curl --request PATCH \
--url https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id} \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"allowed_address_pairs": [
{
"ip_address": "192.168.123.20"
},
{
"ip_address": "192.168.0.0/17"
}
],
"ip_assignments": [
{
"subnet_id": "b39792c3-3160-4356-912e-ba396c95cdcf",
"ip_address": "192.168.123.20"
}
],
"port_security_enabled": true,
"security_group_ids": [
"351b0dd7-ca09-431c-be53-935db3785067"
],
"tags": {
"my-tag": "my-tag-value",
"my-tag-to-remove": null
}
}
'import requests
url = "https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}"
payload = {
"allowed_address_pairs": [{ "ip_address": "192.168.123.20" }, { "ip_address": "192.168.0.0/17" }],
"ip_assignments": [
{
"subnet_id": "b39792c3-3160-4356-912e-ba396c95cdcf",
"ip_address": "192.168.123.20"
}
],
"port_security_enabled": True,
"security_group_ids": ["351b0dd7-ca09-431c-be53-935db3785067"],
"tags": {
"my-tag": "my-tag-value",
"my-tag-to-remove": None
}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
allowed_address_pairs: [{ip_address: '192.168.123.20'}, {ip_address: '192.168.0.0/17'}],
ip_assignments: [
{
subnet_id: 'b39792c3-3160-4356-912e-ba396c95cdcf',
ip_address: '192.168.123.20'
}
],
port_security_enabled: true,
security_group_ids: ['351b0dd7-ca09-431c-be53-935db3785067'],
tags: {'my-tag': 'my-tag-value', 'my-tag-to-remove': null}
})
};
fetch('https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'allowed_address_pairs' => [
[
'ip_address' => '192.168.123.20'
],
[
'ip_address' => '192.168.0.0/17'
]
],
'ip_assignments' => [
[
'subnet_id' => 'b39792c3-3160-4356-912e-ba396c95cdcf',
'ip_address' => '192.168.123.20'
]
],
'port_security_enabled' => true,
'security_group_ids' => [
'351b0dd7-ca09-431c-be53-935db3785067'
],
'tags' => [
'my-tag' => 'my-tag-value',
'my-tag-to-remove' => null
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}"
payload := strings.NewReader("{\n \"allowed_address_pairs\": [\n {\n \"ip_address\": \"192.168.123.20\"\n },\n {\n \"ip_address\": \"192.168.0.0/17\"\n }\n ],\n \"ip_assignments\": [\n {\n \"subnet_id\": \"b39792c3-3160-4356-912e-ba396c95cdcf\",\n \"ip_address\": \"192.168.123.20\"\n }\n ],\n \"port_security_enabled\": true,\n \"security_group_ids\": [\n \"351b0dd7-ca09-431c-be53-935db3785067\"\n ],\n \"tags\": {\n \"my-tag\": \"my-tag-value\",\n \"my-tag-to-remove\": null\n }\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"allowed_address_pairs\": [\n {\n \"ip_address\": \"192.168.123.20\"\n },\n {\n \"ip_address\": \"192.168.0.0/17\"\n }\n ],\n \"ip_assignments\": [\n {\n \"subnet_id\": \"b39792c3-3160-4356-912e-ba396c95cdcf\",\n \"ip_address\": \"192.168.123.20\"\n }\n ],\n \"port_security_enabled\": true,\n \"security_group_ids\": [\n \"351b0dd7-ca09-431c-be53-935db3785067\"\n ],\n \"tags\": {\n \"my-tag\": \"my-tag-value\",\n \"my-tag-to-remove\": null\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"allowed_address_pairs\": [\n {\n \"ip_address\": \"192.168.123.20\"\n },\n {\n \"ip_address\": \"192.168.0.0/17\"\n }\n ],\n \"ip_assignments\": [\n {\n \"subnet_id\": \"b39792c3-3160-4356-912e-ba396c95cdcf\",\n \"ip_address\": \"192.168.123.20\"\n }\n ],\n \"port_security_enabled\": true,\n \"security_group_ids\": [\n \"351b0dd7-ca09-431c-be53-935db3785067\"\n ],\n \"tags\": {\n \"my-tag\": \"my-tag-value\",\n \"my-tag-to-remove\": null\n }\n}"
response = http.request(request)
puts response.read_body{
"tasks": [
"d478ae29-dedc-4869-82f0-96104425f565"
]
}Update port
Updates port security, security groups, allowed address pairs, tags and IP assignments.
