cloud_build library

Cloud Build CI/CD: trigger, private worker pool, v2 SCM connection + repository.

The v2 SCM connection model (GoogleCloudbuildv2Connection + GoogleCloudbuildv2Repository) is the modern way to wire GitHub / GitLab / Bitbucket sources into a Cloud Build trigger. The v1 github / bitbucket_server_trigger_config inline forms inside GoogleCloudbuildTrigger remain supported for existing setups.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
CloudbuildBitbucketServerConfigConnectedRepositories
Typed helper for the connected_repositories block of google_cloudbuild_bitbucket_server_config (derived from provider schema).
CloudbuildBitbucketServerConfigSecrets
Typed helper for the secrets block of google_cloudbuild_bitbucket_server_config (derived from provider schema).
CloudbuildTriggerApprovalConfig
Typed helper for the approval_config block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerArtifacts
Typed helper for the build.artifacts block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerAvailableSecrets
Typed helper for the build.available_secrets block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerBitbucketServerTriggerConfig
Typed helper for the bitbucket_server_trigger_config block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerBitbucketServerTriggerConfigEvent
Exactly one of pull_request, push on the bitbucket_server_trigger_config block of google_cloudbuild_trigger: the provider rejects none and more than one, so each variant sets one of them.
CloudbuildTriggerBitbucketServerTriggerConfigEventPullRequest
The CloudbuildTriggerBitbucketServerTriggerConfigEvent.pullRequest choice: sets pull_request.
CloudbuildTriggerBitbucketServerTriggerConfigEventPush
The CloudbuildTriggerBitbucketServerTriggerConfigEvent.push choice: sets push.
CloudbuildTriggerBitbucketServerTriggerConfigPullRequest
Typed helper for the bitbucket_server_trigger_config.pull_request block of google_cloudbuild_trigger (derived from provider schema). Shared by every block of this shape in the resource.
CloudbuildTriggerBitbucketServerTriggerConfigPush
Typed helper for the bitbucket_server_trigger_config.push block of google_cloudbuild_trigger (derived from provider schema). Shared by every block of this shape in the resource.
CloudbuildTriggerBuild
Typed helper for the build block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerBuildSpec
Exactly one of filename, build, git_file_source on google_cloudbuild_trigger: the provider rejects none and more than one, so each variant sets one of them.
CloudbuildTriggerBuildSpecBuild
The CloudbuildTriggerBuildSpec.build choice: sets build.
CloudbuildTriggerBuildSpecFilename
The CloudbuildTriggerBuildSpec.filename choice: sets filename.
CloudbuildTriggerBuildSpecGitFileSource
The CloudbuildTriggerBuildSpec.gitFileSource choice: sets git_file_source.
CloudbuildTriggerDeveloperConnectEventConfig
Typed helper for the developer_connect_event_config block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerDeveloperConnectEventConfigPullRequest
Typed helper for the developer_connect_event_config.pull_request block of google_cloudbuild_trigger (derived from provider schema). Shared by every block of this shape in the resource.
CloudbuildTriggerDeveloperConnectEventConfigPush
Typed helper for the developer_connect_event_config.push block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerGitFileSource
Typed helper for the git_file_source block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerGithub
Typed helper for the github block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerGithubEvent
Exactly one of pull_request, push on the github block of google_cloudbuild_trigger: the provider rejects none and more than one, so each variant sets one of them.
CloudbuildTriggerGithubEventPullRequest
The CloudbuildTriggerGithubEvent.pullRequest choice: sets pull_request.
CloudbuildTriggerGithubEventPush
The CloudbuildTriggerGithubEvent.push choice: sets push.
CloudbuildTriggerMavenArtifacts
Typed helper for the build.artifacts.maven_artifacts block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerNpmPackages
Typed helper for the build.artifacts.npm_packages block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerObjects
Typed helper for the build.artifacts.objects block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerOptions
Typed helper for the build.options block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerOptionsVolumes
Typed helper for the build.options.volumes block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerPubsubConfig
Typed helper for the pubsub_config block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerPushRevision
Exactly one of branch, tag on the bitbucket_server_trigger_config.push block of google_cloudbuild_trigger: the provider rejects none and more than one, so each variant sets one of them.
CloudbuildTriggerPushRevisionBranch
The CloudbuildTriggerPushRevision.branch choice: sets branch.
CloudbuildTriggerPushRevisionTag
The CloudbuildTriggerPushRevision.tag choice: sets tag.
