iap library
Identity-Aware Proxy (IAP) — settings, tunnel destination groups, plus IAM for App Engine and external HTTPS load balancer backend services.
Classes
-
AppConstant<
T> -
A value the Stack hands to application code as a
static constin the generated AppExports file — known when synth runs, so the app compiles against it. - AppExports
-
Where synth writes the Dart file application code imports: the Stack's
constants, as the
static constmembers of<name>Constants, and a typed reader of its Terraform outputs,<name>Outputs. -
AttributeRef<
T> -
Public for sealed pattern matching, but constructor is private — only
TfRef.attribute()may construct instances. - DartDefineOutput
-
An
outputwhose value is the client build's--dart-definefile, registered withStack.addDartDefineOutput. - Data
-
Base of every user-instantiable Terraform
datablock. - DataGoogleIapAgentRegistryAgentIamPolicy
-
Factory wrapper for
google_iap_agent_registry_agent_iam_policy. - DataGoogleIapAgentRegistryEndpointIamPolicy
-
Factory wrapper for
google_iap_agent_registry_endpoint_iam_policy. - DataGoogleIapAgentRegistryIamPolicy
-
Factory wrapper for
google_iap_agent_registry_iam_policy. - DataGoogleIapAgentRegistryMcpServerIamPolicy
-
Factory wrapper for
google_iap_agent_registry_mcp_server_iam_policy. - DataGoogleIapAppEngineServiceIamPolicy
-
Factory wrapper for
google_iap_app_engine_service_iam_policy. - DataGoogleIapAppEngineVersionIamPolicy
-
Factory wrapper for
google_iap_app_engine_version_iam_policy. - DataGoogleIapLocationWebIamPolicy
-
Factory wrapper for
google_iap_location_web_iam_policy. - DataGoogleIapTunnelDestGroupIamPolicy
-
Factory wrapper for
google_iap_tunnel_dest_group_iam_policy. - DataGoogleIapTunnelIamPolicy
-
Factory wrapper for
google_iap_tunnel_iam_policy. - DataGoogleIapTunnelInstanceIamPolicy
-
Factory wrapper for
google_iap_tunnel_instance_iam_policy. - DataGoogleIapWebBackendServiceIamPolicy
-
Factory wrapper for
google_iap_web_backend_service_iam_policy. - DataGoogleIapWebCloudRunServiceIamPolicy
-
Factory wrapper for
google_iap_web_cloud_run_service_iam_policy. - DataGoogleIapWebForwardingRuleServiceIamPolicy
-
Factory wrapper for
google_iap_web_forwarding_rule_service_iam_policy. - DataGoogleIapWebIamPolicy
-
Factory wrapper for
google_iap_web_iam_policy. - DataGoogleIapWebRegionBackendServiceIamPolicy
-
Factory wrapper for
google_iap_web_region_backend_service_iam_policy. - DataGoogleIapWebRegionForwardingRuleServiceIamPolicy
-
Factory wrapper for
google_iap_web_region_forwarding_rule_service_iam_policy. - DataGoogleIapWebTypeAppEngineIamPolicy
-
Factory wrapper for
google_iap_web_type_app_engine_iam_policy. - DataGoogleIapWebTypeComputeIamPolicy
-
Factory wrapper for
google_iap_web_type_compute_iam_policy. -
DataRef<
T> -
Public for sealed pattern matching, but constructor is private — only
TfRef.data()may construct instances. - EnvironmentConstant
- The AppConstant.fromEnvironment choice.
