privateca library

Private CA (Certificate Authority Service) — CA pools for managed certificate issuance via Certificate Manager.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataGooglePrivatecaCaPoolIamPolicy
Factory wrapper for google_privateca_ca_pool_iam_policy.
DataGooglePrivatecaCertificateAuthority
Factory wrapper for google_privateca_certificate_authority.
DataGooglePrivatecaCertificateTemplateIamPolicy
Factory wrapper for google_privateca_certificate_template_iam_policy.
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
GcsBackend
terraform { backend "gcs" { ... } } configuration.
GooglePrivatecaCaPool
Factory wrapper for google_privateca_ca_pool.
GooglePrivatecaCaPoolIamBinding
Factory wrapper for google_privateca_ca_pool_iam_binding.
GooglePrivatecaCaPoolIamMember
Factory wrapper for google_privateca_ca_pool_iam_member.
GooglePrivatecaCaPoolIamPolicy
Factory wrapper for google_privateca_ca_pool_iam_policy.
GooglePrivatecaCertificate
Factory wrapper for google_privateca_certificate.
GooglePrivatecaCertificateAuthority
Factory wrapper for google_privateca_certificate_authority.
GooglePrivatecaCertificateTemplate
Factory wrapper for google_privateca_certificate_template.
GooglePrivatecaCertificateTemplateIamBinding
Factory wrapper for google_privateca_certificate_template_iam_binding.
GooglePrivatecaCertificateTemplateIamMember
Factory wrapper for google_privateca_certificate_template_iam_member.
GooglePrivatecaCertificateTemplateIamPolicy
Factory wrapper for google_privateca_certificate_template_iam_policy.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
PrivatecaCaPoolAdditionalExtensions
Typed helper for the issuance_policy.baseline_values.additional_extensions block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolAllowedIssuanceModes
Typed helper for the issuance_policy.allowed_issuance_modes block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolAllowedKeyTypes
Typed helper for the issuance_policy.allowed_key_types block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolBaseKeyUsage
Typed helper for the issuance_policy.baseline_values.key_usage.base_key_usage block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolBaselineValues
Typed helper for the issuance_policy.baseline_values block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolCaOptions
Typed helper for the issuance_policy.baseline_values.ca_options block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolCelExpression
Typed helper for the issuance_policy.identity_constraints.cel_expression block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolEllipticCurve
Typed helper for the issuance_policy.allowed_key_types.elliptic_curve block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolEncryptionSpec
Typed helper for the encryption_spec block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolExtendedKeyUsage
Typed helper for the issuance_policy.baseline_values.key_usage.extended_key_usage block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolIamBindingCondition
Typed helper for the condition block of google_privateca_ca_pool_iam_binding (derived from provider schema).
PrivatecaCaPoolIamMemberCondition
Typed helper for the condition block of google_privateca_ca_pool_iam_member (derived from provider schema).
PrivatecaCaPoolIdentityConstraints
Typed helper for the issuance_policy.identity_constraints block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolIssuancePolicy
Typed helper for the issuance_policy block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolKeyUsage
Typed helper for the issuance_policy.baseline_values.key_usage block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolNameConstraints
Typed helper for the issuance_policy.baseline_values.name_constraints block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolObjectId
Typed helper for the issuance_policy.baseline_values.additional_extensions.object_id block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolPolicyIds
Typed helper for the issuance_policy.baseline_values.policy_ids block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolPublishingOptions
Typed helper for the publishing_options block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolRsa
Typed helper for the issuance_policy.allowed_key_types.rsa block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCaPoolUnknownExtendedKeyUsages
Typed helper for the issuance_policy.baseline_values.key_usage.unknown_extended_key_usages block of google_privateca_ca_pool (derived from provider schema).
PrivatecaCertificateAdditionalExtensions
Typed helper for the config.x509_config.additional_extensions block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateAuthorityAdditionalExtensions
Typed helper for the config.x509_config.additional_extensions block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityBaseKeyUsage
Typed helper for the config.x509_config.key_usage.base_key_usage block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityCaOptions
Typed helper for the config.x509_config.ca_options block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityConfig
Typed helper for the config block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityExtendedKeyUsage
Typed helper for the config.x509_config.key_usage.extended_key_usage block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityKeySpec
Exactly one of cloud_kms_key_version, algorithm on the key_spec block of google_privateca_certificate_authority: the provider rejects none and more than one, so each variant sets one of them.
PrivatecaCertificateAuthorityKeySpecAlgorithm
The PrivatecaCertificateAuthorityKeySpec.algorithm choice: sets algorithm.
PrivatecaCertificateAuthorityKeySpecCloudKmsKeyVersion
The PrivatecaCertificateAuthorityKeySpec.cloudKmsKeyVersion choice: sets cloud_kms_key_version.
