GoogleComputeSecurityPolicy class final
Factory wrapper for google_compute_security_policy.
Google Cloud Armor: a layer-7 WAF / DDoS / rate-limiting policy that
attaches to one or more google_compute_backend_service (via that
resource's securityPolicy field) or to backend buckets for edge
variants.
Required identity:
localName: Terraform local name (the address segment aftergoogle_compute_security_policy.).name: GCP resource name (1-63 chars, lowercase RFC1035).
Policy intent:
type: pick SecurityPolicyType.cloudArmor for backend-service policies (the default and most common), SecurityPolicyType.cloudArmorEdge for edge policies that filter at Google's cache layer (cache-bypass protection, applied to backend services and backend buckets), or SecurityPolicyType.cloudArmorNetwork for Network Load Balancing.rules: at least one ComputeSecurityPolicySecurityPolicyRule. Cloud Armor always needs a default rule (priority2147483647, match'*') -- if you omit it the provider auto-injects one with actionallow, which is rarely what you want for a deny-list policy. Author the default-deny explicitly.
selfLink is the canonical reference
google_compute_backend_service.security_policy expects. Use
nameRef when wiring the policy name. fingerprint is used by the
API for optimistic locking on updates.
Example (deny-by-default with a JP allow-list):
final policy = GoogleComputeSecurityPolicy(
localName: 'edge_deny_all',
name: TfArg.literal('edge-deny-all'),
type: TfArg.literal(SecurityPolicyType.cloudArmorEdge),
rules: [
// Higher-priority allow for JP traffic.
ComputeSecurityPolicySecurityPolicyRule(
priority: 1000,
action: SecurityPolicyRuleAction.allow,
match: ComputeSecurityPolicySecurityPolicyRuleMatch.expr(
ComputeSecurityPolicySecurityPolicyRuleMatchExpr(
expression: "origin.region_code == 'JP'",
),
),
description: 'allow JP',
),
// Default-deny (lowest priority, match all).
ComputeSecurityPolicySecurityPolicyRule(
priority: 2147483647,
action: SecurityPolicyRuleAction.deny403,
match: ComputeSecurityPolicySecurityPolicyRuleMatch.config(
versionedExpr: SecurityPolicyRuleMatchVersionedExpr.srcIpsV1,
config: ComputeSecurityPolicySecurityPolicyRuleMatchConfig(srcIpRanges: ['*']),
),
description: 'default deny',
),
],
);
Example (rate-limit on /api/*, redirect overflow to a CAPTCHA):
ComputeSecurityPolicySecurityPolicyRule(
priority: 500,
action: SecurityPolicyRuleAction.throttle,
match: ComputeSecurityPolicySecurityPolicyRuleMatch.expr(
ComputeSecurityPolicySecurityPolicyRuleMatchExpr(
expression: "request.path.matches('/api/.*')",
),
),
rateLimitOptions: ComputeSecurityPolicySecurityPolicyRuleRateLimitOptions(
conformAction: 'allow',
exceedAction: 'redirect',
rateLimitThreshold: ComputeSecurityPolicySecurityPolicyRuleRateLimitThreshold(
count: 100,
intervalSec: 60,
),
exceedRedirectOptions: ComputeSecurityPolicySecurityPolicyRuleRedirectOptions(
type: 'GOOGLE_RECAPTCHA',
),
),
);
All nested classes are prefixed with SecurityPolicy to avoid
collisions with other Cloud Armor / load-balancing wrappers that
reuse the same Terraform field names (config, expr, match,
header_action, ...).
Constructors
-
GoogleComputeSecurityPolicy({required String localName, required TfArg<
String> name, TfArg<String> ? description, TfArg<SecurityPolicyType> ? type, required List<ComputeSecurityPolicySecurityPolicyRule> rules, ComputeSecurityPolicySecurityPolicyAdaptiveProtectionConfig? adaptiveProtectionConfig, ComputeSecurityPolicySecurityPolicyAdvancedOptionsConfig? advancedOptionsConfig, ComputeSecurityPolicySecurityPolicyRecaptchaOptionsConfig? recaptchaOptionsConfig, TfArg<Map< ? labels, TfArg<String, String> >String> ? project, LifecycleOptions? lifecycle, List<DependencyTarget> ? dependsOn, String? provider, TfTimeouts? timeouts})
Properties
-
argMap
→ Map<
String, TfArg?> -
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name).
Synth emits these keys directly; the factory is responsible for the
camelCase → snake_case translation at construction time.
finalinherited
-
dependsOn
→ List<
DependencyTarget> ? -
Optional
depends_on = [...]. Each entry is aDependencyTarget— either a wholesale resource (rendered as bare address) or an explicitTfRef(rendered viabareAddress).finalinherited -
effectiveLabels
→ TfRef<
Map< String, String> > -
Reference to
effective_labelsattribute.no setter -
fingerprint
→ TfRef<
String> -
Reference to
fingerprintattribute.no setter - hashCode → int
-
The hash code for this object.
no setterinherited
-
id
→ TfRef<
String> -
Reference to
idattribute.no setter - kind → ResourceKind
-
Always
ResourceKind.resource. Overridden byData.no setterinherited -
labelFingerprint
→ TfRef<
String> -
Reference to
label_fingerprintattribute.no setter - lifecycle → LifecycleOptions?
-
Optional
lifecycle { ... }block.finalinherited - localName → String
-
User-supplied local name within a Stack.
finalinherited
-
nameRef
→ TfRef<
String> -
Reference to
nameattribute.no setter - provider → String?
-
Optional Terraform
providermeta-argument: a provider name ('google-beta'on a GA type) or aname.aliaspair ('google.eu').finalinherited - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
selfLink
→ TfRef<
String> -
Reference to
self_linkattribute.no setter -
sensitiveFields
→ Set<
String> -
Field names that are
@Sensitiveper the IR-derived per-resource constant. Curated factories override with a baked-instatic const Set<String>(file-private in v0.5+).no setter - supportsDeletionProtection → bool
-
Capability flag: true when this resource's underlying Terraform
schema has a
deletion_protectionboolean attribute that the synth-time devMode flow can flip tofalse. Defaults to false; the codegen emitter overrides this totruefor wrappers whose schema includes the attribute.no setterinherited -
terraformLabels
→ TfRef<
Map< String, String> > -
Reference to
terraform_labelsattribute.no setter - terraformType → String
-
Terraform resource type, e.g.
google_pubsub_topic.finalinherited - tfAddress → String
-
no setterinherited
- timeouts → TfTimeouts?
-
Optional
timeouts { ... }block: how long Terraform waits for each operation. Provider-neutral likelifecycle— synth copies the duration strings verbatim, andterraform validatedecides whether this resource's schema declares the operations set here.finalinherited
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited