GoogleProjectIamCustomRole class final

Factory wrapper for google_project_iam_custom_role.

Defines a project-level custom IAM role: a named bundle of low-level permissions that can be granted via google_project_iam_member / _iam_binding like any predefined role. Custom roles let you express "least privilege" surfaces that don't exist as a predefined role (e.g. read access to a single GCS bucket plus list on a single Pub/Sub topic).

Required identity:

  • localName: Terraform local name.
  • roleId: short ID; the final segment of the role's full path. Must be 3-64 chars matching [a-zA-Z0-9_\.]+. The role's full name is projects/{project}/roles/{roleId}.
  • title: human-readable name (≤100 chars).
  • permissions: set of low-level permission strings, e.g. 'storage.objects.get', 'storage.objects.list'. Each entry must be a real GCP permission — Terraform asks the API to validate the list at apply time and any unknown entry fails the resource.

Optional:

  • description: free-form text.
  • stage: lifecycle stage of the custom role itself (CustomRoleStage). Surfaces in the GCP console; the role is grantable in alpha / beta / ga and unusable in disabled / deprecated.

ForceNew note: roleId is immutable after creation. Renaming requires destroying and recreating the role, which detaches every existing IAM binding that referenced it.

Constructors

GoogleProjectIamCustomRole({required String localName, required TfArg<String> roleId, required TfArg<String> title, required TfArg<List<String>> permissions, TfArg<String>? description, TfArg<CustomRoleStage>? stage, TfArg<String>? project, LifecycleOptions? lifecycle, List<DependencyTarget>? dependsOn, String? provider, TfTimeouts? timeouts})

Properties

argMap Map<String, TfArg?>
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name). Synth emits these keys directly; the factory is responsible for the camelCase → snake_case translation at construction time.
finalinherited
deleted → TfRef<bool>
Reference to deleted attribute — true once the role has been soft-deleted (custom roles enter a 7-day grace window before permanent removal).
no setter
dependsOn List<DependencyTarget>?
Optional depends_on = [...]. Each entry is a DependencyTarget — either a wholesale resource (rendered as bare address) or an explicit TfRef (rendered via bareAddress).
finalinherited
hashCode int
The hash code for this object.
no setterinherited
id → TfRef<String>
Reference to id attribute (full role path projects/{project}/roles/{roleId}).
no setter
kind → ResourceKind
Always ResourceKind.resource. Overridden by Data.
no setterinherited
lifecycle → LifecycleOptions?
Optional lifecycle { ... } block.
finalinherited
localName String
User-supplied local name within a Stack.
finalinherited
nameRef → TfRef<String>
Reference to name attribute — same shape as id; the API returns it as projects/{project}/roles/{roleId}.
no setter
provider String?
Optional Terraform provider meta-argument: a provider name ('google-beta' on a GA type) or a name.alias pair ('google.eu').
finalinherited
runtimeType Type
A representation of the runtime type of the object.
no setterinherited
sensitiveFields Set<String>
Field names that are @Sensitive per the IR-derived per-resource constant. Curated factories override with a baked-in static const Set<String> (file-private in v0.5+).
no setter
supportsDeletionProtection bool
Capability flag: true when this resource's underlying Terraform schema has a deletion_protection boolean attribute that the synth-time devMode flow can flip to false. Defaults to false; the codegen emitter overrides this to true for wrappers whose schema includes the attribute.
no setterinherited
terraformType String
Terraform resource type, e.g. google_pubsub_topic.
finalinherited
tfAddress String
no setterinherited
timeouts → TfTimeouts?
Optional timeouts { ... } block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, and terraform validate decides whether this resource's schema declares the operations set here.
finalinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() String
A string representation of this object.
inherited

Operators

operator ==(Object other) bool
The equality operator.
inherited

Constants

tfType → const String