GoogleKmsProjectAutokeyConfig class final

Factory wrapper for google_kms_project_autokey_config.

ProjectAutokeyConfig is a singleton resource used to configure the auto-provisioning flow of CryptoKeys for CMEK.

~> Note: ProjectAutokeyConfigs cannot be deleted from Google Cloud Platform. Destroying a Terraform-managed ProjectAutokeyConfigs will remove it from state but will not delete the resource from the project.

Project-level Cloud KMS Autokey config — a singleton that controls whether Autokey auto-provisions CMEK CryptoKeys for this project.

Prefer keyProjectResolutionMode DISABLED for smoke stacks: the config is free metadata and does not create keys. Setting RESOURCE_PROJECT enables Autokey provisioning (HSM Autokey key SKUs apply only when keys are created).

Enable cloudkms.googleapis.com via GoogleProjectService (or Apis.enable with Barrels.kmsApi) before apply.

Note: Project Autokey configs cannot be deleted from GCP. Destroying a Terraform-managed config removes it from state but does not delete the singleton from the project (fields are cleared / abandoned per deletionPolicy).

Example:

GoogleKmsProjectAutokeyConfig(
  localName: 'autokey',
  keyProjectResolutionMode: TfArg.literal(
    KmsProjectAutokeyConfigKeyProjectResolutionMode.disabled,
  ),
);

Constructors

GoogleKmsProjectAutokeyConfig({required String localName, TfArg<KmsProjectAutokeyConfigKeyProjectResolutionMode>? keyProjectResolutionMode, TfArg<String>? deletionPolicy, TfArg<String>? project, LifecycleOptions? lifecycle, List<DependencyTarget>? dependsOn, String? provider, TfTimeouts? timeouts})

Properties

argMap Map<String, TfArg?>
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name). Synth emits these keys directly; the factory is responsible for the camelCase → snake_case translation at construction time.
finalinherited
dependsOn List<DependencyTarget>?
Optional depends_on = [...]. Each entry is a DependencyTarget — either a wholesale resource (rendered as bare address) or an explicit TfRef (rendered via bareAddress).
finalinherited
etag → TfRef<String>
Reference to etag attribute.
no setter
hashCode int
The hash code for this object.
no setterinherited
id → TfRef<String>
Reference to id attribute.
no setter
kind → ResourceKind
Always ResourceKind.resource. Overridden by Data.
no setterinherited
lifecycle → LifecycleOptions?
Optional lifecycle { ... } block.
finalinherited
localName String
User-supplied local name within a Stack.
finalinherited
provider String?
Optional Terraform provider meta-argument: a provider name ('google-beta' on a GA type) or a name.alias pair ('google.eu').
finalinherited
runtimeType Type
A representation of the runtime type of the object.
no setterinherited
sensitiveFields Set<String>
Field names that are @Sensitive per the IR-derived per-resource constant. Curated factories override with a baked-in static const Set<String> (file-private in v0.5+).
no setter
supportsDeletionProtection bool
Capability flag: true when this resource's underlying Terraform schema has a deletion_protection boolean attribute that the synth-time devMode flow can flip to false. Defaults to false; the codegen emitter overrides this to true for wrappers whose schema includes the attribute.
no setterinherited
terraformType String
Terraform resource type, e.g. google_pubsub_topic.
finalinherited
tfAddress String
no setterinherited
timeouts → TfTimeouts?
Optional timeouts { ... } block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, and terraform validate decides whether this resource's schema declares the operations set here.
finalinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() String
A string representation of this object.
inherited

Operators

operator ==(Object other) bool
The equality operator.
inherited

Constants

tfType → const String