Filtering GCP firewall rules by the targetTags field using the Go SDK

Viewed 207

I've been trying to list firewall rules with a filter for the targetTags field but I've been unable to get it to successfully return a list.

For reference, what I have is this:

filter := `targetTags = "web-server"`
req := computepb.ListFirewallsRequest{
    Project: sdk.Project,
    Filter:  &filter,
}
it := sdk.Firewalls.List(ctx, &req)
for { ... }

I'm fairly sure that since the targetTags is an array, this is failing as the clause checks for equality. I've tried using targetTags:(web-server) but this also fails.

I can always do the filtering in-memory but I'd prefer to avoid that if possible. Anyone k ow how to get this to work?

1 Answers

I wrote a similar script to test this out, and indeed it doesn’t seem to work regardless of how I send the TargetTags filtering string. Looking in the Github repo for the Go library, I found this interesting issue. The root cause appears to be coming from the REST API used internally by the Go library. There’s an open issue in Google’s issue tracker for this as well, but the resolution does not have an ETA yet.

You would have to create filtering logic for now. Fortunately, the GetTargetTags() method does return the TargetTags array for each firewall rule, so you can create a function that filters your rules based on tags.

Related