Behavior:
- Undefined fields remain unchanged; list fields replace the whole set, so send the full desired list
(
[]to clear,ip_assignmentsmust keep at least one entry) - Tags are merged per key; a
nullvalue removes the key, andtags: nullremoves all user tags - If no changes are detected, no task is created and an empty task list is returned
Supported ports: all compute types (instances, basic VMs, bare metal servers, GPU virtual servers,
GPU bare metal servers), as long as the port capabilities report true for the field being changed.
System-managed ports (DHCP, router, load balancer) and unattached ports are rejected.
Typical uses:
- Per-port firewall:
security_group_idsapplies to this port only, so ports on the same server can differ. While port security is enabled, an empty list permits no traffic - VIP failover (VRRP/keepalived): add the VIP address to
allowed_address_pairsof every port allowed to claim it, all on the VIP’s network - Routing and NAT appliances:
port_security_enabled: falsepermits forwarding traffic with foreign source addresses; clear security groups and allowed address pairs in the same request - Additional addresses:
ip_assignmentsadds or releases IPs (dual-stack, extra service IPs) without detaching the port; the guest OS must be configured for the extra ones. Send an entry with onlysubnet_idto get any free address of that subnet, which is the only option on a shared subnet whose free addresses the caller does not know. Such an entry keeps an address the port already has in that subnet, in the order the port reports them, so a shorter list releases the addresses at the end of that order. A request can replace all current addresses. A port an instance holds takes its addresses from one subnet per IP version, because the guest reaches one address range per version
Public network: port security and allowed address pairs cannot be changed on ports in the region’s public network. IP assignments can. Each IPv4 address there counts against the external IP quota, so a request that allocates one fails when the limit is full, and a request that releases one gives the quota back. IPv6 addresses in that network are not counted.
curl --request PATCH \
--url https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id} \
--header 'Authorization: <api-key>' \
--header 'Content-Type: application/json' \
--data '
{
"allowed_address_pairs": [
{
"ip_address": "192.168.123.20"
},
{
"ip_address": "192.168.0.0/17"
}
],
"ip_assignments": [
{
"subnet_id": "b39792c3-3160-4356-912e-ba396c95cdcf",
"ip_address": "192.168.123.20"
}
],
"port_security_enabled": true,
"security_group_ids": [
"351b0dd7-ca09-431c-be53-935db3785067"
],
"tags": {
"my-tag": "my-tag-value",
"my-tag-to-remove": null
}
}
'import requests
url = "https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}"
payload = {
"allowed_address_pairs": [{ "ip_address": "192.168.123.20" }, { "ip_address": "192.168.0.0/17" }],
"ip_assignments": [
{
"subnet_id": "b39792c3-3160-4356-912e-ba396c95cdcf",
"ip_address": "192.168.123.20"
}
],
"port_security_enabled": True,
"security_group_ids": ["351b0dd7-ca09-431c-be53-935db3785067"],
"tags": {
"my-tag": "my-tag-value",
"my-tag-to-remove": None
}
}
headers = {
"Authorization": "<api-key>",
"Content-Type": "application/json"
}
response = requests.patch(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'PATCH',
headers: {Authorization: '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
allowed_address_pairs: [{ip_address: '192.168.123.20'}, {ip_address: '192.168.0.0/17'}],
ip_assignments: [
{
subnet_id: 'b39792c3-3160-4356-912e-ba396c95cdcf',
ip_address: '192.168.123.20'
}
],
port_security_enabled: true,
security_group_ids: ['351b0dd7-ca09-431c-be53-935db3785067'],
tags: {'my-tag': 'my-tag-value', 'my-tag-to-remove': null}
})
};
fetch('https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "PATCH",
CURLOPT_POSTFIELDS => json_encode([
'allowed_address_pairs' => [
[
'ip_address' => '192.168.123.20'
],
[
'ip_address' => '192.168.0.0/17'
]
],
'ip_assignments' => [
[
'subnet_id' => 'b39792c3-3160-4356-912e-ba396c95cdcf',
'ip_address' => '192.168.123.20'
]
],
'port_security_enabled' => true,
'security_group_ids' => [
'351b0dd7-ca09-431c-be53-935db3785067'
],
'tags' => [
'my-tag' => 'my-tag-value',
'my-tag-to-remove' => null
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: <api-key>",
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}"
