iam library

IAM service accounts, Workload Identity Federation pools (including trust-domain namespaces and managed identities), Workload Identity service-agent minting, Workforce Identity Federation pools / providers / keys / SCIM (apply-excluded; org parent), Workforce OAuth clients, OS Login SSH public keys, project deny policies, and per-resource IAM members live alongside their owning service barrel (e.g. pubsub.dart exports GooglePubsubTopicIamMember). IamPrincipal names who a grant is for.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataGoogleIamPolicy
Factory wrapper for google_iam_policy.
DataGoogleIamRole
Factory wrapper for google_iam_role.
DataGoogleIamTestablePermissions
Factory wrapper for google_iam_testable_permissions.
DataGoogleIamWorkforcePoolIamPolicy
Factory wrapper for google_iam_workforce_pool_iam_policy.
DataGoogleIamWorkloadIdentityPool
Factory wrapper for google_iam_workload_identity_pool.
DataGoogleIamWorkloadIdentityPoolIamPolicy
Factory wrapper for google_iam_workload_identity_pool_iam_policy.
DataGoogleIamWorkloadIdentityPoolOpenidConfig
Factory wrapper for google_iam_workload_identity_pool_openid_config.
DataGoogleIamWorkloadIdentityPoolProvider
Factory wrapper for google_iam_workload_identity_pool_provider.
DataGoogleProjectIamCustomRole
Factory wrapper for google_project_iam_custom_role.
DataGoogleProjectIamPolicy
Factory wrapper for google_project_iam_policy.
DataGoogleServiceAccount
Factory wrapper for google_service_account.
DataGoogleServiceAccountAccessToken
Factory wrapper for google_service_account_access_token.
DataGoogleServiceAccountIamPolicy
Factory wrapper for google_service_account_iam_policy.
DataGoogleServiceAccountIdToken
Factory wrapper for google_service_account_id_token.
DataGoogleServiceAccountJwt
Factory wrapper for google_service_account_jwt.
DataGoogleServiceAccountKey
Factory wrapper for google_service_account_key.
DataGoogleServiceAccounts
Factory wrapper for google_service_accounts.
DataIamPolicyAuditConfig
Typed helper for the audit_config block of google_iam_policy (derived from provider schema).
DataIamPolicyAuditLogConfigs
Typed helper for the audit_config.audit_log_configs block of google_iam_policy (derived from provider schema).
DataIamPolicyBinding
Typed helper for the binding block of google_iam_policy (derived from provider schema).
DataIamPolicyCondition
Typed helper for the binding.condition block of google_iam_policy (derived from provider schema).
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
GcsBackend
terraform { backend "gcs" { ... } } configuration.
GoogleIamAccessBoundaryPolicy
Factory wrapper for google_iam_access_boundary_policy.
GoogleIamDenyPolicy
Factory wrapper for google_iam_deny_policy.
GoogleIamFolderAccessPolicy
Factory wrapper for google_iam_folder_access_policy.
GoogleIamFoldersPolicyBinding
Factory wrapper for google_iam_folders_policy_binding.
GoogleIamOauthClient
Factory wrapper for google_iam_oauth_client.
GoogleIamOauthClientCredential
Factory wrapper for google_iam_oauth_client_credential.
GoogleIamOrganizationAccessPolicy
Factory wrapper for google_iam_organization_access_policy.
GoogleIamOrganizationsPolicyBinding
Factory wrapper for google_iam_organizations_policy_binding.
GoogleIamPrincipalAccessBoundaryPolicy
Factory wrapper for google_iam_principal_access_boundary_policy.
GoogleIamProjectAccessPolicy
Factory wrapper for google_iam_project_access_policy.
GoogleIamProjectsPolicyBinding
Factory wrapper for google_iam_projects_policy_binding.
GoogleIamWorkforcePool
Factory wrapper for google_iam_workforce_pool.
GoogleIamWorkforcePoolIamBinding
Factory wrapper for google_iam_workforce_pool_iam_binding.
GoogleIamWorkforcePoolIamMember
Factory wrapper for google_iam_workforce_pool_iam_member.
