internalGetFieldAccessorTable()
Overrides
isInitialized()
public final boolean isInitialized()
Overrides
newBuilderForType()
public BackendServiceTlsSettings.Builder newBuilderForType()
newBuilderForType(AbstractMessage.BuilderParent parent)
protected BackendServiceTlsSettings.Builder newBuilderForType(AbstractMessage.BuilderParent parent)
Overrides
toBuilder()
public BackendServiceTlsSettings.Builder toBuilder()
writeTo(CodedOutputStream output)
public void writeTo(CodedOutputStream output)
Overrides