CloudbuildTriggerPythonPackages
Typed helper for the build.artifacts.python_packages block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerRepositoryEventConfig
Typed helper for the repository_event_config block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerRepositoryEventConfigEvent
Exactly one of pull_request, push on the repository_event_config block of google_cloudbuild_trigger: the provider rejects none and more than one, so each variant sets one of them.
CloudbuildTriggerRepositoryEventConfigEventPullRequest
The CloudbuildTriggerRepositoryEventConfigEvent.pullRequest choice: sets pull_request.
CloudbuildTriggerRepositoryEventConfigEventPush
The CloudbuildTriggerRepositoryEventConfigEvent.push choice: sets push.
CloudbuildTriggerRepoSource
Typed helper for the build.source.repo_source block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerRepoSourceRevision
Exactly one of branch_name, commit_sha, tag_name on the build.source.repo_source block of google_cloudbuild_trigger: the provider rejects none and more than one, so each variant sets one of them.
CloudbuildTriggerRepoSourceRevisionBranchName
The CloudbuildTriggerRepoSourceRevision.branchName choice: sets branch_name.
CloudbuildTriggerRepoSourceRevisionCommitSha
The CloudbuildTriggerRepoSourceRevision.commitSha choice: sets commit_sha.
CloudbuildTriggerRepoSourceRevisionTagName
The CloudbuildTriggerRepoSourceRevision.tagName choice: sets tag_name.
CloudbuildTriggerRevision
Exactly one of branch_name, tag_name, commit_sha on the trigger_template block of google_cloudbuild_trigger: the provider rejects none and more than one, so each variant sets one of them.
CloudbuildTriggerRevisionBranchName
The CloudbuildTriggerRevision.branchName choice: sets branch_name.
CloudbuildTriggerRevisionCommitSha
The CloudbuildTriggerRevision.commitSha choice: sets commit_sha.
CloudbuildTriggerRevisionTagName
The CloudbuildTriggerRevision.tagName choice: sets tag_name.
CloudbuildTriggerSecret
Typed helper for the build.secret block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerSecretManager
Typed helper for the build.available_secrets.secret_manager block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerSource
Typed helper for the build.source block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerSourceToBuild
Typed helper for the source_to_build block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerStep
Typed helper for the build.step block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerStepVolumes
Typed helper for the build.step.volumes block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerStorageSource
Typed helper for the build.source.storage_source block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerTemplate
Typed helper for the trigger_template block of google_cloudbuild_trigger (derived from provider schema).
CloudbuildTriggerWebhookConfig
Typed helper for the webhook_config block of google_cloudbuild_trigger (derived from provider schema).
Cloudbuildv2ConnectionBitbucketCloudConfig
bitbucket_cloud_config block. Use for cloud-hosted Bitbucket (bitbucket.org).
Cloudbuildv2ConnectionBitbucketDataCenterConfig
bitbucket_data_center_config block. Use for self-hosted Bitbucket Data Center (formerly Bitbucket Server). For cloud-hosted Bitbucket pick Cloudbuildv2ConnectionBitbucketCloudConfig instead.
Cloudbuildv2ConnectionGithubAuthorizerCredential
github_config.authorizer_credential block. OAuth credential of the account that authorized the Cloud Build GitHub App.
Cloudbuildv2ConnectionGithubConfig
github_config block. Use for connections to github.com (the public GitHub host). For GitHub Enterprise Server pick Cloudbuildv2ConnectionGithubEnterpriseConfig instead.
Cloudbuildv2ConnectionGithubEnterpriseConfig
github_enterprise_config block. Use for GitHub Enterprise Server (self-hosted). Distinct from public-github Cloudbuildv2ConnectionGithubConfig — Enterprise uses an App-id + private-key authentication model rather than the public-GitHub OAuth flow.
Cloudbuildv2ConnectionGitlabConfig
gitlab_config block. Use for gitlab.com or self-hosted GitLab Enterprise.
Cloudbuildv2ConnectionHost
At most one of github_config, github_enterprise_config, gitlab_config, bitbucket_cloud_config, bitbucket_data_center_config on google_cloudbuildv2_connection: the provider rejects more than one, so each variant sets one of them and a null choice sets none.
Cloudbuildv2ConnectionHostBitbucketCloudConfig
The Cloudbuildv2ConnectionHost.bitbucketCloudConfig choice: sets bitbucket_cloud_config.