- GcsBackend
-
terraform { backend "gcs" { ... } }configuration. - GoogleIapAgentRegistryAgentIamBinding
-
Factory wrapper for
google_iap_agent_registry_agent_iam_binding. - GoogleIapAgentRegistryAgentIamMember
-
Factory wrapper for
google_iap_agent_registry_agent_iam_member. - GoogleIapAgentRegistryAgentIamPolicy
-
Factory wrapper for
google_iap_agent_registry_agent_iam_policy. - GoogleIapAgentRegistryEndpointIamBinding
-
Factory wrapper for
google_iap_agent_registry_endpoint_iam_binding. - GoogleIapAgentRegistryEndpointIamMember
-
Factory wrapper for
google_iap_agent_registry_endpoint_iam_member. - GoogleIapAgentRegistryEndpointIamPolicy
-
Factory wrapper for
google_iap_agent_registry_endpoint_iam_policy. - GoogleIapAgentRegistryIamBinding
-
Factory wrapper for
google_iap_agent_registry_iam_binding. - GoogleIapAgentRegistryIamMember
-
Factory wrapper for
google_iap_agent_registry_iam_member. - GoogleIapAgentRegistryIamPolicy
-
Factory wrapper for
google_iap_agent_registry_iam_policy. - GoogleIapAgentRegistryMcpServerIamBinding
-
Factory wrapper for
google_iap_agent_registry_mcp_server_iam_binding. - GoogleIapAgentRegistryMcpServerIamMember
-
Factory wrapper for
google_iap_agent_registry_mcp_server_iam_member. - GoogleIapAgentRegistryMcpServerIamPolicy
-
Factory wrapper for
google_iap_agent_registry_mcp_server_iam_policy. - GoogleIapAppEngineServiceIamBinding
-
Factory wrapper for
google_iap_app_engine_service_iam_binding. - GoogleIapAppEngineServiceIamMember
-
Factory wrapper for
google_iap_app_engine_service_iam_member. - GoogleIapAppEngineServiceIamPolicy
-
Factory wrapper for
google_iap_app_engine_service_iam_policy. - GoogleIapAppEngineVersionIamBinding
-
Factory wrapper for
google_iap_app_engine_version_iam_binding. - GoogleIapAppEngineVersionIamMember
-
Factory wrapper for
google_iap_app_engine_version_iam_member. - GoogleIapAppEngineVersionIamPolicy
-
Factory wrapper for
google_iap_app_engine_version_iam_policy. - GoogleIapLocationWebIamBinding
-
Factory wrapper for
google_iap_location_web_iam_binding. - GoogleIapLocationWebIamMember
-
Factory wrapper for
google_iap_location_web_iam_member. - GoogleIapLocationWebIamPolicy
-
Factory wrapper for
google_iap_location_web_iam_policy. - GoogleIapSettings
-
Factory wrapper for
google_iap_settings. - GoogleIapTunnelDestGroup
-
Factory wrapper for
google_iap_tunnel_dest_group. - GoogleIapTunnelDestGroupIamBinding
-
Factory wrapper for
google_iap_tunnel_dest_group_iam_binding. - GoogleIapTunnelDestGroupIamMember
-
Factory wrapper for
google_iap_tunnel_dest_group_iam_member. - GoogleIapTunnelDestGroupIamPolicy
-
Factory wrapper for
google_iap_tunnel_dest_group_iam_policy. - GoogleIapTunnelIamBinding
-
Factory wrapper for
google_iap_tunnel_iam_binding. - GoogleIapTunnelIamMember
-
Factory wrapper for
google_iap_tunnel_iam_member. - GoogleIapTunnelIamPolicy
-
Factory wrapper for
google_iap_tunnel_iam_policy. - GoogleIapTunnelInstanceIamBinding
-
Factory wrapper for
google_iap_tunnel_instance_iam_binding. - GoogleIapTunnelInstanceIamMember
-
Factory wrapper for
google_iap_tunnel_instance_iam_member. - GoogleIapTunnelInstanceIamPolicy
-
Factory wrapper for
google_iap_tunnel_instance_iam_policy. - GoogleIapWebBackendServiceIamBinding
-
Factory wrapper for
google_iap_web_backend_service_iam_binding. - GoogleIapWebBackendServiceIamMember
-
Factory wrapper for
google_iap_web_backend_service_iam_member. - GoogleIapWebBackendServiceIamPolicy
-
Factory wrapper for
google_iap_web_backend_service_iam_policy. - GoogleIapWebCloudRunServiceIamBinding
-
Factory wrapper for
google_iap_web_cloud_run_service_iam_binding. - GoogleIapWebCloudRunServiceIamMember
-
Factory wrapper for
google_iap_web_cloud_run_service_iam_member. - GoogleIapWebCloudRunServiceIamPolicy
-
Factory wrapper for
google_iap_web_cloud_run_service_iam_policy. - GoogleIapWebForwardingRuleServiceIamBinding
-
Factory wrapper for
google_iap_web_forwarding_rule_service_iam_binding. - GoogleIapWebForwardingRuleServiceIamMember
-
Factory wrapper for
google_iap_web_forwarding_rule_service_iam_member. - GoogleIapWebForwardingRuleServiceIamPolicy
-
Factory wrapper for
google_iap_web_forwarding_rule_service_iam_policy. - GoogleIapWebIamBinding
-
Factory wrapper for
google_iap_web_iam_binding. - GoogleIapWebIamMember
-
Factory wrapper for
google_iap_web_iam_member. - GoogleIapWebIamPolicy
-
Factory wrapper for
google_iap_web_iam_policy. - GoogleIapWebRegionBackendServiceIamBinding
-
Factory wrapper for
google_iap_web_region_backend_service_iam_binding. - GoogleIapWebRegionBackendServiceIamMember
-
Factory wrapper for
