iam library
IAM service accounts, Workload Identity Federation pools
(including trust-domain namespaces and managed identities),
Workload Identity service-agent minting, Workforce Identity
Federation pools / providers / keys / SCIM (apply-excluded;
org parent), Workforce OAuth clients, OS Login SSH public keys,
project deny policies, and per-resource IAM members live
alongside their owning service barrel (e.g. pubsub.dart
exports GooglePubsubTopicIamMember). IamPrincipal names who a
grant is for.
Classes
-
AppConstant<
T> -
A value the Stack hands to application code as a
static constin the generated AppExports file — known when synth runs, so the app compiles against it. - AppExports
-
Where synth writes the Dart file application code imports: the Stack's
constants, as the
static constmembers of<name>Constants, and a typed reader of its Terraform outputs,<name>Outputs. -
AttributeRef<
T> -
Public for sealed pattern matching, but constructor is private — only
TfRef.attribute()may construct instances. - DartDefineOutput
-
An
outputwhose value is the client build's--dart-definefile, registered withStack.addDartDefineOutput. - Data
-
Base of every user-instantiable Terraform
datablock. - DataGoogleIamPolicy
-
Factory wrapper for
google_iam_policy. - DataGoogleIamRole
-
Factory wrapper for
google_iam_role. - DataGoogleIamTestablePermissions
-
Factory wrapper for
google_iam_testable_permissions. - DataGoogleIamWorkforcePoolIamPolicy
-
Factory wrapper for
google_iam_workforce_pool_iam_policy. - DataGoogleIamWorkloadIdentityPool
-
Factory wrapper for
google_iam_workload_identity_pool. - DataGoogleIamWorkloadIdentityPoolIamPolicy
-
Factory wrapper for
google_iam_workload_identity_pool_iam_policy. - DataGoogleIamWorkloadIdentityPoolOpenidConfig
-
Factory wrapper for
google_iam_workload_identity_pool_openid_config. - DataGoogleIamWorkloadIdentityPoolProvider
-
Factory wrapper for
google_iam_workload_identity_pool_provider. - DataGoogleProjectIamCustomRole
-
Factory wrapper for
google_project_iam_custom_role. - DataGoogleProjectIamPolicy
-
Factory wrapper for
google_project_iam_policy. - DataGoogleServiceAccount
-
Factory wrapper for
google_service_account. - DataGoogleServiceAccountAccessToken
-
Factory wrapper for
google_service_account_access_token. - DataGoogleServiceAccountIamPolicy
-
Factory wrapper for
google_service_account_iam_policy. - DataGoogleServiceAccountIdToken
-
Factory wrapper for
google_service_account_id_token. - DataGoogleServiceAccountJwt
-
Factory wrapper for
google_service_account_jwt. - DataGoogleServiceAccountKey
-
Factory wrapper for
google_service_account_key. - DataGoogleServiceAccounts
-
Factory wrapper for
google_service_accounts. - DataIamPolicyAuditConfig
-
Typed helper for the
audit_configblock ofgoogle_iam_policy(derived from provider schema). - DataIamPolicyAuditLogConfigs
-
Typed helper for the
audit_config.audit_log_configsblock ofgoogle_iam_policy(derived from provider schema). - DataIamPolicyBinding
-
Typed helper for the
bindingblock ofgoogle_iam_policy(derived from provider schema). - DataIamPolicyCondition
-
Typed helper for the
binding.conditionblock ofgoogle_iam_policy(derived from provider schema). -
DataRef<
T> -
Public for sealed pattern matching, but constructor is private — only
TfRef.data()may construct instances. - EnvironmentConstant
- The AppConstant.fromEnvironment choice.