Cloudbuildv2ConnectionHostBitbucketDataCenterConfig
The Cloudbuildv2ConnectionHost.bitbucketDataCenterConfig choice: sets bitbucket_data_center_config.
Cloudbuildv2ConnectionHostGithubConfig
The Cloudbuildv2ConnectionHost.githubConfig choice: sets github_config.
Cloudbuildv2ConnectionHostGithubEnterpriseConfig
The Cloudbuildv2ConnectionHost.githubEnterpriseConfig choice: sets github_enterprise_config.
Cloudbuildv2ConnectionHostGitlabConfig
The Cloudbuildv2ConnectionHost.gitlabConfig choice: sets gitlab_config.
Cloudbuildv2ConnectionIamBindingCondition
Typed helper for the condition block of google_cloudbuildv2_connection_iam_binding (derived from provider schema).
Cloudbuildv2ConnectionIamMemberCondition
Typed helper for the condition block of google_cloudbuildv2_connection_iam_member (derived from provider schema).
Cloudbuildv2ConnectionServiceDirectoryConfig
service_directory_config block — shared shape across GitHub Enterprise, GitLab, and Bitbucket Data Center configs. Use when the on-premises SCM host sits behind Service Directory rather than on the public internet.
Cloudbuildv2ConnectionUserCredential
Shared shape for authorizer_credential / read_authorizer_credential blocks on the GitLab, Bitbucket Data Center, and Bitbucket Cloud configs. All three SCMs use a user access token whose value lives in Secret Manager.
CloudbuildWorkerPoolNetworkConfig
network_config block. Legacy VPC-peering form: the workers are peered to a customer VPC via Service Networking. Mutually exclusive with CloudbuildWorkerPoolPrivateServiceConnect; pick at most one. Immutable after pool creation.
CloudbuildWorkerPoolPrivateServiceConnect
private_service_connect block. Newer alternative to CloudbuildWorkerPoolNetworkConfig: workers connect to a Network Attachment in the customer VPC via PSC. Mutually exclusive with CloudbuildWorkerPoolNetworkConfig; pick at most one. Immutable after pool creation.
CloudbuildWorkerPoolWorkerConfig
worker_config block. Configures the VM shape used for workers in this pool. All fields are optional — omitting the block leaves Cloud Build's defaults (n1-standard-1, standard disk, public egress).
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataGoogleCloudbuildTrigger
Factory wrapper for google_cloudbuild_trigger.
DataGoogleCloudbuildv2ConnectionIamPolicy
Factory wrapper for google_cloudbuildv2_connection_iam_policy.
DataGoogleCloudbuildWorkerPool
Factory wrapper for google_cloudbuild_worker_pool.
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
GcsBackend
terraform { backend "gcs" { ... } } configuration.
GoogleCloudbuildBitbucketServerConfig
Factory wrapper for google_cloudbuild_bitbucket_server_config.
GoogleCloudbuildTrigger
Factory wrapper for google_cloudbuild_trigger.
GoogleCloudbuildv2Connection
Factory wrapper for google_cloudbuildv2_connection.
GoogleCloudbuildv2ConnectionIamBinding
Factory wrapper for google_cloudbuildv2_connection_iam_binding.
GoogleCloudbuildv2ConnectionIamMember
Factory wrapper for google_cloudbuildv2_connection_iam_member.
GoogleCloudbuildv2ConnectionIamPolicy
Factory wrapper for google_cloudbuildv2_connection_iam_policy.
GoogleCloudbuildv2Repository
Factory wrapper for google_cloudbuildv2_repository.
GoogleCloudbuildWorkerPool
Factory wrapper for google_cloudbuild_worker_pool.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

CloudbuildTriggerCommentControl
comment_control — derived from the provider schema description.
CloudBuildTriggerIncludeBuildLogs
include_build_logs. Controls whether Cloud Build forwards build logs back to the originating GitHub check-run. Only meaningful for triggers attached to a GitHub source.
CloudbuildTriggerLogging
logging — derived from the provider schema description.
CloudbuildTriggerLogStreamingOption
log_streaming_option — derived from the provider schema description.
CloudbuildTriggerRepoType
repo_type — derived from the provider schema description.
CloudbuildTriggerRequestedVerifyOption
requested_verify_option — derived from the provider schema description.
CloudbuildTriggerSourceProvenanceHash
source_provenance_hash — derived from the provider schema description.
CloudbuildTriggerSubstitutionOption
substitution_option — derived from the provider schema description.
OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.