PrivatecaCertificateAuthorityKeyUsage
Typed helper for the config.x509_config.key_usage block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityNameConstraints
Typed helper for the config.x509_config.name_constraints block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityObjectId
Typed helper for the config.x509_config.additional_extensions.object_id block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityPemIssuerChain
Typed helper for the subordinate_config.pem_issuer_chain block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityPolicyIds
Typed helper for the config.x509_config.policy_ids block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthoritySubject
Typed helper for the config.subject_config.subject block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthoritySubjectAltName
Typed helper for the config.subject_config.subject_alt_name block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthoritySubjectConfig
Typed helper for the config.subject_config block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthoritySubjectKeyId
Typed helper for the config.subject_key_id block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthoritySubordinateConfig
Exactly one of certificate_authority, pem_issuer_chain on the subordinate_config block of google_privateca_certificate_authority: the provider rejects none and more than one, so each variant sets one of them.
PrivatecaCertificateAuthoritySubordinateConfigCertificateAuthority
The PrivatecaCertificateAuthoritySubordinateConfig.certificateAuthority choice: sets certificate_authority.
PrivatecaCertificateAuthoritySubordinateConfigPemIssuerChain
The PrivatecaCertificateAuthoritySubordinateConfig.pemIssuerChain choice: sets pem_issuer_chain.
PrivatecaCertificateAuthorityUnknownExtendedKeyUsages
Typed helper for the config.x509_config.key_usage.unknown_extended_key_usages block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityUserDefinedAccessUrls
Typed helper for the user_defined_access_urls block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateAuthorityX509Config
Typed helper for the config.x509_config block of google_privateca_certificate_authority (derived from provider schema).
PrivatecaCertificateBaseKeyUsage
Typed helper for the config.x509_config.key_usage.base_key_usage block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateCaOptions
Typed helper for the config.x509_config.ca_options block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateConfig
Typed helper for the config block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateExtendedKeyUsage
Typed helper for the config.x509_config.key_usage.extended_key_usage block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateKeyUsage
Typed helper for the config.x509_config.key_usage block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateNameConstraints
Typed helper for the config.x509_config.name_constraints block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateObjectId
Typed helper for the config.x509_config.additional_extensions.object_id block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificatePolicyIds
Typed helper for the config.x509_config.policy_ids block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificatePublicKey
Typed helper for the config.public_key block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateRequest
Exactly one of pem_csr, config on google_privateca_certificate: the provider rejects none and more than one, so each variant sets one of them.
PrivatecaCertificateRequestConfig
The PrivatecaCertificateRequest.config choice: sets config.
PrivatecaCertificateRequestPemCsr
The PrivatecaCertificateRequest.pemCsr choice: sets pem_csr.
PrivatecaCertificateSubject
Typed helper for the config.subject_config.subject block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateSubjectAltName
Typed helper for the config.subject_config.subject_alt_name block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateSubjectConfig
Typed helper for the config.subject_config block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateSubjectKeyId
Typed helper for the config.subject_key_id block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateTemplateBaseKeyUsage
Typed helper for the predefined_values.key_usage.base_key_usage block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplateCaOptions
Typed helper for the predefined_values.ca_options block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplateCelExpression
identity_constraints.cel_expression block.
PrivatecaCertificateTemplateExtendedKeyUsage
Typed helper for the predefined_values.key_usage.extended_key_usage block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplateIamBindingCondition
Typed helper for the condition block of google_privateca_certificate_template_iam_binding (derived from provider schema).
PrivatecaCertificateTemplateIamMemberCondition
Typed helper for the condition block of google_privateca_certificate_template_iam_member (derived from provider schema).
PrivatecaCertificateTemplateIdentityConstraints
identity_constraints block — subject / SAN passthrough policy.
PrivatecaCertificateTemplateKeyUsage
Typed helper for the predefined_values.key_usage block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplateNameConstraints
Typed helper for the predefined_values.name_constraints block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplateObjectId
Typed helper for the predefined_values.additional_extensions.object_id block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplatePassthroughExtensions
Typed helper for the passthrough_extensions block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplatePassthroughExtensionsAdditionalExtensions
Typed helper for the passthrough_extensions.additional_extensions block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplatePolicyIds
Typed helper for the predefined_values.policy_ids block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplatePredefinedValues
Typed helper for the predefined_values block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplatePredefinedValuesAdditionalExtensions
Typed helper for the predefined_values.additional_extensions block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateTemplateUnknownExtendedKeyUsages
Typed helper for the predefined_values.key_usage.unknown_extended_key_usages block of google_privateca_certificate_template (derived from provider schema).
PrivatecaCertificateUnknownExtendedKeyUsages
Typed helper for the config.x509_config.key_usage.unknown_extended_key_usages block of google_privateca_certificate (derived from provider schema).
PrivatecaCertificateX509Config
Typed helper for the config.x509_config block of google_privateca_certificate (derived from provider schema).
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
PrivatecaCaPoolEncodingFormat
encoding_format — derived from the provider schema description.
PrivatecaCaPoolSignatureAlgorithm
signature_algorithm — derived from the provider schema description.
PrivatecaCaPoolTier
tier — CAS pool service tier.
PrivatecaCertificateAuthorityDesiredState
desired_state — operational state target for the CA.
PrivatecaCertificateAuthorityKeyAlgorithm
key_spec.algorithm — managed Cloud KMS key algorithm.
PrivatecaCertificateAuthorityType
type — CA tier (must match the parent pool tier).
PrivatecaCertificateFormat
format — derived from the provider schema description.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.