google_iap_web_region_backend_service_iam_member. - GoogleIapWebRegionBackendServiceIamPolicy
-
Factory wrapper for
google_iap_web_region_backend_service_iam_policy. - GoogleIapWebRegionForwardingRuleServiceIamBinding
-
Factory wrapper for
google_iap_web_region_forwarding_rule_service_iam_binding. - GoogleIapWebRegionForwardingRuleServiceIamMember
-
Factory wrapper for
google_iap_web_region_forwarding_rule_service_iam_member. - GoogleIapWebRegionForwardingRuleServiceIamPolicy
-
Factory wrapper for
google_iap_web_region_forwarding_rule_service_iam_policy. - GoogleIapWebTypeAppEngineIamBinding
-
Factory wrapper for
google_iap_web_type_app_engine_iam_binding. - GoogleIapWebTypeAppEngineIamMember
-
Factory wrapper for
google_iap_web_type_app_engine_iam_member. - GoogleIapWebTypeAppEngineIamPolicy
-
Factory wrapper for
google_iap_web_type_app_engine_iam_policy. - GoogleIapWebTypeComputeIamBinding
-
Factory wrapper for
google_iap_web_type_compute_iam_binding. - GoogleIapWebTypeComputeIamMember
-
Factory wrapper for
google_iap_web_type_compute_iam_member. - GoogleIapWebTypeComputeIamPolicy
-
Factory wrapper for
google_iap_web_type_compute_iam_policy. - IapAgentRegistryAgentIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_agent_registry_agent_iam_binding(derived from provider schema). - IapAgentRegistryAgentIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_agent_registry_agent_iam_member(derived from provider schema). - IapAgentRegistryEndpointIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_agent_registry_endpoint_iam_binding(derived from provider schema). - IapAgentRegistryEndpointIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_agent_registry_endpoint_iam_member(derived from provider schema). - IapAgentRegistryIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_agent_registry_iam_binding(derived from provider schema). - IapAgentRegistryIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_agent_registry_iam_member(derived from provider schema). - IapAgentRegistryMcpServerIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_agent_registry_mcp_server_iam_binding(derived from provider schema). - IapAgentRegistryMcpServerIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_agent_registry_mcp_server_iam_member(derived from provider schema). - IapAppEngineServiceIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_app_engine_service_iam_binding(derived from provider schema). - IapAppEngineServiceIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_app_engine_service_iam_member(derived from provider schema). - IapAppEngineVersionIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_app_engine_version_iam_binding(derived from provider schema). - IapAppEngineVersionIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_app_engine_version_iam_member(derived from provider schema). - IapLocationWebIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_location_web_iam_binding(derived from provider schema). - IapLocationWebIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_location_web_iam_member(derived from provider schema). - IapSettingsAccessDeniedPageSettings
-
Typed helper for the
application_settings.access_denied_page_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsAccessSettings
-
Typed helper for the
access_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsAllowedDomainsSettings
-
Typed helper for the
access_settings.allowed_domains_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsApplicationSettings
-
Typed helper for the
application_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsAttributePropagationSettings
-
Typed helper for the
application_settings.attribute_propagation_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsCorsSettings
-
Typed helper for the
access_settings.cors_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsCsmSettings
-
Typed helper for the
application_settings.csm_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsGcipSettings
-
Typed helper for the
access_settings.gcip_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsOauth2
-
Typed helper for the
access_settings.workforce_identity_settings.oauth2block ofgoogle_iap_settings(derived from provider schema). - IapSettingsOauthSettings
-
Typed helper for the
access_settings.oauth_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsReauthSettings
-
Typed helper for the
access_settings.reauth_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapSettingsWorkforceIdentitySettings
-
Typed helper for the