- GcsBackend
-
terraform { backend "gcs" { ... } }configuration. - GoogleIamAccessBoundaryPolicy
-
Factory wrapper for
google_iam_access_boundary_policy. - GoogleIamDenyPolicy
-
Factory wrapper for
google_iam_deny_policy. - GoogleIamFolderAccessPolicy
-
Factory wrapper for
google_iam_folder_access_policy. - GoogleIamFoldersPolicyBinding
-
Factory wrapper for
google_iam_folders_policy_binding. - GoogleIamOauthClient
-
Factory wrapper for
google_iam_oauth_client. - GoogleIamOauthClientCredential
-
Factory wrapper for
google_iam_oauth_client_credential. - GoogleIamOrganizationAccessPolicy
-
Factory wrapper for
google_iam_organization_access_policy. - GoogleIamOrganizationsPolicyBinding
-
Factory wrapper for
google_iam_organizations_policy_binding. - GoogleIamPrincipalAccessBoundaryPolicy
-
Factory wrapper for
google_iam_principal_access_boundary_policy. - GoogleIamProjectAccessPolicy
-
Factory wrapper for
google_iam_project_access_policy. - GoogleIamProjectsPolicyBinding
-
Factory wrapper for
google_iam_projects_policy_binding. - GoogleIamWorkforcePool
-
Factory wrapper for
google_iam_workforce_pool. - GoogleIamWorkforcePoolIamBinding
-
Factory wrapper for
google_iam_workforce_pool_iam_binding. - GoogleIamWorkforcePoolIamMember
-
Factory wrapper for
google_iam_workforce_pool_iam_member. - GoogleIamWorkforcePoolIamPolicy
-
Factory wrapper for
google_iam_workforce_pool_iam_policy. - GoogleIamWorkforcePoolProvider
-
Factory wrapper for
google_iam_workforce_pool_provider. - GoogleIamWorkforcePoolProviderKey
-
Factory wrapper for
google_iam_workforce_pool_provider_key. - GoogleIamWorkforcePoolProviderScimTenant
-
Factory wrapper for
google_iam_workforce_pool_provider_scim_tenant. - GoogleIamWorkforcePoolProviderScimToken
-
Factory wrapper for
google_iam_workforce_pool_provider_scim_token. - GoogleIamWorkloadIdentityPool
-
Factory wrapper for
google_iam_workload_identity_pool. - GoogleIamWorkloadIdentityPoolIamBinding
-
Factory wrapper for
google_iam_workload_identity_pool_iam_binding. - GoogleIamWorkloadIdentityPoolIamMember
-
Factory wrapper for
google_iam_workload_identity_pool_iam_member. - GoogleIamWorkloadIdentityPoolIamPolicy
-
Factory wrapper for
google_iam_workload_identity_pool_iam_policy. - GoogleIamWorkloadIdentityPoolManagedIdentity
-
Factory wrapper for
google_iam_workload_identity_pool_managed_identity. - GoogleIamWorkloadIdentityPoolNamespace
-
Factory wrapper for
google_iam_workload_identity_pool_namespace. - GoogleIamWorkloadIdentityPoolProvider
-
Factory wrapper for
google_iam_workload_identity_pool_provider. - GoogleOsLoginSshPublicKey
-
Factory wrapper for
google_os_login_ssh_public_key. - GoogleProjectIamAuditConfig
-
Factory wrapper for
google_project_iam_audit_config. - GoogleProjectIamBinding
-
Factory wrapper for
google_project_iam_binding. - GoogleProjectIamCustomRole
-
Factory wrapper for
google_project_iam_custom_role. - GoogleProjectIamMember
-
Factory wrapper for
google_project_iam_member. - GoogleProjectIamMemberRemove
-
Factory wrapper for
google_project_iam_member_remove. - GoogleProjectIamPolicy
-
Factory wrapper for
google_project_iam_policy. - GoogleServiceAccount
-
Factory wrapper for
google_service_account. - GoogleServiceAccountIamBinding
-
Factory wrapper for
google_service_account_iam_binding. - GoogleServiceAccountIamMember
-
Factory wrapper for
google_service_account_iam_member. - GoogleServiceAccountIamPolicy
-
Factory wrapper for
google_service_account_iam_policy. - GoogleServiceAccountKey
-
Factory wrapper for
google_service_account_key. - GoogleWorkloadIdentityServiceAgent
-
Factory wrapper for
google_workload_identity_service_agent. - IamAccessBoundaryPolicyAccessBoundaryRule
