GoogleProjectIamCustomRole class final
Factory wrapper for google_project_iam_custom_role.
Defines a project-level custom IAM role: a named bundle of low-level
permissions that can be granted via google_project_iam_member /
_iam_binding like any predefined role. Custom roles let you express
"least privilege" surfaces that don't exist as a predefined role
(e.g. read access to a single GCS bucket plus list on a single
Pub/Sub topic).
Required identity:
localName: Terraform local name.roleId: short ID; the final segment of the role's full path. Must be 3-64 chars matching[a-zA-Z0-9_\.]+. The role's full name isprojects/{project}/roles/{roleId}.title: human-readable name (≤100 chars).permissions: set of low-level permission strings, e.g.'storage.objects.get','storage.objects.list'. Each entry must be a real GCP permission — Terraform asks the API to validate the list at apply time and any unknown entry fails the resource.
Optional:
description: free-form text.stage: lifecycle stage of the custom role itself (CustomRoleStage). Surfaces in the GCP console; the role is grantable inalpha/beta/gaand unusable indisabled/deprecated.
ForceNew note: roleId is immutable after creation. Renaming
requires destroying and recreating the role, which detaches every
existing IAM binding that referenced it.
Constructors
-
GoogleProjectIamCustomRole({required String localName, required TfArg<
String> roleId, required TfArg<String> title, required TfArg<List< permissions, TfArg<String> >String> ? description, TfArg<CustomRoleStage> ? stage, TfArg<String> ? project, LifecycleOptions? lifecycle, List<DependencyTarget> ? dependsOn, String? provider, TfTimeouts? timeouts})
Properties
-
argMap
→ Map<
String, TfArg?> -
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name).
Synth emits these keys directly; the factory is responsible for the
camelCase → snake_case translation at construction time.
finalinherited
-
deleted
→ TfRef<
bool> -
Reference to
deletedattribute —trueonce the role has been soft-deleted (custom roles enter a 7-day grace window before permanent removal).no setter -
dependsOn
→ List<
DependencyTarget> ? -
Optional
depends_on = [...]. Each entry is aDependencyTarget— either a wholesale resource (rendered as bare address) or an explicitTfRef(rendered viabareAddress).finalinherited - hashCode → int
-
The hash code for this object.
no setterinherited
-
id
→ TfRef<
String> -
Reference to
idattribute (full role pathprojects/{project}/roles/{roleId}).no setter - kind → ResourceKind
-
Always
ResourceKind.resource. Overridden byData.no setterinherited - lifecycle → LifecycleOptions?
-
Optional
lifecycle { ... }block.finalinherited - localName → String
-
User-supplied local name within a Stack.
finalinherited
-
nameRef
→ TfRef<
String> -
Reference to
nameattribute — same shape as id; the API returns it asprojects/{project}/roles/{roleId}.no setter - provider → String?
-
Optional Terraform
providermeta-argument: a provider name ('google-beta'on a GA type) or aname.aliaspair ('google.eu').finalinherited - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
sensitiveFields
→ Set<
String> -
Field names that are
@Sensitiveper the IR-derived per-resource constant. Curated factories override with a baked-instatic const Set<String>(file-private in v0.5+).no setter - supportsDeletionProtection → bool
-
Capability flag: true when this resource's underlying Terraform
schema has a
deletion_protectionboolean attribute that the synth-time devMode flow can flip tofalse. Defaults to false; the codegen emitter overrides this totruefor wrappers whose schema includes the attribute.no setterinherited - terraformType → String
-
Terraform resource type, e.g.
google_pubsub_topic.finalinherited - tfAddress → String
-
no setterinherited
- timeouts → TfTimeouts?
-
Optional
timeouts { ... }block: how long Terraform waits for each operation. Provider-neutral likelifecycle— synth copies the duration strings verbatim, andterraform validatedecides whether this resource's schema declares the operations set here.finalinherited
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited