# Azion CLI firewall-instance

The Azion CLI `firewall-instance` commands create, list, describe, update, and delete [function instances on a firewall](/en/documentation/platform/firewall/functions-instances/). An instance binds one function to one firewall and holds the arguments the function receives there. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create firewall-instance` creates a function instance on the firewall you name:

```bash
azion create firewall-instance [flags]
```

| Flag            | Short | Type   | Default  | Description                                                                                                                           |
| --------------- | ----- | ------ | -------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| `--active`      | —     | string | `"true"` | Whether the instance is active: `true` or `false`.                                                                                    |
| `--args`        | —     | string | —        | Path to a JSON file with the arguments the function receives on this instance.                                                        |
| `--file`        | —     | string | —        | Path to a JSON file with the attributes of the instance. Use `-` to read the JSON from standard input.                                |
| `--firewall-id` | —     | int    | —        | ID of the firewall that holds the instance.                                                                                           |
| `--function-id` | —     | int    | —        | **Required** unless `--file` is set. ID of the function the instance runs. Without it, the command asks `? Enter the Function's ID:`. |
| `--name`        | —     | string | —        | Name of the instance.                                                                                                                 |

This command creates an instance named `my-firewall-instance` of the function with ID `12370` on the firewall with ID `12353`, with the arguments in `args.json`:

```bash
azion create firewall-instance --firewall-id 12353 --function-id 12370 --name my-firewall-instance --args ./args.json
```

The command prints the ID of the instance:

```text
Created Firewall Function Instance with ID 12355
```

---

## List

`azion list firewall-instance` lists the function instances of a firewall, 50 to a page:

```bash
azion list firewall-instance [flags]
```

| Flag            | Short | Type   | Default | Description                                                                                               |
| --------------- | ----- | ------ | ------- | --------------------------------------------------------------------------------------------------------- |
| `--details`     | —     | —      | —       | Adds the `LAST EDITOR` and `LAST MODIFIED` columns to the `ID`, `NAME`, `ACTIVE`, and `FUNCTION` columns. |
| `--filter`      | —     | string | —       | Name to filter the list by.                                                                               |
| `--firewall-id` | —     | int    | —       | ID of the firewall whose instances to list.                                                               |
| `--order-by`    | —     | string | —       | Field to sort the list by.                                                                                |
| `--page`        | —     | int    | `1`     | Number of the page to return.                                                                             |
| `--page-size`   | —     | int    | `50`    | Number of instances on each page.                                                                         |

This command lists the instances of the firewall with ID `12353`:

```bash
azion list firewall-instance --firewall-id 12353
```

The command prints one row per instance. The `FUNCTION` column holds the ID of the function each instance runs:

```text
ID     NAME                  ACTIVE  FUNCTION
12355  my-firewall-instance  true    12370
12356  my-file-instance      true    12370
```

---

## Describe

`azion describe firewall-instance` prints the settings of one function instance:

```bash
azion describe firewall-instance [flags]
```

| Flag            | Short | Type | Default | Description                                 |
| --------------- | ----- | ---- | ------- | ------------------------------------------- |
| `--firewall-id` | —     | int  | —       | ID of the firewall that holds the instance. |
| `--instance-id` | —     | int  | —       | ID of the instance to describe.             |

This command describes the instance with ID `12355` on the firewall with ID `12353`:

```bash
azion describe firewall-instance --firewall-id 12353 --instance-id 12355
```

The command prints the ID, the name, and the function of the instance, and who changed it last and when:

```text
ID:              12355
Name:            my-firewall-instance
Function:        12370
Last Editor:     you@example.com
Last Modified:   "2026-01-01T12:00:00.276936Z"
```

With `--format json`, the command prints the full object: `active`, `args`, `azion_form`, `created_at`, `function`, `id`, `last_editor`, `last_modified`, and `name`. The `args` object holds the arguments that `--args` or the JSON file set, and `function` holds the ID of the function.

An instance ID that does not exist on the firewall fails with `Error: failed to describe the Firewall Function Instance: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct`.

---

## Update

`azion update firewall-instance` changes the attributes of a function instance:

```bash
azion update firewall-instance [flags]
```

| Flag            | Short | Type   | Default  | Description                                                                                      |
| --------------- | ----- | ------ | -------- | ------------------------------------------------------------------------------------------------ |
| `--active`      | —     | string | `"true"` | Whether the instance is active: `true` or `false`.                                               |
| `--args`        | —     | string | —        | Path to a JSON file with the arguments the function receives on this instance.                   |
| `--file`        | —     | string | —        | Path to a JSON file with the attributes to change. Use `-` to read the JSON from standard input. |
| `--firewall-id` | —     | int    | —        | ID of the firewall that holds the instance.                                                      |
| `--function-id` | —     | int    | —        | ID of the function the instance runs.                                                            |
| `--instance-id` | —     | int    | —        | ID of the instance to update.                                                                    |
| `--name`        | —     | string | —        | New name of the instance.                                                                        |

An instance cannot be turned off. With `--active false`, the command fails with this error:

```text
Error: failed to update the Firewall Function Instance: ["You can't deactivate a function instance."]
```

This command renames the instance with ID `12355` to `my-firewall-instance-renamed`:

```bash
azion update firewall-instance --firewall-id 12353 --instance-id 12355 --name my-firewall-instance-renamed
```

The command prints the ID of the updated instance. The arguments of the instance keep their values:

```text
Updated Firewall Function Instance with ID 12355
```

---

## Delete

`azion delete firewall-instance` deletes a function instance from a firewall:

```bash
azion delete firewall-instance [flags]
```

| Flag            | Short | Type | Default | Description                                 |
| --------------- | ----- | ---- | ------- | ------------------------------------------- |
| `--firewall-id` | —     | int  | —       | ID of the firewall that holds the instance. |
| `--instance-id` | —     | int  | —       | ID of the instance to delete.               |

This command deletes the instance with ID `12356` from the firewall with ID `12353`:

```bash
azion delete firewall-instance --firewall-id 12353 --instance-id 12356 -y
```

The command confirms the deletion:

```text
Firewall Function Instance 12356 was successfully deleted
```

---

## Use a JSON file

`azion create firewall-instance` and `azion update firewall-instance` read the attributes of the instance from a JSON file with `--file`. Pass `--firewall-id` on the command line in both cases.

This file creates an active instance named `my-file-instance` of the function with ID `12370`, with no arguments. Because the file carries `function`, `--function-id` is not needed:

```json
{
  "name": "my-file-instance",
  "function": 12370,
  "active": true,
  "args": {}
}
```

Pass the file to the create command:

```bash
azion create firewall-instance --firewall-id 12353 --file fwi-create.json
```

The command prints the ID of the instance:

```text
Created Firewall Function Instance with ID 12356
```

On update, pass `--instance-id` as well. This file renames the instance and replaces its arguments:

```json
{
  "name": "my-file-instance-updated",
  "args": {"mode": "updated"}
}
```

Pass the file to the update command:

```bash
azion update firewall-instance --firewall-id 12353 --instance-id 12356 --file fwi-update.json
```

The command prints the ID of the updated instance:

```text
Updated Firewall Function Instance with ID 12356
```

The update is partial: a field the file leaves out, such as `active`, keeps its value.

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Function instances for Firewall](/en/documentation/platform/firewall/functions-instances.md): What an instance holds and how its arguments reach the function.
- [Azion CLI function](/en/documentation/devtools/cli/resources/function.md): The commands that create the function an instance runs and print its ID.
- [Azion CLI firewall-rule](/en/documentation/devtools/cli/resources/firewall-rule.md): The commands that create the rules that run an instance on a firewall.
