rules library

Cloudflare rulesets, page rules, lists, and filters.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
CloudflareFilter
Factory wrapper for cloudflare_filter.
CloudflareList
Factory wrapper for cloudflare_list.
CloudflareListItem
Factory wrapper for cloudflare_list_item.
CloudflarePageRule
Factory wrapper for cloudflare_page_rule.
CloudflareRuleset
Factory wrapper for cloudflare_ruleset.
CloudflareUrlNormalizationSettings
Factory wrapper for cloudflare_url_normalization_settings.
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataCloudflareFilter
Factory wrapper for cloudflare_filter.
DataCloudflareList
Factory wrapper for cloudflare_list.
DataCloudflareListItem
Factory wrapper for cloudflare_list_item.
DataCloudflarePageRule
Factory wrapper for cloudflare_page_rule.
DataCloudflareRuleset
Factory wrapper for cloudflare_ruleset.
DataCloudflareUrlNormalizationSettings
Factory wrapper for cloudflare_url_normalization_settings.
DataFilter
Typed helper for the filter block of cloudflare_filter (derived from provider schema).
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
FilterBody
Typed helper for the body block of cloudflare_filter (derived from provider schema).
GcsBackend
terraform { backend "gcs" { ... } } configuration.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
ListHostname
Typed helper for the items.hostname block of cloudflare_list (derived from provider schema).
ListItemHostname
Typed helper for the hostname block of cloudflare_list_item (derived from provider schema).
ListItemRedirect
Typed helper for the redirect block of cloudflare_list_item (derived from provider schema).
ListItems
Typed helper for the items block of cloudflare_list (derived from provider schema).
ListRedirect
Typed helper for the items.redirect block of cloudflare_list (derived from provider schema).
ListValue
At most one of asn, ip, hostname, redirect on the items block of cloudflare_list: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
ListValueAsn
The ListValue.asn choice: sets asn.
ListValueHostname
The ListValue.hostname choice: sets hostname.
ListValueIp
The ListValue.ip choice: sets ip.
ListValueRedirect
The ListValue.redirect choice: sets redirect.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
PageRuleActions
Typed helper for the actions block of cloudflare_page_rule (derived from provider schema).
PageRuleCacheKeyFields
Typed helper for the actions.cache_key_fields block of cloudflare_page_rule (derived from provider schema).
PageRuleCookie
Typed helper for the actions.cache_key_fields.cookie block of cloudflare_page_rule (derived from provider schema).
PageRuleForwardingUrl
Typed helper for the actions.forwarding_url block of cloudflare_page_rule (derived from provider schema).
PageRuleHeader
Typed helper for the actions.cache_key_fields.header block of cloudflare_page_rule (derived from provider schema).
PageRuleHost
Typed helper for the actions.cache_key_fields.host block of cloudflare_page_rule (derived from provider schema).
PageRuleQueryString
Typed helper for the actions.cache_key_fields.query_string block of cloudflare_page_rule (derived from provider schema).
PageRuleUser
Typed helper for the actions.cache_key_fields.user block of cloudflare_page_rule (derived from provider schema).
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
RulesetActionParameters
Typed helper for the rules.action_parameters block of cloudflare_ruleset (derived from provider schema).
RulesetAlgorithms
Typed helper for the rules.action_parameters.algorithms block of cloudflare_ruleset (derived from provider schema).
RulesetAutominify
Typed helper for the rules.action_parameters.autominify block of cloudflare_ruleset (derived from provider schema).
RulesetBody
At most one of asset_name, content on the rules.action_parameters block of cloudflare_ruleset: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
RulesetBodyAssetName
The RulesetBody.assetName choice: sets asset_name.
RulesetBodyContent
The RulesetBody.content choice: sets content.
RulesetBrowserTtl
Typed helper for the rules.action_parameters.browser_ttl block of cloudflare_ruleset (derived from provider schema).
RulesetCacheKey
Typed helper for the rules.action_parameters.cache_key block of cloudflare_ruleset (derived from provider schema).
RulesetCacheReserve
Typed helper for the rules.action_parameters.cache_reserve block of cloudflare_ruleset (derived from provider schema).
RulesetCategories
Typed helper for the rules.action_parameters.overrides.categories block of cloudflare_ruleset (derived from provider schema).
RulesetCookie
Typed helper for the rules.action_parameters.cache_key.custom_key.cookie block of cloudflare_ruleset (derived from provider schema).
RulesetCookieFields
Typed helper for the rules.action_parameters.cookie_fields block of cloudflare_ruleset (derived from provider schema).
RulesetCustomKey
Typed helper for the rules.action_parameters.cache_key.custom_key block of cloudflare_ruleset (derived from provider schema).
RulesetDefault
Typed helper for the rules.action_parameters.vary.default block of cloudflare_ruleset (derived from provider schema).
RulesetEdgeTtl
Typed helper for the rules.action_parameters.edge_ttl block of cloudflare_ruleset (derived from provider schema).
RulesetExclude
Exactly one of list, all on the rules.action_parameters.cache_key.custom_key.query_string.exclude block of cloudflare_ruleset: the provider rejects none and more than one, so each variant sets one of them.
RulesetExcludeAll
The RulesetExclude.all choice: sets all.
RulesetExcludeList
The RulesetExclude.list choice: sets list.
RulesetExposedCredentialCheck
Typed helper for the rules.exposed_credential_check block of cloudflare_ruleset (derived from provider schema).
RulesetFromList
Typed helper for the rules.action_parameters.from_list block of cloudflare_ruleset (derived from provider schema).
RulesetFromValue
Typed helper for the rules.action_parameters.from_value block of cloudflare_ruleset (derived from provider schema).
RulesetHeader
Typed helper for the rules.action_parameters.cache_key.custom_key.header block of cloudflare_ruleset (derived from provider schema).
RulesetHeaders
Typed helper for the rules.action_parameters.headers block of cloudflare_ruleset (derived from provider schema).
RulesetHeadersValue
At most one of value, expression on the rules.action_parameters.headers block of cloudflare_ruleset: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
RulesetHeadersValueChoice
The RulesetHeadersValue.value choice: sets value.
RulesetHeadersValueExpression
The RulesetHeadersValue.expression choice: sets expression.
RulesetHost
Typed helper for the rules.action_parameters.cache_key.custom_key.host block of cloudflare_ruleset (derived from provider schema).
RulesetImmutable
Typed helper for the rules.action_parameters.immutable block of cloudflare_ruleset (derived from provider schema).
RulesetInclude
Exactly one of list, all on the rules.action_parameters.cache_key.custom_key.query_string.include block of cloudflare_ruleset: the provider rejects none and more than one, so each variant sets one of them.
RulesetIncludeAll
The RulesetInclude.all choice: sets all.
RulesetIncludeList
The RulesetInclude.list choice: sets list.
RulesetLogging
Typed helper for the rules.logging block of cloudflare_ruleset (derived from provider schema).
RulesetMatch
Exactly one of status_code_range, status_code on the rules.action_parameters.edge_ttl.status_code_ttl block of cloudflare_ruleset: the provider rejects none and more than one, so each variant sets one of them.
RulesetMatchedData
Typed helper for the rules.action_parameters.matched_data block of cloudflare_ruleset (derived from provider schema).
RulesetMatchStatusCode
The RulesetMatch.statusCode choice: sets status_code.
RulesetMatchStatusCodeRange
The RulesetMatch.statusCodeRange choice: sets status_code_range.
RulesetMaxAge
Typed helper for the rules.action_parameters.max_age block of cloudflare_ruleset (derived from provider schema).
RulesetMustRevalidate
Typed helper for the rules.action_parameters.must_revalidate block of cloudflare_ruleset (derived from provider schema).
RulesetMustUnderstand
Typed helper for the rules.action_parameters.must_understand block of cloudflare_ruleset (derived from provider schema).
RulesetNoCache
Typed helper for the rules.action_parameters.no_cache block of cloudflare_ruleset (derived from provider schema).
RulesetNoStore
Typed helper for the rules.action_parameters.no_store block of cloudflare_ruleset (derived from provider schema).
RulesetNoTransform
Typed helper for the rules.action_parameters.no_transform block of cloudflare_ruleset (derived from provider schema).
RulesetOrigin
Typed helper for the rules.action_parameters.origin block of cloudflare_ruleset (derived from provider schema).
