OptionalauthenticationThe authenticated identity the request must match. When unset, the rule matches all users and service principals.
OptionaldestinationThe destination the request must match — the resource being accessed, for example the workspace UI or workspace APIs. See RequestDestination.
OptionallabelThe label for this ingress rule.
OptionaloriginThe origin the request must match — the source workspace the request comes from, either specific source workspaces or any source workspace in any account. See CrossWorkspaceRequestOrigin.
An ingress rule is enforced when a request satisfies all specified attributes — including request origin, destination, and authentication.