-
Typed helper for the
rules.access_boundary_ruleblock ofgoogle_iam_access_boundary_policy(derived from provider schema). - IamAccessBoundaryPolicyAvailabilityCondition
-
Typed helper for the
rules.access_boundary_rule.availability_conditionblock ofgoogle_iam_access_boundary_policy(derived from provider schema). - IamAccessBoundaryPolicyRules
-
Typed helper for the
rulesblock ofgoogle_iam_access_boundary_policy(derived from provider schema). - IamDenyPolicyDenialCondition
-
Typed helper for the
rules.deny_rule.denial_conditionblock ofgoogle_iam_deny_policy(derived from provider schema). - IamDenyPolicyDenyRule
-
Typed helper for the
rules.deny_ruleblock ofgoogle_iam_deny_policy(derived from provider schema). - IamDenyPolicyRules
-
Typed helper for the
rulesblock ofgoogle_iam_deny_policy(derived from provider schema). - IamFolderAccessPolicyConditions
-
Typed helper for the
details.rules.conditionsblock ofgoogle_iam_folder_access_policy(derived from provider schema). - IamFolderAccessPolicyDetails
-
Typed helper for the
detailsblock ofgoogle_iam_folder_access_policy(derived from provider schema). - IamFolderAccessPolicyOperation
-
Typed helper for the
details.rules.operationblock ofgoogle_iam_folder_access_policy(derived from provider schema). - IamFolderAccessPolicyRules
-
Typed helper for the
details.rulesblock ofgoogle_iam_folder_access_policy(derived from provider schema). - IamFoldersPolicyBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iam_folders_policy_binding(derived from provider schema). - IamFoldersPolicyBindingTarget
-
Typed helper for the
targetblock ofgoogle_iam_folders_policy_binding(derived from provider schema). - IamOrganizationAccessPolicyConditions
-
Typed helper for the
details.rules.conditionsblock ofgoogle_iam_organization_access_policy(derived from provider schema). - IamOrganizationAccessPolicyDetails
-
Typed helper for the
detailsblock ofgoogle_iam_organization_access_policy(derived from provider schema). - IamOrganizationAccessPolicyOperation
-
Typed helper for the
details.rules.operationblock ofgoogle_iam_organization_access_policy(derived from provider schema). - IamOrganizationAccessPolicyRules
-
Typed helper for the
details.rulesblock ofgoogle_iam_organization_access_policy(derived from provider schema). - IamOrganizationsPolicyBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iam_organizations_policy_binding(derived from provider schema). - IamOrganizationsPolicyBindingTarget
-
Typed helper for the
targetblock ofgoogle_iam_organizations_policy_binding(derived from provider schema). - IamPrincipalAccessBoundaryPolicyDetails
-
Typed helper for the
detailsblock ofgoogle_iam_principal_access_boundary_policy(derived from provider schema). - IamPrincipalAccessBoundaryPolicyRules
-
Typed helper for the
details.rulesblock ofgoogle_iam_principal_access_boundary_policy(derived from provider schema). - IamProjectAccessPolicyConditions
-
Typed helper for the
details.rules.conditionsblock ofgoogle_iam_project_access_policy(derived from provider schema). - IamProjectAccessPolicyDetails
-
Typed helper for the
detailsblock ofgoogle_iam_project_access_policy(derived from provider schema). - IamProjectAccessPolicyOperation
-
Typed helper for the
details.rules.operationblock ofgoogle_iam_project_access_policy(derived from provider schema). - IamProjectAccessPolicyRules
-
Typed helper for the
details.rulesblock ofgoogle_iam_project_access_policy(derived from provider schema). - IamProjectsPolicyBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iam_projects_policy_binding(derived from provider schema). - IamProjectsPolicyBindingTarget
-
Typed helper for the