payload := strings.NewReader("{\n \"allowed_address_pairs\": [\n {\n \"ip_address\": \"192.168.123.20\"\n },\n {\n \"ip_address\": \"192.168.0.0/17\"\n }\n ],\n \"ip_assignments\": [\n {\n \"subnet_id\": \"b39792c3-3160-4356-912e-ba396c95cdcf\",\n \"ip_address\": \"192.168.123.20\"\n }\n ],\n \"port_security_enabled\": true,\n \"security_group_ids\": [\n \"351b0dd7-ca09-431c-be53-935db3785067\"\n ],\n \"tags\": {\n \"my-tag\": \"my-tag-value\",\n \"my-tag-to-remove\": null\n }\n}")
req, _ := http.NewRequest("PATCH", url, payload)
req.Header.Add("Authorization", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.patch("https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}")
.header("Authorization", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"allowed_address_pairs\": [\n {\n \"ip_address\": \"192.168.123.20\"\n },\n {\n \"ip_address\": \"192.168.0.0/17\"\n }\n ],\n \"ip_assignments\": [\n {\n \"subnet_id\": \"b39792c3-3160-4356-912e-ba396c95cdcf\",\n \"ip_address\": \"192.168.123.20\"\n }\n ],\n \"port_security_enabled\": true,\n \"security_group_ids\": [\n \"351b0dd7-ca09-431c-be53-935db3785067\"\n ],\n \"tags\": {\n \"my-tag\": \"my-tag-value\",\n \"my-tag-to-remove\": null\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.gcore.com/cloud/v1/ports/{project_id}/{region_id}/{port_id}")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Patch.new(url)
request["Authorization"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"allowed_address_pairs\": [\n {\n \"ip_address\": \"192.168.123.20\"\n },\n {\n \"ip_address\": \"192.168.0.0/17\"\n }\n ],\n \"ip_assignments\": [\n {\n \"subnet_id\": \"b39792c3-3160-4356-912e-ba396c95cdcf\",\n \"ip_address\": \"192.168.123.20\"\n }\n ],\n \"port_security_enabled\": true,\n \"security_group_ids\": [\n \"351b0dd7-ca09-431c-be53-935db3785067\"\n ],\n \"tags\": {\n \"my-tag\": \"my-tag-value\",\n \"my-tag-to-remove\": null\n }\n}"
response = http.request(request)
puts response.read_body{
"tasks": [
"d478ae29-dedc-4869-82f0-96104425f565"
]
}Authorizations
API key for authentication. Make sure to include the word apikey, followed by a single space and then your token.
Example: apikey 1234_abcdef
Path Parameters
Project ID
1
Region ID
1
Port ID
"1f0ca628-a73b-42c0-bdac-7b10d023e097"
Body
A set of zero or more allowed port address pair and/or subnet masks. Replaces the full set of allowed address pairs. Send [] to clear; omit the field to leave existing pairs unchanged.
10Show child attributes
Show child attributes
[
{ "ip_address": "192.168.123.20" },
{ "ip_address": "192.168.0.0/17" }
]
IP assignments on the port. Replaces the full set. Subnets must belong to the port's network, and a port an instance holds supports one subnet per IP version. An entry without ip_address keeps an address the port already has in that subnet, in the order the port reports them, or takes a free one when the port has none. Addresses that no entry keeps are released.
64Show child attributes
Show child attributes
When true, the network driver enforces port security on this port (anti-spoofing checks and security-group filtering apply). When false, all traffic is allowed and security groups are not applied.
List of security group IDs. Replaces the full set of security groups attached to the port. Send [] to detach all groups; omit the field to leave existing groups unchanged.
10["351b0dd7-ca09-431c-be53-935db3785067"]
Update key-value tags using JSON Merge Patch semantics (RFC 7386). Provide key-value pairs to add or update tags. Set tag values to null to remove tags. Unspecified tags remain unchanged. Read-only tags are always preserved and cannot be modified.
Examples:
- Add/update tags:
{'tags': {'environment': 'production', 'team': 'backend'}}adds new tags or updates existing ones. - Delete tags:
{'tags': {'old_tag': null}}removes specific tags. - Remove all tags:
{'tags': null}removes all user-managed tags (read-only tags are preserved). - Partial update:
{'tags': {'environment': 'staging'}}only updates specified tags. - Mixed operations:
{'tags': {'environment': 'production', 'cost_center': 'engineering', 'deprecated_tag': null}}adds/updates 'environment' and 'cost_center' while removing 'deprecated_tag', preserving other existing tags. - Replace all: first delete existing tags with null values, then add new ones in the same request.
Show child attributes
Show child attributes
{
"my-tag": "my-tag-value",
"my-tag-to-remove": null
}
Response
Task IDs
List of task IDs representing asynchronous operations. Use these IDs to monitor operation progress:
GET /v1/tasks/{task_id}- Check individual task status and details Poll task status until completion (FINISHED/ERROR) before proceeding with dependent operations.
["d478ae29-dedc-4869-82f0-96104425f565"]
Was this page helpful?