- NAME
-
- gcloud network-security firewall-endpoints update - update a Firewall Plus endpoint
- SYNOPSIS
-
-
gcloud network-security firewall-endpoints update(FIREWALL_ENDPOINT:--organization=ORGANIZATION--zone=ZONE) [--async] [--description=DESCRIPTION] [--location=LOCATION] [--max-wait=MAX_WAIT; default="60m"] [--update-billing-project=BILLING_PROJECT] [--update-labels=[KEY=VALUE, …]] [--clear-labels|--remove-labels=[KEY, …]] [GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
- Update a firewall endpoint. Check the progress of endpoint update by using
gcloud network-security firewall-endpoints describe.For more examples, refer to the EXAMPLES section below.
- EXAMPLES
- To update labels k1 and k2, run:
gcloud network-security firewall-endpoints update my-endpoint --zone = us-central1-a --organization = 1234 --update-labels = k1 = v1,k2 = v2To remove labels k3 and k4, run:
gcloud network-security firewall-endpoints update my-endpoint --zone = us-central1-a --organization = 1234 --remove-labels = k3,k4To clear all labels from the firewall endpoint, run:
gcloud network-security firewall-endpoints update my-endpoint --zone = us-central1-a --organization = 1234 --clear-labels - POSITIONAL ARGUMENTS
-
- Firewall endpoint resource - Firewall Plus. The arguments in this group can be
used to specify the attributes of this resource. This resource can be one of the
following types: [firewall endpoint].
This must be specified.
-
FIREWALL_ENDPOINT - ID of the firewall endpoint or fully qualified identifier for the firewall
endpoint.
To set the
endpoint-nameattribute:- provide the argument
FIREWALL_ENDPOINTon the command line.
This positional argument must be specified if any of the other arguments in this group are specified.
- provide the argument
-
--organization=ORGANIZATION - Organization ID of the firewall endpoint.
To set the
organizationattribute:- provide the argument
FIREWALL_ENDPOINTon the command line with a fully specified name; - provide the argument
--organizationon the command line.
- provide the argument
-
--zone=ZONE - Zone of the firewall endpoint.
To set the
zoneattribute:- provide the argument
FIREWALL_ENDPOINTon the command line with a fully specified name; - provide the argument
--zoneon the command line; - provide the argument
--locationon the command line.
- provide the argument
-
- Firewall endpoint resource - Firewall Plus. The arguments in this group can be
used to specify the attributes of this resource. This resource can be one of the
following types: [firewall endpoint].
- FLAGS
-
-
--async - Return immediately, without waiting for the operation in progress to complete.
The default is
True. Enabled by default, use--no-asyncto disable. -
--description=DESCRIPTION - Description of the endpoint
-
--location=LOCATION - Location of the endpoint
-
--max-wait=MAX_WAIT; default="60m" - Time to synchronously wait for the operation to complete, after which the operation continues asynchronously. Ignored if --no-async isn't specified. See $ gcloud topic datetimes for information on time formats.
-
--update-billing-project=BILLING_PROJECT - The Google Cloud project ID to use for API enablement check, quota, and endpoint
uptime billing. Overrides the default
billing/quota_projectproperty value for this command invocation. -
--update-labels=[KEY=VALUE,…] - List of label KEY=VALUE pairs to update. If a label exists, its value is
modified. Otherwise, a new label is created.
Keys must start with a lowercase character and contain only hyphens (
-), underscores (_), lowercase characters, and numbers. Values must contain only hyphens (-), underscores (_), lowercase characters, and numbers. - At most one of these can be specified:
-
--clear-labels - Remove all labels. If
--update-labelsis also specified then--clear-labelsis applied first.For example, to remove all labels:
gcloud network-security firewall-endpoints update --clear-labelsTo remove all existing labels and create two new labels,
andfoo:bazgcloud network-security firewall-endpoints update --clear-labels --update-labels foo = bar,baz = qux -
--remove-labels=[KEY,…] - List of label keys to remove. If a label does not exist it is silently ignored.
If
--update-labelsis also specified then--update-labelsis applied first.
-
-
- GCLOUD WIDE FLAGS
- These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$ gcloud helpfor details. - NOTES
- These variants are also available:
gcloud alpha network-security firewall-endpoints updategcloud beta network-security firewall-endpoints update
gcloud network-security firewall-endpoints update
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License , and code samples are licensed under the Apache 2.0 License . For details, see the Google Developers Site Policies . Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-05-27 UTC.

