GoogleComputeFirewall class final
Factory wrapper for google_compute_firewall.
Each network has its own firewall controlling access to and from the instances.
All traffic to instances, even from other instances, is blocked by the firewall unless firewall rules are created to allow it.
The default network has automatically created firewall rules that are shown in default firewall rules. No manually created network has automatically created firewall rules except for a default "allow" rule for outgoing traffic and a default "deny" for incoming traffic. For all networks except the default network, you must create any firewall rules you need.
This resource models a VPC firewall rule.
Required identity:
- localName: Terraform local name (the address segment after
google_compute_firewall.). name: GCP firewall rule name.network: VPC network this rule attaches to. Typicallyvpc.refwherevpcis aGoogleComputeNetwork.
Choose exactly one ComputeFirewallRulePolicy:
- ComputeFirewallAllowPolicy — permit matching traffic.
- ComputeFirewallDenyPolicy — block matching traffic.
Example:
final allowSsh = GoogleComputeFirewall(
'allow_ssh',
name: TfArg.literal('allow-ssh'),
network: vpc.ref,
direction: FirewallDirection.ingress,
priority: TfArg.literal(1000),
rulePolicy: ComputeFirewallAllowPolicy(
protocol: TfArg.literal('tcp'),
ports: ['22'],
),
sourceRanges: TfArg.literal(['10.0.0.0/8']),
);
Composition pattern: extends Resource for runtime behavior. The
allow / deny list-typed blocks and the single log_config block
are modeled as helper classes in the prelude below.
Constructors
-
GoogleComputeFirewall(String localName, {required TfArg<
String> name, required RefTo<GoogleComputeNetwork> network, FirewallDirection? direction, TfArg<num> ? priority, required ComputeFirewallRulePolicy rulePolicy, TfArg<List< ? sourceRanges, TfArg<String> >List< ? sourceTags, TfArg<String> >List< ? sourceServiceAccounts, TfArg<String> >List< ? targetTags, TfArg<String> >List< ? targetServiceAccounts, TfArg<String> >List< ? destinationRanges, ComputeFirewallLogConfig? logConfig, TfArg<String> >bool> ? disabled, TfArg<bool> ? enableLogging, TfArg<String> ? description, ComputeFirewallParams? params, TfArg<String> ? project, LifecycleOptions? lifecycle, List<TfAddressed> ? dependsOn, StackProvider? provider, TfTimeouts? timeouts})
Properties
-
argMap
→ Map<
String, TfArg?> -
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name).
Synth emits these keys directly; the factory is responsible for the
camelCase → snake_case translation at construction time.
finalinherited
-
creationTimestamp
→ TfRef<
String> -
Reference to
creation_timestampattribute.no setter - defaultProvider → String
-
The provider name a block without provider uses: by default the
prefix of terraformType (
googleforgoogle_pubsub_topic).no setterinherited -
deletionPolicy
→ TfRef<
String> -
Reference to
deletion_policyattribute.no setter -
dependsOn
→ List<
TfAddressed> ? -
Optional
depends_on = [...]: the resources, data sources and module calls this block waits for, e.g.dependsOn: [api, ...apiDeps]. Terraform takes whole blocks only, so an entry is never an attribute.finalinherited -
description
→ TfRef<
String> -
Reference to
descriptionattribute.no setter -
destinationRanges
→ TfRef<
List< String> > -
Reference to
destination_rangesattribute.no setter -
direction
→ TfRef<
String> -
Reference to
directionattribute.no setter -
disabled
→ TfRef<
bool> -
Reference to
disabledattribute.no setter -
enableLogging
→ TfRef<
bool> -
Reference to
enable_loggingattribute.no setter - hashCode → int
-
The hash code for this object.
no setterinherited
-
id
→ TfRef<
String> -
Reference to
idattribute.no setter - kind → ResourceKind
-
Always
ResourceKind.resource. Overridden byData.no setterinherited - lifecycle → LifecycleOptions?
-
Optional
lifecycle { ... }block.finalinherited - localName → String
-
User-supplied local name within a Stack.
finalinherited
-
name
→ TfRef<
String> -
Reference to
nameattribute.no setter -
network
→ TfRef<
String> -
Reference to
networkattribute.no setter -
priority
→ TfRef<
num> -
Reference to
priorityattribute.no setter -
project
→ TfRef<
String> -
Reference to
projectattribute.no setter - provider → StackProvider?
-
Optional Terraform
providermeta-argument: the provider configuration this block uses, e.g. the aliasedGoogleProvider(alias: 'eu')the Stack registered withaddProvider.finalinherited -
ref
→ RefTo<
GoogleComputeFirewall> -
A reference to this resource, for arguments typed
RefTo<GoogleComputeFirewall>.no setter - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
selfLink
→ TfRef<
String> -
Reference to
self_linkattribute.no setter -
sensitiveFields
→ Set<
String> -
Field names that are
@Sensitiveper the IR-derived per-resource constant. Curated factories override with a baked-instatic const Set<String>(file-private in v0.5+).no setteroverride -
sourceRanges
→ TfRef<
List< String> > -
Reference to
source_rangesattribute.no setter -
sourceServiceAccounts
→ TfRef<
List< String> > -
Reference to
source_service_accountsattribute.no setter -
sourceTags
→ TfRef<
List< String> > -
Reference to
source_tagsattribute.no setter - supportsDeletionProtection → bool
-
Capability flag: true when this resource's underlying Terraform
schema has a
deletion_protectionboolean attribute that the synth-time devMode flow can flip tofalse. Defaults to false; the codegen emitter overrides this totruefor wrappers whose schema includes the attribute.no setterinherited -
targetServiceAccounts
→ TfRef<
List< String> > -
Reference to
target_service_accountsattribute.no setter -
targetTags
→ TfRef<
List< String> > -
Reference to
target_tagsattribute.no setter - terraformType → String
-
Terraform resource type, e.g.
google_pubsub_topic.finalinherited - tfAddress → String
-
Terraform address
<terraformType>.<localName>, e.g.google_pubsub_topic.orders.no setterinherited - timeouts → TfTimeouts?
-
Optional
timeouts { ... }block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, andterraform validatedecides whether this resource's schema declares the operations set here.finalinherited
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited