security library

Cloudflare WAF, bot management, firewall, and related security.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
CloudflareBotManagement
Factory wrapper for cloudflare_bot_management.
CloudflareContentScanning
Factory wrapper for cloudflare_content_scanning.
CloudflareContentScanningExpression
Factory wrapper for cloudflare_content_scanning_expression.
CloudflareFirewallRule
Factory wrapper for cloudflare_firewall_rule.
CloudflareLeakedCredentialCheck
Factory wrapper for cloudflare_leaked_credential_check.
CloudflareLeakedCredentialCheckRule
Factory wrapper for cloudflare_leaked_credential_check_rule.
CloudflarePageShieldPolicy
Factory wrapper for cloudflare_page_shield_policy.
CloudflareRateLimit
Factory wrapper for cloudflare_rate_limit.
CloudflareUserAgentBlockingRule
Factory wrapper for cloudflare_user_agent_blocking_rule.
CloudflareVulnerabilityScannerCredential
Factory wrapper for cloudflare_vulnerability_scanner_credential.
CloudflareVulnerabilityScannerCredentialSet
Factory wrapper for cloudflare_vulnerability_scanner_credential_set.
CloudflareVulnerabilityScannerTargetEnvironment
Factory wrapper for cloudflare_vulnerability_scanner_target_environment.
ContentScanningExpressionBody
Typed helper for the body block of cloudflare_content_scanning_expression (derived from provider schema).
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataCloudflareBotManagement
Factory wrapper for cloudflare_bot_management.
DataCloudflareContentScanning
Factory wrapper for cloudflare_content_scanning.
DataCloudflareContentScanningExpressions
Factory wrapper for cloudflare_content_scanning_expressions.
DataCloudflareFirewallRule
Factory wrapper for cloudflare_firewall_rule.
DataCloudflareLeakedCredentialCheck
Factory wrapper for cloudflare_leaked_credential_check.
DataCloudflareLeakedCredentialCheckRule
Factory wrapper for cloudflare_leaked_credential_check_rule.
DataCloudflareLeakedCredentialCheckRules
Factory wrapper for cloudflare_leaked_credential_check_rules.
DataCloudflarePageShieldConnections
Factory wrapper for cloudflare_page_shield_connections.
DataCloudflarePageShieldConnectionsList
Factory wrapper for cloudflare_page_shield_connections_list.
DataCloudflarePageShieldCookies
Factory wrapper for cloudflare_page_shield_cookies.
DataCloudflarePageShieldCookiesList
Factory wrapper for cloudflare_page_shield_cookies_list.
DataCloudflarePageShieldPolicies
Factory wrapper for cloudflare_page_shield_policies.
DataCloudflarePageShieldPolicy
Factory wrapper for cloudflare_page_shield_policy.
DataCloudflarePageShieldScripts
Factory wrapper for cloudflare_page_shield_scripts.
DataCloudflarePageShieldScriptsList
Factory wrapper for cloudflare_page_shield_scripts_list.
DataCloudflareRateLimit
Factory wrapper for cloudflare_rate_limit.
DataCloudflareUserAgentBlockingRule
Factory wrapper for cloudflare_user_agent_blocking_rule.
DataCloudflareVulnerabilityScannerCredential
Factory wrapper for cloudflare_vulnerability_scanner_credential.
DataCloudflareVulnerabilityScannerCredentials
Factory wrapper for cloudflare_vulnerability_scanner_credentials.
DataCloudflareVulnerabilityScannerCredentialSet
Factory wrapper for cloudflare_vulnerability_scanner_credential_set.
DataCloudflareVulnerabilityScannerCredentialSets
Factory wrapper for cloudflare_vulnerability_scanner_credential_sets.
DataCloudflareVulnerabilityScannerTargetEnvironment
Factory wrapper for cloudflare_vulnerability_scanner_target_environment.
DataCloudflareVulnerabilityScannerTargetEnvironments
Factory wrapper for cloudflare_vulnerability_scanner_target_environments.
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
DataUserAgentBlockingRuleFilter
Typed helper for the filter block of cloudflare_user_agent_blocking_rule (derived from provider schema).
EnvironmentConstant
The AppConstant.fromEnvironment choice.
FirewallRuleAction
Typed helper for the action block of cloudflare_firewall_rule (derived from provider schema).
FirewallRuleFilter
Typed helper for the filter block of cloudflare_firewall_rule (derived from provider schema).
FirewallRuleResponse
Typed helper for the action.response block of cloudflare_firewall_rule (derived from provider schema).
GcsBackend
terraform { backend "gcs" { ... } } configuration.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RateLimitAction
Typed helper for the action block of cloudflare_rate_limit (derived from provider schema).
RateLimitActionResponse
Typed helper for the action.response block of cloudflare_rate_limit (derived from provider schema).
RateLimitHeaders
Typed helper for the match.headers block of cloudflare_rate_limit (derived from provider schema).
RateLimitMatch
Typed helper for the match block of cloudflare_rate_limit (derived from provider schema).
RateLimitMatchResponse
Typed helper for the match.response block of cloudflare_rate_limit (derived from provider schema).
RateLimitRequest
Typed helper for the match.request block of cloudflare_rate_limit (derived from provider schema).
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
UserAgentBlockingRuleConfiguration
Typed helper for the configuration block of cloudflare_user_agent_blocking_rule (derived from provider schema).
ValueConstant<T>
The AppConstant.value choice.
VulnerabilityScannerTargetEnvironmentTarget
Typed helper for the target block of cloudflare_vulnerability_scanner_target_environment (derived from provider schema).

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

BotManagementAiBotsProtection
Bot Management Ai Bots enum for ai_bots_protection.
BotManagementAisearch
Bot Management enum for aisearch.
BotManagementAiTraining
Bot Management Ai enum for ai_training.
BotManagementAiUser
Bot Management Ai enum for ai_user.
BotManagementCfRobotsVariant
Bot Management Cf Robots enum for cf_robots_variant.
BotManagementContentBotsProtection
Bot Management Content Bots enum for content_bots_protection.
BotManagementCrawlerProtection
Bot Management Crawler enum for crawler_protection.
BotManagementSbfmDefinitelyAutomated
Bot Management Sbfm Definitely enum for sbfm_definitely_automated.
BotManagementSbfmLikelyAutomated
Bot Management Sbfm Likely enum for sbfm_likely_automated.
BotManagementSbfmVerifiedBots
Bot Management Sbfm Verified enum for sbfm_verified_bots.
ContentScanningValue
Content Scanning enum for value.
FirewallRuleMode
mode — derived from the provider schema description.
OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
PageShieldPolicyAction
Page Shield Policy enum for action.
RateLimitMethods
methods — derived from the provider schema description.
RateLimitMode
mode — derived from the provider schema description.
RateLimitOp
op — derived from the provider schema description.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).
UserAgentBlockingRuleMode
User Agent Blocking Rule enum for mode.
UserAgentBlockingRuleTarget
target — derived from the provider schema description.
VulnerabilityScannerCredentialLocation
Vulnerability Scanner Credential enum for location.
VulnerabilityScannerTargetEnvironmentType
type — derived from the provider schema description.

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.