gcloud alpha network-security firewall-endpoints update

NAME
gcloud alpha network-security firewall-endpoints update - update a Firewall Plus endpoint
SYNOPSIS
gcloud alpha network-security firewall-endpoints update(FIREWALL_ENDPOINT :--organization=ORGANIZATION--zone=ZONE)[--async][--description=DESCRIPTION][--max-wait=MAX_WAIT; default="60m"][--update-billing-project=BILLING_PROJECT][--update-labels=[KEY=VALUE,…]][--clear-labels    |--remove-labels=[KEY,…]][GCLOUD_WIDE_FLAG]
DESCRIPTION
(ALPHA) Update a firewall endpoint. Check the progress of endpointupdate by usinggcloudnetwork-security firewall-endpoints describe.

For more examples, refer to the EXAMPLES section below.

EXAMPLES
To update labels k1 and k2, run:
gcloudalphanetwork-securityfirewall-endpointsupdatemy-endpoint--zone=us-central1-a--organization=1234--update-labels=k1=v1,k2=v2

To remove labels k3 and k4, run:

gcloudalphanetwork-securityfirewall-endpointsupdatemy-endpoint--zone=us-central1-a--organization=1234--remove-labels=k3,k4

To clear all labels from the firewall endpoint, run:

gcloudalphanetwork-securityfirewall-endpointsupdatemy-endpoint--zone=us-central1-a--organization=1234--clear-labels
POSITIONAL ARGUMENTS
Firewall endpoint resource - Firewall Plus. The arguments in this group can beused to specify the attributes of this resource. (NOTE) Some attributes are notgiven arguments in this group but can be set in other ways.

To set theproject attribute:

  • provide the argumentFIREWALL_ENDPOINT on the command line with afully specified name;
  • set the propertycore/project. This resource can be one of thefollowing types: [networksecurity.organizations.locations.firewallEndpoints,networksecurity.projects.locations.firewallEndpoints].

This must be specified.

FIREWALL_ENDPOINT
ID of the firewall endpoint or fully qualified identifier for the firewallendpoint.

To set theendpoint-name attribute:

  • provide the argumentFIREWALL_ENDPOINT on the command line.

This positional argument must be specified if any of the other arguments in thisgroup are specified.

--organization=ORGANIZATION
Organization ID of the firewall endpoint.

To set theorganization attribute:

  • provide the argumentFIREWALL_ENDPOINT on the command line with afully specified name;
  • provide the argument--organization on the command line. Must bespecified for resource of type[networksecurity.organizations.locations.firewallEndpoints].
--zone=ZONE
Zone of the firewall endpoint.

To set thezone attribute:

  • provide the argumentFIREWALL_ENDPOINT on the command line with afully specified name;
  • provide the argument--zone on the command line.
FLAGS
--async
Return immediately, without waiting for the operation in progress to complete.The default isTrue. Enabled by default, use--no-async to disable.
--description=DESCRIPTION
Description of the endpoint
--max-wait=MAX_WAIT; default="60m"
Time to synchronously wait for the operation to complete, after which theoperation continues asynchronously. Ignored if --no-async isn't specified. See $gcloud topic datetimes forinformation on time formats.
--update-billing-project=BILLING_PROJECT
The Google Cloud project ID to use for API enablement check, quota, and endpointuptime billing. Overrides the defaultbilling/quota_projectproperty value for this command invocation.
--update-labels=[KEY=VALUE,…]
List of label KEY=VALUE pairs to update. If a label exists, its value ismodified. Otherwise, a new label is created.

Keys must start with a lowercase character and contain only hyphens(-), underscores (_), lowercase characters, andnumbers. Values must contain only hyphens (-), underscores(_), lowercase characters, and numbers.

At most one of these can be specified:
--clear-labels
Remove all labels. If--update-labels is also specified then--clear-labels is applied first.

For example, to remove all labels:

gcloudalphanetwork-securityfirewall-endpointsupdate--clear-labels

To remove all existing labels and create two new labels,foo andbaz:

gcloudalphanetwork-securityfirewall-endpointsupdate--clear-labels--update-labelsfoo=bar,baz=qux
--remove-labels=[KEY,…]
List of label keys to remove. If a label does not exist it is silently ignored.If--update-labels is also specified then--update-labels is applied first.
GCLOUD WIDE FLAGS
These flags are available to all commands:--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.

Run$gcloud help for details.

NOTES
This command is currently in alpha and might change without notice. If thiscommand fails with API permission errors despite specifying the correct project,you might be trying to access an API with an invitation-only early accessallowlist. These variants are also available:
gcloudnetwork-securityfirewall-endpointsupdate
gcloudbetanetwork-securityfirewall-endpointsupdate

Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2026-01-27 UTC.