targetblock ofgoogle_iam_projects_policy_binding(derived from provider schema). - IamWorkforcePoolAccessRestrictions
-
Typed helper for the
access_restrictionsblock ofgoogle_iam_workforce_pool(derived from provider schema). - IamWorkforcePoolAllowedServices
-
Typed helper for the
access_restrictions.allowed_servicesblock ofgoogle_iam_workforce_pool(derived from provider schema). - IamWorkforcePoolIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iam_workforce_pool_iam_binding(derived from provider schema). - IamWorkforcePoolIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iam_workforce_pool_iam_member(derived from provider schema). - IamWorkforcePoolProviderClientSecret
-
Typed helper for the
extended_attributes_oauth2_client.client_secretblock ofgoogle_iam_workforce_pool_provider(derived from provider schema). Shared by every block of this shape in the resource. - IamWorkforcePoolProviderExtendedAttributesOauth2Client
-
Typed helper for the
extended_attributes_oauth2_clientblock ofgoogle_iam_workforce_pool_provider(derived from provider schema). - IamWorkforcePoolProviderExtraAttributesOauth2Client
-
Typed helper for the
extra_attributes_oauth2_clientblock ofgoogle_iam_workforce_pool_provider(derived from provider schema). - IamWorkforcePoolProviderGroupSource
-
At most one of
extended_attributes_oauth2_client,scim_usageongoogle_iam_workforce_pool_provider: the provider rejects more than one, so each variant sets one of them and a null choice sets none. - IamWorkforcePoolProviderGroupSourceExtendedAttributesOauth2Client
-
The IamWorkforcePoolProviderGroupSource.extendedAttributesOauth2Client choice: sets
extended_attributes_oauth2_client. - IamWorkforcePoolProviderGroupSourceScimUsage
-
The IamWorkforcePoolProviderGroupSource.scimUsage choice: sets
scim_usage. - IamWorkforcePoolProviderKeyData
-
Typed helper for the
key_datablock ofgoogle_iam_workforce_pool_provider_key(derived from provider schema). - IamWorkforcePoolProviderOidc
-
Typed helper for the
oidcblock ofgoogle_iam_workforce_pool_provider(derived from provider schema). - IamWorkforcePoolProviderPlainText
-
Exactly one of
plain_text,plain_text_woon theextended_attributes_oauth2_client.client_secret.valueblock ofgoogle_iam_workforce_pool_provider: the provider rejects none and more than one, so each variant sets one of them. - IamWorkforcePoolProviderPlainTextChoice
-
The IamWorkforcePoolProviderPlainText.plainText choice: sets
plain_text. - IamWorkforcePoolProviderPlainTextWo
-
The IamWorkforcePoolProviderPlainText.plainTextWo choice: sets
plain_text_wo. - IamWorkforcePoolProviderQueryParameters
-
Typed helper for the
extended_attributes_oauth2_client.query_parametersblock ofgoogle_iam_workforce_pool_provider(derived from provider schema). Shared by every block of this shape in the resource. - IamWorkforcePoolProviderSaml
-
Typed helper for the
samlblock ofgoogle_iam_workforce_pool_provider(derived from provider schema). - IamWorkforcePoolProviderTrustSource
-
Exactly one of
saml,oidcongoogle_iam_workforce_pool_provider: the provider rejects none and more than one, so each variant sets one of them. - IamWorkforcePoolProviderTrustSourceOidc
-
The IamWorkforcePoolProviderTrustSource.oidc choice: sets
oidc. - IamWorkforcePoolProviderTrustSourceSaml
-
The IamWorkforcePoolProviderTrustSource.saml choice: sets
saml. - IamWorkforcePoolProviderValue
-
Typed helper for the
extended_attributes_oauth2_client.client_secret.valueblock ofgoogle_iam_workforce_pool_provider(derived from provider schema). Shared by every block of this shape in the resource. - IamWorkforcePoolProviderWebSsoConfig
-
Typed helper for the
oidc.web_sso_configblock ofgoogle_iam_workforce_pool_provider(derived from provider schema). - IamWorkloadIdentityPoolAdditionalTrustBundles
