curl --request POST \
--url https://network.{region}.basaltic.sh/v1/nat-gateways \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "main",
"subnet": "7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d",
"description": "NAT gateway for private subnet egress",
"tags": {}
}
'import requests
url = "https://network.{region}.basaltic.sh/v1/nat-gateways"
payload = {
"name": "main",
"subnet": "7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d",
"description": "NAT gateway for private subnet egress",
"tags": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'main',
subnet: '7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d',
description: 'NAT gateway for private subnet egress',
tags: {}
})
};
fetch('https://network.{region}.basaltic.sh/v1/nat-gateways', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://network.{region}.basaltic.sh/v1/nat-gateways",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'main',
'subnet' => '7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d',
'description' => 'NAT gateway for private subnet egress',
'tags' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://network.{region}.basaltic.sh/v1/nat-gateways"
payload := strings.NewReader("{\n \"name\": \"main\",\n \"subnet\": \"7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d\",\n \"description\": \"NAT gateway for private subnet egress\",\n \"tags\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://network.{region}.basaltic.sh/v1/nat-gateways")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"main\",\n \"subnet\": \"7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d\",\n \"description\": \"NAT gateway for private subnet egress\",\n \"tags\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://network.{region}.basaltic.sh/v1/nat-gateways")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"main\",\n \"subnet\": \"7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d\",\n \"description\": \"NAT gateway for private subnet egress\",\n \"tags\": {}\n}"
response = http.request(request)
puts response.read_body{
"nat_gateway": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"crn": "crn:network:sa-saopaulo-1:my-account:nat-gateway/main",
"name": "main",
"subnet": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"crn": "crn:network:sa-saopaulo-1:my-account:vpc/prod/subnet/prod-web",
"vpc": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"crn": "crn:network:sa-saopaulo-1:my-account:vpc/prod",
"name": "prod",
"cidr_ipv4": "10.0.0.0/16",
"tags": {},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"description": "Production VPC for web and app tiers",
"cidr_ipv6": "2a13:9500:1a6:100::/60"
},
"route_table": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"crn": "crn:network:sa-saopaulo-1:my-account:vpc/prod/route-table/prod-private-rt",
"name": "prod-private-rt"
},
"name": "prod-web",
"cidr_ipv4": "10.0.1.0/24",
"gateway_ipv4": "10.0.1.1",
"tags": {},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"description": "Public web-tier subnet",
"cidr_ipv6": "2a13:9500:1a6:100::/64",
"gateway_ipv6": "2a13:9500:1a6:100::1"
},
"public_ipv4": "203.0.113.10",
"tags": {},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"description": "NAT gateway for private subnet egress",
"public_ipv6": "2001:db8:ffff::10"
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "ACCESS_DENIED",
"message": "You don't have permission to perform this action",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "CONFLICT",
"message": "Resource with this name already exists",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "IDEMPOTENCY_KEY_REUSED",
"message": "This Idempotency-Key was already used with a different request payload",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "An internal error occurred",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}Criar gateway NAT
Aloca IPv4 público e, quando a sub-rede de hospedagem tiver IPv6, IPv6 público do pool de locatários regional. A ativação do IPv6 na sub-rede de hospedagem posteriormente também atribui o IPv6 público do gateway. Ambos os endereços são estáveis até a exclusão do gateway e contam para a cota de IP público de sua família. A alocação não depende de rotas. As sub-redes usam o gateway para NAT de origem compartilhada roteando 0.0.0.0/0 ou ::/0 para ele. O NAT de origem IPv6 suporta ULA e endereços globais. A VPC de destino já deve ter um gateway de Internet anexado.