access_settings.workforce_identity_settingsblock ofgoogle_iap_settings(derived from provider schema). - IapTunnelDestGroupIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_tunnel_dest_group_iam_binding(derived from provider schema). - IapTunnelDestGroupIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_tunnel_dest_group_iam_member(derived from provider schema). - IapTunnelIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_tunnel_iam_binding(derived from provider schema). - IapTunnelIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_tunnel_iam_member(derived from provider schema). - IapTunnelInstanceIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_tunnel_instance_iam_binding(derived from provider schema). - IapTunnelInstanceIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_tunnel_instance_iam_member(derived from provider schema). - IapWebBackendServiceIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_backend_service_iam_binding(derived from provider schema). - IapWebBackendServiceIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_backend_service_iam_member(derived from provider schema). - IapWebCloudRunServiceIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_cloud_run_service_iam_binding(derived from provider schema). - IapWebCloudRunServiceIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_cloud_run_service_iam_member(derived from provider schema). - IapWebForwardingRuleServiceIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_forwarding_rule_service_iam_binding(derived from provider schema). - IapWebForwardingRuleServiceIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_forwarding_rule_service_iam_member(derived from provider schema). - IapWebIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_iam_binding(derived from provider schema). - IapWebIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_iam_member(derived from provider schema). - IapWebRegionBackendServiceIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_region_backend_service_iam_binding(derived from provider schema). - IapWebRegionBackendServiceIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_region_backend_service_iam_member(derived from provider schema). - IapWebRegionForwardingRuleServiceIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_region_forwarding_rule_service_iam_binding(derived from provider schema). - IapWebRegionForwardingRuleServiceIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_region_forwarding_rule_service_iam_member(derived from provider schema). - IapWebTypeAppEngineIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_type_app_engine_iam_binding(derived from provider schema). - IapWebTypeAppEngineIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_type_app_engine_iam_member(derived from provider schema). - IapWebTypeComputeIamBindingCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_type_compute_iam_binding(derived from provider schema). - IapWebTypeComputeIamMemberCondition
-
Typed helper for the
conditionblock ofgoogle_iap_web_type_compute_iam_member(derived from provider schema). - IgnoreAllChanges
- IgnoreChanges.all.
- IgnoreAttributes
- IgnoreChanges.of.
- IgnoreChanges
-
What
ignore_changescovers: every attribute, or the listed ones. - InvalidDartDefineOutput
-
An output of
Stack.addDartDefineOutputthat cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all. - InvalidLifecycle
-
A
lifecycleblock Terraform rejects: a data source (or one of its attributes) inreplaceTriggeredBy,allinside IgnoreChanges.of, or a condition with an empty error message. - InvalidMoveTarget
-
A
movedblock whosetonames no resource of the Stack. - InvalidTimeout
-
A negative
timeoutsduration. - LifecycleCondition
-
A
preconditionorpostconditionblock: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false. - LifecycleOptions
-
lifecycle { ... }block on a resource. - LocalBackend
-
terraform { backend "local" { ... } }configuration. - MissingProvider
-
A block needs a provider configuration the Stack does not register:
the provider its type implies (
googleforgoogle_pubsub_topic), the one itsprovidermeta-argument names, or one a module call passes on. - ModuleCall
-
A
module "<localName>" { ... }call as a Dart value. - NoProviders
- The Stack registers no provider, but declares resources or data sources.
- ProviderConflict
- Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
-
RefConstant<
T> - The AppConstant.ref choice.
- ReplaceTrigger
-
What
lifecycle.replaceTriggeredBylists: a resource of the Stack or an attribute getter of one.Resourceand TfRef implement it; synth reports a data source or a data-source attribute as anInvalidLifecycle. - Resource
- Base of every user-instantiable Terraform resource.
