action | string | Required | Action applied to matching requests (allow, block, challenge, js_challenge, managed_challenge, log) |
expression | string | Required | Security rule expression that defines matching traffic |
name | string | Required, Identifier | The logical name of the security rule |
zoneId | string | Required, Identifier | The zone ID this security rule applies to |
description | string | | Human friendly description shown in the Cloudflare dashboard |
enabled | bool | | Whether the rule is enabled (set to false to pause the rule) |
reference | string | | Optional reference identifier persisted with the rule; defaults to the resource name on create |
ruleId | string | | Cloudflare custom rule ID (output only) |