-
Typed helper for the
inline_trust_config.additional_trust_bundlesblock ofgoogle_iam_workload_identity_pool(derived from provider schema). - IamWorkloadIdentityPoolAttestationRules
-
Typed helper for the
attestation_rulesblock ofgoogle_iam_workload_identity_pool(derived from provider schema). - IamWorkloadIdentityPoolCa
-
Exactly one of
ca_pools,use_default_shared_caon theinline_certificate_issuance_configblock ofgoogle_iam_workload_identity_pool: the provider rejects none and more than one, so each variant sets one of them. - IamWorkloadIdentityPoolCaPools
-
The IamWorkloadIdentityPoolCa.caPools choice: sets
ca_pools. - IamWorkloadIdentityPoolIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iam_workload_identity_pool_iam_binding(derived from provider schema). - IamWorkloadIdentityPoolIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iam_workload_identity_pool_iam_member(derived from provider schema). - IamWorkloadIdentityPoolInlineCertificateIssuanceConfig
-
Typed helper for the
inline_certificate_issuance_configblock ofgoogle_iam_workload_identity_pool(derived from provider schema). - IamWorkloadIdentityPoolInlineTrustConfig
-
Typed helper for the
inline_trust_configblock ofgoogle_iam_workload_identity_pool(derived from provider schema). - IamWorkloadIdentityPoolManagedIdentityAttestationRules
-
Typed helper for the
attestation_rulesblock ofgoogle_iam_workload_identity_pool_managed_identity(derived from provider schema). - IamWorkloadIdentityPoolProviderAws
-
Typed helper for the
awsblock ofgoogle_iam_workload_identity_pool_provider(derived from provider schema). - IamWorkloadIdentityPoolProviderIntermediateCas
-
Typed helper for the
x509.trust_store.intermediate_casblock ofgoogle_iam_workload_identity_pool_provider(derived from provider schema). - IamWorkloadIdentityPoolProviderOidc
-
Typed helper for the
oidcblock ofgoogle_iam_workload_identity_pool_provider(derived from provider schema). - IamWorkloadIdentityPoolProviderSaml
-
Typed helper for the
samlblock ofgoogle_iam_workload_identity_pool_provider(derived from provider schema). - IamWorkloadIdentityPoolProviderTrustAnchors
-
Typed helper for the
x509.trust_store.trust_anchorsblock ofgoogle_iam_workload_identity_pool_provider(derived from provider schema). - IamWorkloadIdentityPoolProviderTrustSource
-
Exactly one of
aws,oidc,saml,x509ongoogle_iam_workload_identity_pool_provider: the provider rejects none and more than one, so each variant sets one of them. - IamWorkloadIdentityPoolProviderTrustSourceAws
-
The IamWorkloadIdentityPoolProviderTrustSource.aws choice: sets
aws. - IamWorkloadIdentityPoolProviderTrustSourceOidc
-
The IamWorkloadIdentityPoolProviderTrustSource.oidc choice: sets
oidc. - IamWorkloadIdentityPoolProviderTrustSourceSaml
-
The IamWorkloadIdentityPoolProviderTrustSource.saml choice: sets
saml. - IamWorkloadIdentityPoolProviderTrustSourceX509
-
The IamWorkloadIdentityPoolProviderTrustSource.x509 choice: sets
x509. - IamWorkloadIdentityPoolProviderTrustStore
-
Typed helper for the
x509.trust_storeblock ofgoogle_iam_workload_identity_pool_provider(derived from provider schema). - IamWorkloadIdentityPoolProviderX509
-
Typed helper for the
x509block ofgoogle_iam_workload_identity_pool_provider(derived from provider schema). - IamWorkloadIdentityPoolTrustAnchors
-
Typed helper for the
inline_trust_config.additional_trust_bundles.trust_anchorsblock ofgoogle_iam_workload_identity_pool(derived from provider schema). -
The IamWorkloadIdentityPoolCa.useDefaultSharedCa choice: sets
use_default_shared_ca. - IgnoreAllChanges
- IgnoreChanges.all.
- IgnoreAttributes
- IgnoreChanges.of.