GoogleIamWorkforcePoolIamPolicy
Factory wrapper for google_iam_workforce_pool_iam_policy.
GoogleIamWorkforcePoolProvider
Factory wrapper for google_iam_workforce_pool_provider.
GoogleIamWorkforcePoolProviderKey
Factory wrapper for google_iam_workforce_pool_provider_key.
GoogleIamWorkforcePoolProviderScimTenant
Factory wrapper for google_iam_workforce_pool_provider_scim_tenant.
GoogleIamWorkforcePoolProviderScimToken
Factory wrapper for google_iam_workforce_pool_provider_scim_token.
GoogleIamWorkloadIdentityPool
Factory wrapper for google_iam_workload_identity_pool.
GoogleIamWorkloadIdentityPoolIamBinding
Factory wrapper for google_iam_workload_identity_pool_iam_binding.
GoogleIamWorkloadIdentityPoolIamMember
Factory wrapper for google_iam_workload_identity_pool_iam_member.
GoogleIamWorkloadIdentityPoolIamPolicy
Factory wrapper for google_iam_workload_identity_pool_iam_policy.
GoogleIamWorkloadIdentityPoolManagedIdentity
Factory wrapper for google_iam_workload_identity_pool_managed_identity.
GoogleIamWorkloadIdentityPoolNamespace
Factory wrapper for google_iam_workload_identity_pool_namespace.
GoogleIamWorkloadIdentityPoolProvider
Factory wrapper for google_iam_workload_identity_pool_provider.
GoogleOsLoginSshPublicKey
Factory wrapper for google_os_login_ssh_public_key.
GoogleProjectIamAuditConfig
Factory wrapper for google_project_iam_audit_config.
GoogleProjectIamBinding
Factory wrapper for google_project_iam_binding.
GoogleProjectIamCustomRole
Factory wrapper for google_project_iam_custom_role.
GoogleProjectIamMember
Factory wrapper for google_project_iam_member.
GoogleProjectIamMemberRemove
Factory wrapper for google_project_iam_member_remove.
GoogleProjectIamPolicy
Factory wrapper for google_project_iam_policy.
GoogleServiceAccount
Factory wrapper for google_service_account.
GoogleServiceAccountIamBinding
Factory wrapper for google_service_account_iam_binding.
GoogleServiceAccountIamMember
Factory wrapper for google_service_account_iam_member.
GoogleServiceAccountIamPolicy
Factory wrapper for google_service_account_iam_policy.
GoogleServiceAccountKey
Factory wrapper for google_service_account_key.
GoogleWorkloadIdentityServiceAgent
Factory wrapper for google_workload_identity_service_agent.
IamAccessBoundaryPolicyAccessBoundaryRule
Typed helper for the rules.access_boundary_rule block of google_iam_access_boundary_policy (derived from provider schema).
IamAccessBoundaryPolicyAvailabilityCondition
Typed helper for the rules.access_boundary_rule.availability_condition block of google_iam_access_boundary_policy (derived from provider schema).
IamAccessBoundaryPolicyRules
Typed helper for the rules block of google_iam_access_boundary_policy (derived from provider schema).
IamDenyPolicyDenialCondition
Typed helper for the rules.deny_rule.denial_condition block of google_iam_deny_policy (derived from provider schema).
IamDenyPolicyDenyRule
Typed helper for the rules.deny_rule block of google_iam_deny_policy (derived from provider schema).
IamDenyPolicyRules
Typed helper for the rules block of google_iam_deny_policy (derived from provider schema).
IamFolderAccessPolicyConditions
Typed helper for the details.rules.conditions block of google_iam_folder_access_policy (derived from provider schema).
IamFolderAccessPolicyDetails
Typed helper for the details block of google_iam_folder_access_policy (derived from provider schema).
IamFolderAccessPolicyOperation
Typed helper for the details.rules.operation block of google_iam_folder_access_policy (derived from provider schema).
IamFolderAccessPolicyRules
Typed helper for the details.rules block of google_iam_folder_access_policy (derived from provider schema).
IamFoldersPolicyBindingCondition
Typed helper for the condition block of google_iam_folders_policy_binding (derived from provider schema).
IamFoldersPolicyBindingTarget
Typed helper for the target block of google_iam_folders_policy_binding (derived from provider schema).
IamOrganizationAccessPolicyConditions
Typed helper for the details.rules.conditions block of google_iam_organization_access_policy (derived from provider schema).
IamOrganizationAccessPolicyDetails
Typed helper for the details block of google_iam_organization_access_policy (derived from provider schema).
IamOrganizationAccessPolicyOperation
Typed helper for the details.rules.operation block of google_iam_organization_access_policy (derived from provider schema).
IamOrganizationAccessPolicyRules
Typed helper for the details.rules block of google_iam_organization_access_policy (derived from provider schema).
IamOrganizationsPolicyBindingCondition
Typed helper for the condition block of google_iam_organizations_policy_binding (derived from provider schema).
IamOrganizationsPolicyBindingTarget
Typed helper for the target block of google_iam_organizations_policy_binding (derived from provider schema).
IamPrincipalAccessBoundaryPolicyDetails
Typed helper for the details block of google_iam_principal_access_boundary_policy (derived from provider schema).
IamPrincipalAccessBoundaryPolicyRules
Typed helper for the details.rules block of google_iam_principal_access_boundary_policy (derived from provider schema).
IamProjectAccessPolicyConditions
Typed helper for the details.rules.conditions block of google_iam_project_access_policy (derived from provider schema).
IamProjectAccessPolicyDetails
Typed helper for the details block of google_iam_project_access_policy (derived from provider schema).
IamProjectAccessPolicyOperation
Typed helper for the details.rules.operation block of google_iam_project_access_policy (derived from provider schema).
IamProjectAccessPolicyRules
Typed helper for the details.rules block of google_iam_project_access_policy (derived from provider schema).
IamProjectsPolicyBindingCondition
Typed helper for the condition block of google_iam_projects_policy_binding (derived from provider schema).
IamProjectsPolicyBindingTarget
Typed helper for the target block of google_iam_projects_policy_binding (derived from provider schema).
IamWorkforcePoolAccessRestrictions
Typed helper for the access_restrictions block of google_iam_workforce_pool (derived from provider schema).
IamWorkforcePoolAllowedServices
Typed helper for the access_restrictions.allowed_services block of google_iam_workforce_pool (derived from provider schema).
IamWorkforcePoolIamBindingCondition
Typed helper for the condition block of google_iam_workforce_pool_iam_binding (derived from provider schema).
IamWorkforcePoolIamMemberCondition
Typed helper for the condition block of google_iam_workforce_pool_iam_member (derived from provider schema).
IamWorkforcePoolProviderClientSecret
Typed helper for the extended_attributes_oauth2_client.client_secret block of google_iam_workforce_pool_provider (derived from provider schema). Shared by every block of this shape in the resource.
IamWorkforcePoolProviderExtendedAttributesOauth2Client
Typed helper for the extended_attributes_oauth2_client block of google_iam_workforce_pool_provider (derived from provider schema).
IamWorkforcePoolProviderExtraAttributesOauth2Client
Typed helper for the extra_attributes_oauth2_client block of google_iam_workforce_pool_provider (derived from provider schema).
IamWorkforcePoolProviderGroupSource
At most one of extended_attributes_oauth2_client, scim_usage on google_iam_workforce_pool_provider: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
IamWorkforcePoolProviderGroupSourceExtendedAttributesOauth2Client
The IamWorkforcePoolProviderGroupSource.extendedAttributesOauth2Client choice: sets extended_attributes_oauth2_client.
IamWorkforcePoolProviderGroupSourceScimUsage
The IamWorkforcePoolProviderGroupSource.scimUsage choice: sets scim_usage.
IamWorkforcePoolProviderKeyData
Typed helper for the key_data block of google_iam_workforce_pool_provider_key (derived from provider schema).
IamWorkforcePoolProviderOidc
Typed helper for the oidc block of google_iam_workforce_pool_provider (derived from provider schema).