- ResourceRef
-
Public for sealed pattern matching, but constructor is private — only
TfRef.resource()may construct instances. - S3Backend
-
terraform { backend "s3" { ... } }configuration. -
Sensitive<
T> -
What an argument Terraform marks sensitive takes: a variable, an
expression or an attribute getter — a value Terraform resolves, never a
Dart literal that would be written into
main.tf.json. - SensitiveLiteral
-
A sensitive field is set to a literal, which would write the secret in
plain text into
main.tf.json. - Stack
- User-extended IaC composition root.
- StackBackend
-
Lightweight backend hook. Core ships
GcsBackend,S3Backend, andLocalBackend; anything else implements this interface in the caller. TheStackonly stores the value and exposes a discriminator for synth'sterraform { backend ... }emitter. - StackProvider
-
Coordination interface between
Stack(in this package) and concrete providers (e.g.GoogleProviderinterradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen. - SynthIssue
- One reason a Stack cannot be synthesized.
- SynthResult
-
Bundle returned by
StackSynth.synth. - TfAddressed
-
Anything that exposes a Terraform address, e.g.
google_pubsub_topic.orders. -
TfArg<
T> - A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
-
TfArgExpression<
T> - A raw Terraform expression — the tf.json template string, verbatim.
-
TfArgLiteral<
T> -
TfArgVariable<
T> - TfCollectionType
-
list(...),set(...)ormap(...). - TfMoved
-
One
moved { from = ... to = ... }block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create. - TfObjectType
-
object({ ... }). - TfOptionalType
-
optional(<type>[, <default>]). -
TfOutput<
T> -
An
output "<name>" { value = ... }block, registered withStack.addOutput. - TfPrimitiveType
-
string,number,boolorany. -
TfRef<
T> - A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
- TfTimeouts
-
timeouts { ... }on a resource or data source: how long Terraform waits for each operation before giving up. - TfTupleType
-
tuple([...]). - TfType
-
A Terraform type constraint:
string,list(number),object({ name = string }). - TfVariable
-
One
variable "<name>" { ... }declaration. - UndeclaredVariable
-
A
TfArg.variableorvar.<name>in an expression names a variable the Stack does not declare. - UnregisteredReference
-
A block references another block that was never registered on the
Stack: built, but not passed to
add(...)/addModule(...). - UnresolvableConstant
-
An
AppConstant.refwhose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered. -
ValueConstant<
T> - The AppConstant.value choice.
Enums
- ResourceKind
-
Whether a Stack entry is a
resourceblock or adatablock in Terraform JSON.
Extension Types
- IapSettingsMethod
-
method— derived from the provider schema description. - IapSettingsOutputCredentials
-
output_credentials— derived from the provider schema description. - IapSettingsPolicyType
-
policy_type— derived from the provider schema description. - OutputEnvironment
-
The environment
Stack.outputEnvironmentreturns: each variable and its value, in registration order. - RefTo
-
A reference to a resource of type
R, for an argument that names another resource (network,vpc_id,role_arn, ...).
Extensions
-
RefToList
on TfArg<
List< RefTo< >R> > -
A list-valued reference argument (
security_group_ids,subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'),TfArg.expression(...)). - TerraformDurationExt on Duration
- Converts a Dart Duration into a Terraform duration string ("604800s").
Constants
- terradartManifestVariable → const String
-
The environment variable the
terradartcommand sets to the file runStack and runEnvironments describe what they wrote in.
Functions
-
runEnvironments<
E extends Enum> (List< String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void> -
The entry point of a project with one Stack per environment. The
environments are the members of an enum of the project's own — any
names, each carrying its values — so the Stack takes a typed
envand derives everything per environment from it, its backend included: -
runStack(
List< String> args, Stack build(), {String out = 'tf-out'}) → Future<void> -
The entry point of a project with one Stack: writes it to
out.
Exceptions / Errors
- DuplicateModuleError
-
A
ModuleCallregistered twice under one name. - DuplicateResourceError
-
Thrown by
Stack.addwhen an entry with the same(kind, terraformType, localName)triple is registered twice. - SynthException
-
Thrown by
Stack.synth()andStack.writeTo()when the Stack has one or more SynthIssues. Nothing is written.