Skip to main content

network_rules

Creates, updates, deletes, gets or lists a network_rules resource.

Overview

Namenetwork_rules
TypeResource
Idsnowflake.security.network_rules

Fields

The following fields are returned by SELECT queries:

successful

NameDatatypeDescription
namestringName of the network rule (pattern: ^"([^"]|"")+"|[a-zA-Z_][a-zA-Z0-9_$]*$)
database_namestringDatabase in which the network rule is stored (pattern: ^"([^"]|"")+"|[a-zA-Z_][a-zA-Z0-9_$]*$)
schema_namestringSchema in which the network rule is stored (pattern: ^"([^"]|"")+"|[a-zA-Z_][a-zA-Z0-9_$]*$)
commentstringComment for the network rule
created_onstring (date-time)Date and time when the network rule was created
modestringSpecifies what is restricted by the network rule. Possible values: INGRESS, INTERNAL_STAGE, EGRESS
ownerstringRole that owns the network rule (pattern: ^"([^"]|"")+"|[a-zA-Z_][a-zA-Z0-9_$]*$)
owner_role_typestringThe type of role that owns the network rule
typestringType of the network rule
value_listarrayList of values in a network rule

Methods

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectdatabase_name, schema_name, name, endpointFetch a network rule
listselectdatabase_name, schema_name, endpointlike, startsWith, showLimit, fromNameList network rules
createinsertdatabase_name, schema_name, endpoint, type, namecreateModeCreate a network rule
deletedeletedatabase_name, schema_name, name, endpointifExistsDelete a network rule

Parameters

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
database_namestringIdentifier (i.e. name) for the database to which the resource belongs. You can use the /api/v2/databases GET request to get a list of available databases.
endpointstringOrganization and account identifier (orgname-accountname) (default: orgname-accountname)
namestringIdentifier (i.e. name) for the resource.
schema_namestringIdentifier (i.e. name) for the schema to which the resource belongs. You can use the /api/v2/databases/{database}/schemas GET request to get a list of available schemas for the specified database.
createModestringParameter allowing support for different modes of resource creation. Possible values include: - errorIfExists: Throws an error if you try to create a resource that already exists. - orReplace: Automatically replaces the existing resource with the current one. - ifNotExists: Creates a new resource when an alter is requested for a non-existent resource.
fromNamestringParameter to enable fetching rows only following the first row whose object name matches the specified string. Case-sensitive and does not have to be the full name.
ifExistsbooleanParameter that specifies how to handle the request for a resource that does not exist: - true: The endpoint does not throw an error if the resource does not exist. It returns a 200 success response, but does not take any action on the resource. - false: The endpoint throws an error if the resource doesn't exist.
likestringParameter to filter the command output by resource name. Uses case-insensitive pattern matching, with support for SQL wildcard characters.
showLimitintegerParameter to limit the maximum number of rows returned by a command.
startsWithstringParameter to filter the command output based on the string of characters that appear at the beginning of the object name. Uses case-sensitive pattern matching.

SELECT examples

Fetch a network rule

SELECT
name,
database_name,
schema_name,
comment,
created_on,
mode,
owner,
owner_role_type,
type,
value_list
FROM snowflake.security.network_rules
WHERE database_name = '{{ database_name }}' -- required
AND schema_name = '{{ schema_name }}' -- required
AND name = '{{ name }}' -- required
AND endpoint = '{{ endpoint }}' -- required
;

INSERT examples

Create a network rule

INSERT INTO snowflake.security.network_rules (
type,
mode,
value_list,
comment,
name,
database_name,
schema_name,
endpoint,
createMode
)
SELECT
'{{ type }}' /* required */,
'{{ mode }}',
'{{ value_list }}',
'{{ comment }}',
'{{ name }}' /* required */,
'{{ database_name }}',
'{{ schema_name }}',
'{{ endpoint }}',
'{{ createMode }}'
RETURNING
status
;

DELETE examples

Delete a network rule

DELETE FROM snowflake.security.network_rules
WHERE database_name = '{{ database_name }}' --required
AND schema_name = '{{ schema_name }}' --required
AND name = '{{ name }}' --required
AND endpoint = '{{ endpoint }}' --required
AND ifExists = '{{ ifExists }}'
;