RulesetOriginRangeRequests
Typed helper for the rules.action_parameters.origin_range_requests block of cloudflare_ruleset (derived from provider schema).
RulesetOverrides
Typed helper for the rules.action_parameters.overrides block of cloudflare_ruleset (derived from provider schema).
RulesetOverridesRules
Typed helper for the rules.action_parameters.overrides.rules block of cloudflare_ruleset (derived from provider schema).
RulesetPath
Exactly one of value, expression on the rules.action_parameters.uri.path block of cloudflare_ruleset: the provider rejects none and more than one, so each variant sets one of them.
RulesetPathExpression
The RulesetPath.expression choice: sets expression.
RulesetPathValue
The RulesetPath.value choice: sets value.
RulesetPrivate
Typed helper for the rules.action_parameters.private block of cloudflare_ruleset (derived from provider schema).
RulesetProxyRevalidate
Typed helper for the rules.action_parameters.proxy_revalidate block of cloudflare_ruleset (derived from provider schema).
RulesetPublic
Typed helper for the rules.action_parameters.public block of cloudflare_ruleset (derived from provider schema).
RulesetQuery
Exactly one of value, expression on the rules.action_parameters.uri.query block of cloudflare_ruleset: the provider rejects none and more than one, so each variant sets one of them.
RulesetQueryExpression
The RulesetQuery.expression choice: sets expression.
RulesetQueryString
At most one of include, exclude on the rules.action_parameters.cache_key.custom_key.query_string block of cloudflare_ruleset: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
RulesetQueryStringExclude
The RulesetQueryString.exclude choice: sets exclude.
RulesetQueryStringInclude
The RulesetQueryString.include choice: sets include.
RulesetQueryValue
The RulesetQuery.value choice: sets value.
RulesetRatelimit
Typed helper for the rules.ratelimit block of cloudflare_ruleset (derived from provider schema).
RulesetRawResponseFields
Typed helper for the rules.action_parameters.raw_response_fields block of cloudflare_ruleset (derived from provider schema).
RulesetRequestFields
Typed helper for the rules.action_parameters.request_fields block of cloudflare_ruleset (derived from provider schema).
RulesetResponse
Typed helper for the rules.action_parameters.response block of cloudflare_ruleset (derived from provider schema).
RulesetResponseFields
Typed helper for the rules.action_parameters.response_fields block of cloudflare_ruleset (derived from provider schema).
RulesetRules
Typed helper for the rules block of cloudflare_ruleset (derived from provider schema).
RulesetScope
Exactly one of account_id, zone_id on cloudflare_ruleset: the provider rejects none and more than one, so each variant sets one of them.
RulesetScopeAccountId
The RulesetScope.accountId choice: sets account_id.
RulesetScopeZoneId
The RulesetScope.zoneId choice: sets zone_id.
RulesetServeStale
Typed helper for the rules.action_parameters.serve_stale block of cloudflare_ruleset (derived from provider schema).
RulesetSMaxage
Typed helper for the rules.action_parameters.s_maxage block of cloudflare_ruleset (derived from provider schema).
RulesetSni
Typed helper for the rules.action_parameters.sni block of cloudflare_ruleset (derived from provider schema).
RulesetSource
At most one of from_list, from_value on the rules.action_parameters block of cloudflare_ruleset: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
RulesetSourceFromList
The RulesetSource.fromList choice: sets from_list.
RulesetSourceFromValue
The RulesetSource.fromValue choice: sets from_value.
RulesetStaleIfError
Typed helper for the rules.action_parameters.stale_if_error block of cloudflare_ruleset (derived from provider schema).
RulesetStaleWhileRevalidate
Typed helper for the rules.action_parameters.stale_while_revalidate block of cloudflare_ruleset (derived from provider schema).
RulesetStatusCodeRange
Typed helper for the rules.action_parameters.edge_ttl.status_code_ttl.status_code_range block of cloudflare_ruleset (derived from provider schema).
RulesetStatusCodeTtl
Typed helper for the rules.action_parameters.edge_ttl.status_code_ttl block of cloudflare_ruleset (derived from provider schema).
RulesetTargetUrl
Exactly one of value, expression on the rules.action_parameters.from_value.target_url block of cloudflare_ruleset: the provider rejects none and more than one, so each variant sets one of them.
