iam library

AWS IAM.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
AwsIamAccessKey
Factory wrapper for aws_iam_access_key.
AwsIamAccountAlias
Factory wrapper for aws_iam_account_alias.
AwsIamAccountPasswordPolicy
Factory wrapper for aws_iam_account_password_policy.
AwsIamGroup
Factory wrapper for aws_iam_group.
AwsIamGroupMembership
Factory wrapper for aws_iam_group_membership.
AwsIamGroupPoliciesExclusive
Factory wrapper for aws_iam_group_policies_exclusive.
AwsIamGroupPolicy
Factory wrapper for aws_iam_group_policy.
AwsIamGroupPolicyAttachment
Factory wrapper for aws_iam_group_policy_attachment.
AwsIamGroupPolicyAttachmentsExclusive
Factory wrapper for aws_iam_group_policy_attachments_exclusive.
AwsIamInstanceProfile
Factory wrapper for aws_iam_instance_profile.
AwsIamOpenidConnectProvider
Factory wrapper for aws_iam_openid_connect_provider.
AwsIamOrganizationsFeatures
Factory wrapper for aws_iam_organizations_features.
AwsIamOutboundWebIdentityFederation
Factory wrapper for aws_iam_outbound_web_identity_federation.
AwsIamPolicy
Factory wrapper for aws_iam_policy.
AwsIamPolicyAttachment
Factory wrapper for aws_iam_policy_attachment.
AwsIamRole
Factory wrapper for aws_iam_role.
AwsIamRolePoliciesExclusive
Factory wrapper for aws_iam_role_policies_exclusive.
AwsIamRolePolicy
Factory wrapper for aws_iam_role_policy.
AwsIamRolePolicyAttachment
Factory wrapper for aws_iam_role_policy_attachment.
AwsIamRolePolicyAttachmentsExclusive
Factory wrapper for aws_iam_role_policy_attachments_exclusive.
AwsIamSamlProvider
Factory wrapper for aws_iam_saml_provider.
AwsIamSecurityTokenServicePreferences
Factory wrapper for aws_iam_security_token_service_preferences.
AwsIamServerCertificate
Factory wrapper for aws_iam_server_certificate.
AwsIamServiceLinkedRole
Factory wrapper for aws_iam_service_linked_role.
AwsIamServiceSpecificCredential
Factory wrapper for aws_iam_service_specific_credential.
AwsIamSigningCertificate
Factory wrapper for aws_iam_signing_certificate.
AwsIamUser
Factory wrapper for aws_iam_user.
AwsIamUserGroupMembership
Factory wrapper for aws_iam_user_group_membership.
AwsIamUserLoginProfile
Factory wrapper for aws_iam_user_login_profile.
AwsIamUserPoliciesExclusive
Factory wrapper for aws_iam_user_policies_exclusive.
AwsIamUserPolicy
Factory wrapper for aws_iam_user_policy.
AwsIamUserPolicyAttachment
Factory wrapper for aws_iam_user_policy_attachment.
AwsIamUserPolicyAttachmentsExclusive
Factory wrapper for aws_iam_user_policy_attachments_exclusive.
AwsIamUserSshKey
Factory wrapper for aws_iam_user_ssh_key.
AwsIamVirtualMfaDevice
Factory wrapper for aws_iam_virtual_mfa_device.
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataAwsIamAccessKeys
Factory wrapper for aws_iam_access_keys.
DataAwsIamAccountAlias
Factory wrapper for aws_iam_account_alias.
DataAwsIamGroup
Factory wrapper for aws_iam_group.
DataAwsIamInstanceProfile
Factory wrapper for aws_iam_instance_profile.
DataAwsIamInstanceProfiles
Factory wrapper for aws_iam_instance_profiles.
DataAwsIamOpenidConnectProvider
Factory wrapper for aws_iam_openid_connect_provider.
DataAwsIamOutboundWebIdentityFederation
Factory wrapper for aws_iam_outbound_web_identity_federation.
DataAwsIamPolicy
Factory wrapper for aws_iam_policy.
DataAwsIamPolicyDocument
Factory wrapper for aws_iam_policy_document.
DataAwsIamPrincipalPolicySimulation
Factory wrapper for aws_iam_principal_policy_simulation.