IamWorkforcePoolProviderPlainText
Exactly one of plain_text, plain_text_wo on the extended_attributes_oauth2_client.client_secret.value block of google_iam_workforce_pool_provider: the provider rejects none and more than one, so each variant sets one of them.
IamWorkforcePoolProviderPlainTextChoice
The IamWorkforcePoolProviderPlainText.plainText choice: sets plain_text.
IamWorkforcePoolProviderPlainTextWo
The IamWorkforcePoolProviderPlainText.plainTextWo choice: sets plain_text_wo.
IamWorkforcePoolProviderQueryParameters
Typed helper for the extended_attributes_oauth2_client.query_parameters block of google_iam_workforce_pool_provider (derived from provider schema). Shared by every block of this shape in the resource.
IamWorkforcePoolProviderSaml
Typed helper for the saml block of google_iam_workforce_pool_provider (derived from provider schema).
IamWorkforcePoolProviderTrustSource
Exactly one of saml, oidc on google_iam_workforce_pool_provider: the provider rejects none and more than one, so each variant sets one of them.
IamWorkforcePoolProviderTrustSourceOidc
The IamWorkforcePoolProviderTrustSource.oidc choice: sets oidc.
IamWorkforcePoolProviderTrustSourceSaml
The IamWorkforcePoolProviderTrustSource.saml choice: sets saml.
IamWorkforcePoolProviderValue
Typed helper for the extended_attributes_oauth2_client.client_secret.value block of google_iam_workforce_pool_provider (derived from provider schema). Shared by every block of this shape in the resource.
IamWorkforcePoolProviderWebSsoConfig
Typed helper for the oidc.web_sso_config block of google_iam_workforce_pool_provider (derived from provider schema).
IamWorkloadIdentityPoolAdditionalTrustBundles
Typed helper for the inline_trust_config.additional_trust_bundles block of google_iam_workload_identity_pool (derived from provider schema).
IamWorkloadIdentityPoolAttestationRules
Typed helper for the attestation_rules block of google_iam_workload_identity_pool (derived from provider schema).
IamWorkloadIdentityPoolCa
Exactly one of ca_pools, use_default_shared_ca on the inline_certificate_issuance_config block of google_iam_workload_identity_pool: the provider rejects none and more than one, so each variant sets one of them.
IamWorkloadIdentityPoolCaPools
The IamWorkloadIdentityPoolCa.caPools choice: sets ca_pools.
IamWorkloadIdentityPoolIamBindingCondition
Typed helper for the condition block of google_iam_workload_identity_pool_iam_binding (derived from provider schema).
IamWorkloadIdentityPoolIamMemberCondition
Typed helper for the condition block of google_iam_workload_identity_pool_iam_member (derived from provider schema).
IamWorkloadIdentityPoolInlineCertificateIssuanceConfig
Typed helper for the inline_certificate_issuance_config block of google_iam_workload_identity_pool (derived from provider schema).
IamWorkloadIdentityPoolInlineTrustConfig
Typed helper for the inline_trust_config block of google_iam_workload_identity_pool (derived from provider schema).
IamWorkloadIdentityPoolManagedIdentityAttestationRules
Typed helper for the attestation_rules block of google_iam_workload_identity_pool_managed_identity (derived from provider schema).
IamWorkloadIdentityPoolProviderAws
Typed helper for the aws block of google_iam_workload_identity_pool_provider (derived from provider schema).
IamWorkloadIdentityPoolProviderIntermediateCas
Typed helper for the x509.trust_store.intermediate_cas block of google_iam_workload_identity_pool_provider (derived from provider schema).
IamWorkloadIdentityPoolProviderOidc
Typed helper for the oidc block of google_iam_workload_identity_pool_provider (derived from provider schema).
IamWorkloadIdentityPoolProviderSaml
Typed helper for the saml block of google_iam_workload_identity_pool_provider (derived from provider schema).
IamWorkloadIdentityPoolProviderTrustAnchors
Typed helper for the x509.trust_store.trust_anchors block of google_iam_workload_identity_pool_provider (derived from provider schema).
