cloud_security_compliance library

Compliance Manager — cloud controls, frameworks, and framework deployments. Org/folder scoped; apply-excluded leftover factories.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
CloudSecurityComplianceCloudControlAllowedValues
Typed helper for the parameter_spec.validation.allowed_values block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlAllowedValuesValues
Typed helper for the parameter_spec.sub_parameters.sub_parameters.validation.allowed_values.values block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlAttributeSubstitutionRule
Typed helper for the parameter_spec.substitution_rules.attribute_substitution_rule block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlCelExpression
Typed helper for the rules.cel_expression block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlDefaultValue
Typed helper for the parameter_spec.default_value block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlIntRange
Typed helper for the parameter_spec.validation.int_range block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlOneofValue
Typed helper for the parameter_spec.default_value.oneof_value block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlOneofValueParameterValue
Typed helper for the parameter_spec.default_value.oneof_value.parameter_value.oneof_value.parameter_value block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlParameterSpec
Typed helper for the parameter_spec block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlParameterValue
Typed helper for the parameter_spec.default_value.oneof_value.parameter_value block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlParameterValueOneofValue
Typed helper for the parameter_spec.default_value.oneof_value.parameter_value.oneof_value block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlPlaceholderSubstitutionRule
Typed helper for the parameter_spec.substitution_rules.placeholder_substitution_rule block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlRegexpPattern
Typed helper for the parameter_spec.validation.regexp_pattern block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlResourceTypesValues
Typed helper for the rules.cel_expression.resource_types_values block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlRules
Typed helper for the rules block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlStringListValue
Typed helper for the parameter_spec.default_value.string_list_value block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlSubParameters
Typed helper for the parameter_spec.sub_parameters block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlSubParametersDefaultValue
Typed helper for the parameter_spec.sub_parameters.sub_parameters.default_value block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlSubParametersSubParameters
Typed helper for the parameter_spec.sub_parameters.sub_parameters block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlSubParametersValidation
Typed helper for the parameter_spec.sub_parameters.sub_parameters.validation block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlSubstitutionRules
Typed helper for the parameter_spec.substitution_rules block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlValidation
Typed helper for the parameter_spec.validation block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceCloudControlValidationAllowedValues
Typed helper for the parameter_spec.sub_parameters.sub_parameters.validation.allowed_values block of google_cloud_security_compliance_cloud_control (derived from provider schema).
CloudSecurityComplianceCloudControlValues
Typed helper for the parameter_spec.validation.allowed_values.values block of google_cloud_security_compliance_cloud_control (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceFrameworkCloudControlDetails
Typed helper for the cloud_control_details block of google_cloud_security_compliance_framework (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentCloudControlDetails
Typed helper for the cloud_control_metadata.cloud_control_details block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentCloudControlMetadata
Typed helper for the cloud_control_metadata block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentFolderCreationConfig
Typed helper for the target_resource_config.target_resource_creation_config.folder_creation_config block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentFramework
Typed helper for the framework block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentOneofValue
Typed helper for the cloud_control_metadata.cloud_control_details.parameters.parameter_value.oneof_value block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentOneofValueParameterValue
Typed helper for the cloud_control_metadata.cloud_control_details.parameters.parameter_value.oneof_value.parameter_value block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentParameters
Typed helper for the cloud_control_metadata.cloud_control_details.parameters block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentParameterValue
Typed helper for the cloud_control_metadata.cloud_control_details.parameters.parameter_value block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentProjectCreationConfig
Typed helper for the target_resource_config.target_resource_creation_config.project_creation_config block of google_cloud_security_compliance_framework_deployment (derived from provider schema).
CloudSecurityComplianceFrameworkDeploymentStringListValue
Typed helper for the cloud_control_metadata.cloud_control_details.parameters.parameter_value.string_list_value block of google_cloud_security_compliance_framework_deployment (derived from provider schema). Shared by every block of this shape in the resource.
CloudSecurityComplianceFrameworkDeploymentTargetResourceConfig
Exactly one of existing_target_resource, target_resource_creation_config on the target_resource_config block of google_cloud_security_compliance_framework_deployment: the provider rejects none and more than one, so each variant sets one of them.
CloudSecurityComplianceFrameworkDeploymentTargetResourceConfigExistingTargetResource
The CloudSecurityComplianceFrameworkDeploymentTargetResourceConfig.existingTargetResource choice: sets existing_target_resource.
CloudSecurityComplianceFrameworkDeploymentTargetResourceConfigTargetResourceCreationConfig
The CloudSecurityComplianceFrameworkDeploymentTargetResourceConfig.targetResourceCreationConfig choice: sets target_resource_creation_config.
CloudSecurityComplianceFrameworkDeploymentTargetResourceCreationConfig
Exactly one of folder_creation_config, project_creation_config on the target_resource_config.target_resource_creation_config block of google_cloud_security_compliance_framework_deployment: the provider rejects none and more than one, so each variant sets one of them.
CloudSecurityComplianceFrameworkDeploymentTargetResourceCreationConfigFolderCreationConfig
The CloudSecurityComplianceFrameworkDeploymentTargetResourceCreationConfig.folderCreationConfig choice: sets folder_creation_config.
CloudSecurityComplianceFrameworkDeploymentTargetResourceCreationConfigProjectCreationConfig
The CloudSecurityComplianceFrameworkDeploymentTargetResourceCreationConfig.projectCreationConfig choice: sets project_creation_config.
CloudSecurityComplianceFrameworkOneofValue
Typed helper for the cloud_control_details.parameters.parameter_value.oneof_value block of google_cloud_security_compliance_framework (derived from provider schema).
CloudSecurityComplianceFrameworkOneofValueParameterValue
Typed helper for the cloud_control_details.parameters.parameter_value.oneof_value.parameter_value block of google_cloud_security_compliance_framework (derived from provider schema).
CloudSecurityComplianceFrameworkParameters
Typed helper for the cloud_control_details.parameters block of google_cloud_security_compliance_framework (derived from provider schema).
CloudSecurityComplianceFrameworkParameterValue
Typed helper for the cloud_control_details.parameters.parameter_value block of google_cloud_security_compliance_framework (derived from provider schema).
CloudSecurityComplianceFrameworkStringListValue
Typed helper for the cloud_control_details.parameters.parameter_value.string_list_value block of google_cloud_security_compliance_framework (derived from provider schema). Shared by every block of this shape in the resource.
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
GcsBackend
terraform { backend "gcs" { ... } } configuration.
GoogleCloudSecurityComplianceCloudControl
Factory wrapper for google_cloud_security_compliance_cloud_control.
GoogleCloudSecurityComplianceFramework
Factory wrapper for google_cloud_security_compliance_framework.
GoogleCloudSecurityComplianceFrameworkDeployment
Factory wrapper for google_cloud_security_compliance_framework_deployment.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.