GoogleComputeSecurityPolicy class final

Factory wrapper for google_compute_security_policy.

Google Cloud Armor: a layer-7 WAF / DDoS / rate-limiting policy that attaches to one or more google_compute_backend_service (via that resource's securityPolicy field) or to backend buckets for edge variants.

Required identity:

  • localName: Terraform local name (the address segment after google_compute_security_policy.).
  • name: GCP resource name (1-63 chars, lowercase RFC1035).

Policy intent:

selfLink is the canonical reference google_compute_backend_service.security_policy expects. Use nameRef when wiring the policy name. fingerprint is used by the API for optimistic locking on updates.

Example (deny-by-default with a JP allow-list):

final policy = GoogleComputeSecurityPolicy(
  localName: 'edge_deny_all',
  name: TfArg.literal('edge-deny-all'),
  type: TfArg.literal(SecurityPolicyType.cloudArmorEdge),
  rules: [
    // Higher-priority allow for JP traffic.
    ComputeSecurityPolicySecurityPolicyRule(
      priority: 1000,
      action: SecurityPolicyRuleAction.allow,
      match: ComputeSecurityPolicySecurityPolicyRuleMatch.expr(
        ComputeSecurityPolicySecurityPolicyRuleMatchExpr(
          expression: "origin.region_code == 'JP'",
        ),
      ),
      description: 'allow JP',
    ),
    // Default-deny (lowest priority, match all).
    ComputeSecurityPolicySecurityPolicyRule(
      priority: 2147483647,
      action: SecurityPolicyRuleAction.deny403,
      match: ComputeSecurityPolicySecurityPolicyRuleMatch.config(
        versionedExpr: SecurityPolicyRuleMatchVersionedExpr.srcIpsV1,
        config: ComputeSecurityPolicySecurityPolicyRuleMatchConfig(srcIpRanges: ['*']),
      ),
      description: 'default deny',
    ),
  ],
);

Example (rate-limit on /api/*, redirect overflow to a CAPTCHA):

ComputeSecurityPolicySecurityPolicyRule(
  priority: 500,
  action: SecurityPolicyRuleAction.throttle,
  match: ComputeSecurityPolicySecurityPolicyRuleMatch.expr(
    ComputeSecurityPolicySecurityPolicyRuleMatchExpr(
      expression: "request.path.matches('/api/.*')",
    ),
  ),
  rateLimitOptions: ComputeSecurityPolicySecurityPolicyRuleRateLimitOptions(
    conformAction: 'allow',
    exceedAction: 'redirect',
    rateLimitThreshold: ComputeSecurityPolicySecurityPolicyRuleRateLimitThreshold(
      count: 100,
      intervalSec: 60,
    ),
    exceedRedirectOptions: ComputeSecurityPolicySecurityPolicyRuleRedirectOptions(
      type: 'GOOGLE_RECAPTCHA',
    ),
  ),
);

All nested classes are prefixed with SecurityPolicy to avoid collisions with other Cloud Armor / load-balancing wrappers that reuse the same Terraform field names (config, expr, match, header_action, ...).

Constructors

GoogleComputeSecurityPolicy({required String localName, required TfArg<String> name, TfArg<String>? description, TfArg<SecurityPolicyType>? type, required List<ComputeSecurityPolicySecurityPolicyRule> rules, ComputeSecurityPolicySecurityPolicyAdaptiveProtectionConfig? adaptiveProtectionConfig, ComputeSecurityPolicySecurityPolicyAdvancedOptionsConfig? advancedOptionsConfig, ComputeSecurityPolicySecurityPolicyRecaptchaOptionsConfig? recaptchaOptionsConfig, TfArg<Map<String, String>>? labels, TfArg<String>? project, LifecycleOptions? lifecycle, List<DependencyTarget>? dependsOn, String? provider, TfTimeouts? timeouts})

Properties

argMap Map<String, TfArg?>
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name). Synth emits these keys directly; the factory is responsible for the camelCase → snake_case translation at construction time.
finalinherited
dependsOn List<DependencyTarget>?
Optional depends_on = [...]. Each entry is a DependencyTarget — either a wholesale resource (rendered as bare address) or an explicit TfRef (rendered via bareAddress).
finalinherited
effectiveLabels → TfRef<Map<String, String>>
Reference to effective_labels attribute.
no setter
fingerprint → TfRef<String>
Reference to fingerprint attribute.
no setter
hashCode int
The hash code for this object.
no setterinherited
id → TfRef<String>
Reference to id attribute.
no setter
kind → ResourceKind
Always ResourceKind.resource. Overridden by Data.
no setterinherited
labelFingerprint → TfRef<String>
Reference to label_fingerprint attribute.
no setter
lifecycle → LifecycleOptions?
Optional lifecycle { ... } block.
finalinherited
localName String
User-supplied local name within a Stack.
finalinherited
nameRef → TfRef<String>
Reference to name attribute.
no setter
provider String?
Optional Terraform provider meta-argument: a provider name ('google-beta' on a GA type) or a name.alias pair ('google.eu').
finalinherited
runtimeType Type
A representation of the runtime type of the object.
no setterinherited
Reference to self_link attribute.
no setter
sensitiveFields Set<String>
Field names that are @Sensitive per the IR-derived per-resource constant. Curated factories override with a baked-in static const Set<String> (file-private in v0.5+).
no setter
supportsDeletionProtection bool
Capability flag: true when this resource's underlying Terraform schema has a deletion_protection boolean attribute that the synth-time devMode flow can flip to false. Defaults to false; the codegen emitter overrides this to true for wrappers whose schema includes the attribute.
no setterinherited
terraformLabels → TfRef<Map<String, String>>
Reference to terraform_labels attribute.
no setter
terraformType String
Terraform resource type, e.g. google_pubsub_topic.
finalinherited
tfAddress String
no setterinherited
timeouts → TfTimeouts?
Optional timeouts { ... } block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, and terraform validate decides whether this resource's schema declares the operations set here.
finalinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() String
A string representation of this object.
inherited

Operators

operator ==(Object other) bool
The equality operator.
inherited

Constants

tfType → const String