- IgnoreChanges
-
What
ignore_changescovers: every attribute, or the listed ones. - InvalidDartDefineOutput
-
An output of
Stack.addDartDefineOutputthat cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all. - InvalidLifecycle
-
A
lifecycleblock Terraform rejects: a data source (or one of its attributes) inreplaceTriggeredBy,allinside IgnoreChanges.of, or a condition with an empty error message. - InvalidMoveTarget
-
A
movedblock whosetonames no resource of the Stack. - InvalidTimeout
-
A negative
timeoutsduration. - LifecycleCondition
-
A
preconditionorpostconditionblock: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false. - LifecycleOptions
-
lifecycle { ... }block on a resource. - LocalBackend
-
terraform { backend "local" { ... } }configuration. - MissingProvider
-
A block needs a provider configuration the Stack does not register:
the provider its type implies (
googleforgoogle_pubsub_topic), the one itsprovidermeta-argument names, or one a module call passes on. - ModuleCall
-
A
module "<localName>" { ... }call as a Dart value. - NoProviders
- The Stack registers no provider, but declares resources or data sources.
- ProjectIamAuditConfigAuditLogConfig
-
Typed helper for the
audit_log_configblock ofgoogle_project_iam_audit_config(derived from provider schema). - ProjectIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_project_iam_binding(derived from provider schema). - ProjectIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_project_iam_member(derived from provider schema). - ProviderConflict
- Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
-
RefConstant<
T> - The AppConstant.ref choice.
- ReplaceTrigger
-
What
lifecycle.replaceTriggeredBylists: a resource of the Stack or an attribute getter of one.Resourceand TfRef implement it; synth reports a data source or a data-source attribute as anInvalidLifecycle. - Resource
- Base of every user-instantiable Terraform resource.
- ResourceRef
-
Public for sealed pattern matching, but constructor is private — only
TfRef.resource()may construct instances. - S3Backend
-
terraform { backend "s3" { ... } }configuration. -
Sensitive<
T> -
What an argument Terraform marks sensitive takes: a variable, an
expression or an attribute getter — a value Terraform resolves, never a
Dart literal that would be written into
main.tf.json. - SensitiveLiteral
-
A sensitive field is set to a literal, which would write the secret in
plain text into
main.tf.json. - ServiceAccountIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_service_account_iam_binding(derived from provider schema). - ServiceAccountIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_service_account_iam_member(derived from provider schema). - Stack
- User-extended IaC composition root.
- StackBackend
-
Lightweight backend hook. Core ships
GcsBackend,S3Backend, andLocalBackend; anything else implements this interface in the caller. TheStackonly stores the value and exposes a discriminator for synth'sterraform { backend ... }emitter. - StackProvider
-
Coordination interface between
Stack(in this package) and concrete providers (e.g.GoogleProviderinterradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen. - SynthIssue
- One reason a Stack cannot be synthesized.
- SynthResult
-
Bundle returned by
StackSynth.synth. - TfAddressed
-
Anything that exposes a Terraform address, e.g.
google_pubsub_topic.orders. -
TfArg<
T> - A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
-
TfArgExpression<
T> - A raw Terraform expression — the tf.json template string, verbatim.
-
TfArgLiteral<
T> -
TfArgVariable<
T> - TfCollectionType
-
list(...),set(...)ormap(...). - TfMoved
-
One
moved { from = ... to = ... }block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create. - TfObjectType
-
object({ ... }). - TfOptionalType
-
optional(<type>[, <default>]). -
TfOutput<
T> -
An
output "<name>" { value = ... }block, registered withStack.addOutput. - TfPrimitiveType
-
string,number,boolorany. -
TfRef<
T> - A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
- TfTimeouts
-
timeouts { ... }on a resource or data source: how long Terraform waits for each operation before giving up. - TfTupleType
-
tuple([...]). - TfType
-
A Terraform type constraint:
string,list(number),object({ name = string }). - TfVariable
-
One
variable "<name>" { ... }declaration. - UndeclaredVariable
-
A
TfArg.variableorvar.<name>in an expression names a variable the Stack does not declare. - UnregisteredReference
-
A block references another block that was never registered on the
Stack: built, but not passed to
add(...)/addModule(...). - UnresolvableConstant
-
An
AppConstant.refwhose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered. -
ValueConstant<
T> - The AppConstant.value choice.