RulesetTargetUrlExpression
The RulesetTargetUrl.expression choice: sets expression.
RulesetTargetUrlValue
The RulesetTargetUrl.value choice: sets value.
RulesetTransformedRequestFields
Typed helper for the rules.action_parameters.transformed_request_fields block of cloudflare_ruleset (derived from provider schema).
RulesetUri
Typed helper for the rules.action_parameters.uri block of cloudflare_ruleset (derived from provider schema).
RulesetUser
Typed helper for the rules.action_parameters.cache_key.custom_key.user block of cloudflare_ruleset (derived from provider schema).
RulesetValue
At most one of values, expression on the rules.action_parameters block of cloudflare_ruleset: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
RulesetValueExpression
The RulesetValue.expression choice: sets expression.
RulesetValueValues
The RulesetValue.values choice: sets values.
RulesetVary
Typed helper for the rules.action_parameters.vary block of cloudflare_ruleset (derived from provider schema).
RulesetVaryHeaders
Typed helper for the rules.action_parameters.vary.headers block of cloudflare_ruleset (derived from provider schema).
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

ListKind
List enum for kind.
OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
PageRuleAutomaticHttpsRewrites
automatic_https_rewrites — derived from the provider schema description.
PageRuleBrowserCheck
browser_check — derived from the provider schema description.
PageRuleCacheByDeviceType
cache_by_device_type — derived from the provider schema description.
PageRuleCacheDeceptionArmor
cache_deception_armor — derived from the provider schema description.
PageRuleCacheLevel
cache_level — derived from the provider schema description.
PageRuleEmailObfuscation
email_obfuscation — derived from the provider schema description.
PageRuleExplicitCacheControl
explicit_cache_control — derived from the provider schema description.
PageRuleIpGeolocation
ip_geolocation — derived from the provider schema description.
PageRuleMirage
mirage — derived from the provider schema description.
PageRuleOpportunisticEncryption
opportunistic_encryption — derived from the provider schema description.
PageRuleOriginErrorPagePassThru
origin_error_page_pass_thru — derived from the provider schema description.
PageRulePolish
polish — derived from the provider schema description.
PageRuleRespectStrongEtag
respect_strong_etag — derived from the provider schema description.
PageRuleResponseBuffering
response_buffering — derived from the provider schema description.
PageRuleRocketLoader
rocket_loader — derived from the provider schema description.
PageRuleSecurityLevel
security_level — derived from the provider schema description.
PageRuleSortQueryStringForCache
sort_query_string_for_cache — derived from the provider schema description.
PageRuleSsl
ssl — derived from the provider schema description.
PageRuleStatus
Page Rule enum for status.
PageRuleTrueClientIpHeader
true_client_ip_header — derived from the provider schema description.
PageRuleWaf
waf — derived from the provider schema description.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).
Ruleset
ruleset — derived from the provider schema description.
RulesetAction
action — derived from the provider schema description.
RulesetAlgorithmsName
name — derived from the provider schema description.
RulesetBrowserTtlMode
mode — derived from the provider schema description.
RulesetContentType
content_type — derived from the provider schema description.
RulesetDefaultAction
action — derived from the provider schema description.
RulesetEdgeTtlMode
mode — derived from the provider schema description.
RulesetHeadersOperation
operation — derived from the provider schema description.
RulesetImmutableOperation
operation — derived from the provider schema description.
RulesetKind
Ruleset enum for kind.
RulesetOperation
operation — derived from the provider schema description.
RulesetOriginRangeRequestsMode
mode — derived from the provider schema description.
RulesetPhase
Ruleset enum for phase.
RulesetPhases
phases — derived from the provider schema description.
RulesetPolish
polish — derived from the provider schema description.
RulesetProducts
products — derived from the provider schema description.
RulesetRequestBodyBuffering
request_body_buffering — derived from the provider schema description.
RulesetResponseBodyBuffering
response_body_buffering — derived from the provider schema description.
RulesetSecurityLevel
security_level — derived from the provider schema description.
RulesetSensitivityLevel
sensitivity_level — derived from the provider schema description.
RulesetSsl
ssl — derived from the provider schema description.
UrlNormalizationSettingsScope
Url Normalization Settings enum for scope.
UrlNormalizationSettingsType
Url Normalization Settings enum for type.

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.