curl --request POST \
--url https://network.{region}.basaltic.sh/v1/nat-gateways \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '
{
"name": "main",
"subnet": "7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d",
"description": "NAT gateway for private subnet egress",
"tags": {}
}
'import requests
url = "https://network.{region}.basaltic.sh/v1/nat-gateways"
payload = {
"name": "main",
"subnet": "7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d",
"description": "NAT gateway for private subnet egress",
"tags": {}
}
headers = {
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {Authorization: 'Bearer <token>', 'Content-Type': 'application/json'},
body: JSON.stringify({
name: 'main',
subnet: '7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d',
description: 'NAT gateway for private subnet egress',
tags: {}
})
};
fetch('https://network.{region}.basaltic.sh/v1/nat-gateways', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://network.{region}.basaltic.sh/v1/nat-gateways",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'name' => 'main',
'subnet' => '7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d',
'description' => 'NAT gateway for private subnet egress',
'tags' => [
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://network.{region}.basaltic.sh/v1/nat-gateways"
payload := strings.NewReader("{\n \"name\": \"main\",\n \"subnet\": \"7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d\",\n \"description\": \"NAT gateway for private subnet egress\",\n \"tags\": {}\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://network.{region}.basaltic.sh/v1/nat-gateways")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"name\": \"main\",\n \"subnet\": \"7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d\",\n \"description\": \"NAT gateway for private subnet egress\",\n \"tags\": {}\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://network.{region}.basaltic.sh/v1/nat-gateways")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"name\": \"main\",\n \"subnet\": \"7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d\",\n \"description\": \"NAT gateway for private subnet egress\",\n \"tags\": {}\n}"
response = http.request(request)
puts response.read_body{
"nat_gateway": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"crn": "crn:network:sa-saopaulo-1:my-account:nat-gateway/main",
"name": "main",
"subnet": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"crn": "crn:network:sa-saopaulo-1:my-account:vpc/prod/subnet/prod-web",
"vpc": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"crn": "crn:network:sa-saopaulo-1:my-account:vpc/prod",
"name": "prod",
"cidr_ipv4": "10.0.0.0/16",
"tags": {},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"description": "Production VPC for web and app tiers",
"cidr_ipv6": "2a13:9500:1a6:100::/60"
},
"route_table": {
"id": "3c90c3cc-0d44-4b50-8888-8dd25736052a",
"crn": "crn:network:sa-saopaulo-1:my-account:vpc/prod/route-table/prod-private-rt",
"name": "prod-private-rt"
},
"name": "prod-web",
"cidr_ipv4": "10.0.1.0/24",
"gateway_ipv4": "10.0.1.1",
"tags": {},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"description": "Public web-tier subnet",
"cidr_ipv6": "2a13:9500:1a6:100::/64",
"gateway_ipv6": "2a13:9500:1a6:100::1"
},
"public_ipv4": "203.0.113.10",
"tags": {},
"created_at": "2023-11-07T05:31:56Z",
"updated_at": "2023-11-07T05:31:56Z",
"description": "NAT gateway for private subnet egress",
"public_ipv6": "2001:db8:ffff::10"
}
}{
"error": {
"code": "INVALID_INPUT",
"message": "Invalid request parameters",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "UNAUTHORIZED",
"message": "Authentication required",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "ACCESS_DENIED",
"message": "You don't have permission to perform this action",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "CONFLICT",
"message": "Resource with this name already exists",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "IDEMPOTENCY_KEY_REUSED",
"message": "This Idempotency-Key was already used with a different request payload",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}{
"error": {
"code": "INTERNAL_ERROR",
"message": "An internal error occurred",
"request_id": "550e8400-e29b-41d4-a716-446655440000"
}
}network:CreateNATGateway. Consulte permissões de redes para obter a lista completa, o que cada uma abrange e um exemplo de política.Autorizações
Um token bearer OAuth 2.0, enviado como Authorization: Bearer <token>. Esta é a forma recomendada de autenticação.
Obtenha o token trocando o par de chaves de acesso de uma conta de serviço em POST /v1/oauth/token com grant_type=client_credentials. Esse é o fluxo padrão de credenciais de cliente; bibliotecas compatíveis com OAuth podem obter e renovar o token para você.
curl -s -u "$KEY_ID:$SECRET" -d grant_type=client_credentials \
https://iam.basaltic.sh/v1/oauth/token
Os tokens duram uma hora por padrão. O mesmo par de chaves de acesso também serve como credencial AWS SigV4 para o endpoint de objetos compatível com S3, que aceita somente esse método de autenticação.
Cabeçalhos
Chave opcional gerada pelo cliente que torna uma criação segura para reprodução. A reintentar uma solicitação com a mesma chave retorna o resultado original literalmente em vez de criar um recurso duplicado. A reutilização de uma chave com um corpo de solicitação diferente é rejeitada (422); uma solicitação cuja chave ainda está sendo processada retorna 409. Os registros são honrados por 24 horas. Use um UUID ou token exclusivo semelhante.
255Corpo
Os nomes de recursos não devem começar com o prefixo literal crn: ou ser UUIDs (formas canônicas, compactas, entre colchetes ou urn:uuid:, em qualquer caso).
"main"
UUID de sub-rede ou CRN aninhado (vpc//subnet/Um nome nu requer um filtro de VPC explícito; as solicitações de criação sem uma VPC não aceitam nomes nu.
"7a1c9d3e-2f5b-4c8a-9e6d-3b2a1c4f5e8d"
"NAT gateway for private subnet egress"
Show child attributes
Show child attributes
Resposta
Gateway NAT criado
Show child attributes
Show child attributes