IamWorkloadIdentityPoolProviderTrustSource
Exactly one of aws, oidc, saml, x509 on google_iam_workload_identity_pool_provider: the provider rejects none and more than one, so each variant sets one of them.
IamWorkloadIdentityPoolProviderTrustSourceAws
The IamWorkloadIdentityPoolProviderTrustSource.aws choice: sets aws.
IamWorkloadIdentityPoolProviderTrustSourceOidc
The IamWorkloadIdentityPoolProviderTrustSource.oidc choice: sets oidc.
IamWorkloadIdentityPoolProviderTrustSourceSaml
The IamWorkloadIdentityPoolProviderTrustSource.saml choice: sets saml.
IamWorkloadIdentityPoolProviderTrustSourceX509
The IamWorkloadIdentityPoolProviderTrustSource.x509 choice: sets x509.
IamWorkloadIdentityPoolProviderTrustStore
Typed helper for the x509.trust_store block of google_iam_workload_identity_pool_provider (derived from provider schema).
IamWorkloadIdentityPoolProviderX509
Typed helper for the x509 block of google_iam_workload_identity_pool_provider (derived from provider schema).
IamWorkloadIdentityPoolTrustAnchors
Typed helper for the inline_trust_config.additional_trust_bundles.trust_anchors block of google_iam_workload_identity_pool (derived from provider schema).
IamWorkloadIdentityPoolUseDefaultSharedCa
The IamWorkloadIdentityPoolCa.useDefaultSharedCa choice: sets use_default_shared_ca.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
ProjectIamAuditConfigAuditLogConfig
Typed helper for the audit_log_config block of google_project_iam_audit_config (derived from provider schema).
ProjectIamBindingCondition
Typed helper for the condition block of google_project_iam_binding (derived from provider schema).
ProjectIamMemberCondition
Typed helper for the condition block of google_project_iam_member (derived from provider schema).
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
ServiceAccountIamBindingCondition
Typed helper for the condition block of google_service_account_iam_binding (derived from provider schema).
ServiceAccountIamMemberCondition
Typed helper for the condition block of google_service_account_iam_member (derived from provider schema).
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

CustomRoleStage
Lifecycle stage for GoogleProjectIamCustomRole.stage. Mirrors the stage field exposed by the IAM API — alpha / beta / ga are grantable; deprecated / disabled keep the role visible but reject new bindings.
IamFolderAccessPolicyEffect
effect — derived from the provider schema description.
IamOrganizationAccessPolicyEffect
effect — derived from the provider schema description.
IamPrincipal
Who an IAM grant is for: the member of an *IamMember and each entry of an *IamBinding's members.
IamProjectAccessPolicyEffect
effect — derived from the provider schema description.
IamWorkforcePoolProviderAssertionClaimsBehavior
assertion_claims_behavior — derived from the provider schema description.
IamWorkforcePoolProviderAttributesType
attributes_type — derived from the provider schema description.
IamWorkforcePoolProviderKeySpec
key_spec — derived from the provider schema description.
IamWorkforcePoolProviderResponseType
response_type — derived from the provider schema description.
IamWorkforcePoolProviderScimUsage
scim_usage — whether authorization checks use SCIM-managed groups instead of the google.groups attribute mapping.
IamWorkloadIdentityPoolKeyAlgorithm
key_algorithm — derived from the provider schema description.
KeyAlgorithm
Signing algorithm for GoogleServiceAccountKey.keyAlgorithm. GCP supports RSA-1024 (legacy) and RSA-2048 (default); unspecified lets the API pick.
OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
PrivateKeyType
Output format for the emitted private key (GoogleServiceAccountKey.privateKeyType). googleCredentialsFile (the default) returns a JSON credentials file matching what gcloud iam service-accounts keys create emits; pkcs12File returns a PKCS#12 keystore for systems that consume that format.
ProjectIamAuditConfigAuditLogConfigLogType
Permission type for which IAM audit logging is configured.
PublicKeyType
Output format for the public key half (GoogleServiceAccountKey.publicKeyType). x509PemFile is the most portable choice; rawPublicKey returns just the key material.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).
WorkloadIdentityPoolMode
Operating mode for a workload identity pool.

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.