Enums
- ResourceKind
-
Whether a Stack entry is a
resourceblock or adatablock in Terraform JSON.
Extension Types
- CustomRoleStage
-
Lifecycle stage for
GoogleProjectIamCustomRole.stage. Mirrors thestagefield exposed by the IAM API —alpha/beta/gaare grantable;deprecated/disabledkeep the role visible but reject new bindings. - IamFolderAccessPolicyEffect
-
effect— derived from the provider schema description. - IamOrganizationAccessPolicyEffect
-
effect— derived from the provider schema description. - IamPrincipal
-
Who an IAM grant is for: the
memberof an*IamMemberand each entry of an*IamBinding'smembers. - IamProjectAccessPolicyEffect
-
effect— derived from the provider schema description. - IamWorkforcePoolProviderAssertionClaimsBehavior
-
assertion_claims_behavior— derived from the provider schema description. - IamWorkforcePoolProviderAttributesType
-
attributes_type— derived from the provider schema description. - IamWorkforcePoolProviderKeySpec
-
key_spec— derived from the provider schema description. - IamWorkforcePoolProviderResponseType
-
response_type— derived from the provider schema description. - IamWorkforcePoolProviderScimUsage
-
scim_usage— whether authorization checks use SCIM-managed groups instead of thegoogle.groupsattribute mapping. - IamWorkloadIdentityPoolKeyAlgorithm
-
key_algorithm— derived from the provider schema description. - KeyAlgorithm
-
Signing algorithm for
GoogleServiceAccountKey.keyAlgorithm. GCP supports RSA-1024 (legacy) and RSA-2048 (default);unspecifiedlets the API pick. - OutputEnvironment
-
The environment
Stack.outputEnvironmentreturns: each variable and its value, in registration order. - PrivateKeyType
-
Output format for the emitted private key
(
GoogleServiceAccountKey.privateKeyType).googleCredentialsFile(the default) returns a JSON credentials file matching whatgcloud iam service-accounts keys createemits;pkcs12Filereturns a PKCS#12 keystore for systems that consume that format. - ProjectIamAuditConfigAuditLogConfigLogType
- Permission type for which IAM audit logging is configured.
- PublicKeyType
-
Output format for the public key half
(
GoogleServiceAccountKey.publicKeyType).x509PemFileis the most portable choice;rawPublicKeyreturns just the key material. - RefTo
-
A reference to a resource of type
R, for an argument that names another resource (network,vpc_id,role_arn, ...). - WorkloadIdentityPoolMode
- Operating mode for a workload identity pool.
Extensions
-
RefToList
on TfArg<
List< RefTo< >R> > -
A list-valued reference argument (
security_group_ids,subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'),TfArg.expression(...)). - TerraformDurationExt on Duration
- Converts a Dart Duration into a Terraform duration string ("604800s").
Constants
- terradartManifestVariable → const String
-
The environment variable the
terradartcommand sets to the file runStack and runEnvironments describe what they wrote in.
Functions
-
runEnvironments<
E extends Enum> (List< String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void> -
The entry point of a project with one Stack per environment. The
environments are the members of an enum of the project's own — any
names, each carrying its values — so the Stack takes a typed
envand derives everything per environment from it, its backend included: -
runStack(
List< String> args, Stack build(), {String out = 'tf-out'}) → Future<void> -
The entry point of a project with one Stack: writes it to
out.
Exceptions / Errors
- DuplicateModuleError
-
A
ModuleCallregistered twice under one name. - DuplicateResourceError
-
Thrown by
Stack.addwhen an entry with the same(kind, terraformType, localName)triple is registered twice. - SynthException
-
Thrown by
Stack.synth()andStack.writeTo()when the Stack has one or more SynthIssues. Nothing is written.