DataAwsIamRole
Factory wrapper for aws_iam_role.
DataAwsIamRolePolicies
Factory wrapper for aws_iam_role_policies.
DataAwsIamRolePolicyAttachments
Factory wrapper for aws_iam_role_policy_attachments.
DataAwsIamRoles
Factory wrapper for aws_iam_roles.
DataAwsIamSamlProvider
Factory wrapper for aws_iam_saml_provider.
DataAwsIamServerCertificate
Factory wrapper for aws_iam_server_certificate.
DataAwsIamSessionContext
Factory wrapper for aws_iam_session_context.
DataAwsIamUser
Factory wrapper for aws_iam_user.
DataAwsIamUsers
Factory wrapper for aws_iam_users.
DataAwsIamUserSshKey
Factory wrapper for aws_iam_user_ssh_key.
DataIamPolicyDocumentCondition
Typed helper for the statement.condition block of aws_iam_policy_document (derived from provider schema).
DataIamPolicyDocumentNotPrincipals
Typed helper for the statement.not_principals block of aws_iam_policy_document (derived from provider schema).
DataIamPolicyDocumentPrincipals
Typed helper for the statement.principals block of aws_iam_policy_document (derived from provider schema).
DataIamPolicyDocumentStatement
Typed helper for the statement block of aws_iam_policy_document (derived from provider schema).
DataIamPrincipalPolicySimulationContext
Typed helper for the context block of aws_iam_principal_policy_simulation (derived from provider schema).
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
GcsBackend
terraform { backend "gcs" { ... } } configuration.
IamGroupPolicyName
At most one of name, name_prefix on aws_iam_group_policy: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
IamGroupPolicyNameChoice
The IamGroupPolicyName.name choice: sets name.
IamGroupPolicyNamePrefix
The IamGroupPolicyName.namePrefix choice: sets name_prefix.
IamInstanceProfileName
At most one of name, name_prefix on aws_iam_instance_profile: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
IamInstanceProfileNameChoice
The IamInstanceProfileName.name choice: sets name.
IamInstanceProfileNamePrefix
The IamInstanceProfileName.namePrefix choice: sets name_prefix.
IamPolicyName
At most one of name, name_prefix on aws_iam_policy: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
IamPolicyNameChoice
The IamPolicyName.name choice: sets name.
IamPolicyNamePrefix
The IamPolicyName.namePrefix choice: sets name_prefix.
IamRoleInlinePolicy
Typed helper for the inline_policy block of aws_iam_role (derived from provider schema).
IamRoleName
At most one of name, name_prefix on aws_iam_role: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
IamRoleNameChoice
The IamRoleName.name choice: sets name.
IamRoleNamePrefix
The IamRoleName.namePrefix choice: sets name_prefix.
IamRolePolicyName
At most one of name, name_prefix on aws_iam_role_policy: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
IamRolePolicyNameChoice
The IamRolePolicyName.name choice: sets name.
IamRolePolicyNamePrefix
The IamRolePolicyName.namePrefix choice: sets name_prefix.
IamServerCertificateName
At most one of name, name_prefix on aws_iam_server_certificate: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
IamServerCertificateNameChoice
The IamServerCertificateName.name choice: sets name.
IamServerCertificateNamePrefix
The IamServerCertificateName.namePrefix choice: sets name_prefix.
IamUserPolicyName
At most one of name, name_prefix on aws_iam_user_policy: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
IamUserPolicyNameChoice
The IamUserPolicyName.name choice: sets name.
IamUserPolicyNamePrefix
The IamUserPolicyName.namePrefix choice: sets name_prefix.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

IamAccessKeyStatus
Iam Access Key enum for status.
IamOrganizationsFeaturesEnabledFeatures
Iam Organizations Features Enabled enum for enabled_features.
IamSecurityTokenServicePreferencesGlobalEndpointTokenVersion
Iam Security Token Service Preferences Global Endpoint Token enum for global_endpoint_token_version.
IamServiceSpecificCredentialStatus
Iam Service Specific Credential enum for status.
IamSigningCertificateStatus
Iam Signing Certificate enum for status.
IamUserSshKeyEncoding
Iam User Ssh Key enum for encoding.
OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.