iap library

Identity-Aware Proxy (IAP) — settings, tunnel destination groups, plus IAM for App Engine and external HTTPS load balancer backend services.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataGoogleIapAgentRegistryAgentIamPolicy
Factory wrapper for google_iap_agent_registry_agent_iam_policy.
DataGoogleIapAgentRegistryEndpointIamPolicy
Factory wrapper for google_iap_agent_registry_endpoint_iam_policy.
DataGoogleIapAgentRegistryIamPolicy
Factory wrapper for google_iap_agent_registry_iam_policy.
DataGoogleIapAgentRegistryMcpServerIamPolicy
Factory wrapper for google_iap_agent_registry_mcp_server_iam_policy.
DataGoogleIapAppEngineServiceIamPolicy
Factory wrapper for google_iap_app_engine_service_iam_policy.
DataGoogleIapAppEngineVersionIamPolicy
Factory wrapper for google_iap_app_engine_version_iam_policy.
DataGoogleIapLocationWebIamPolicy
Factory wrapper for google_iap_location_web_iam_policy.
DataGoogleIapTunnelDestGroupIamPolicy
Factory wrapper for google_iap_tunnel_dest_group_iam_policy.
DataGoogleIapTunnelIamPolicy
Factory wrapper for google_iap_tunnel_iam_policy.
DataGoogleIapTunnelInstanceIamPolicy
Factory wrapper for google_iap_tunnel_instance_iam_policy.
DataGoogleIapWebBackendServiceIamPolicy
Factory wrapper for google_iap_web_backend_service_iam_policy.
DataGoogleIapWebCloudRunServiceIamPolicy
Factory wrapper for google_iap_web_cloud_run_service_iam_policy.
DataGoogleIapWebForwardingRuleServiceIamPolicy
Factory wrapper for google_iap_web_forwarding_rule_service_iam_policy.
DataGoogleIapWebIamPolicy
Factory wrapper for google_iap_web_iam_policy.
DataGoogleIapWebRegionBackendServiceIamPolicy
Factory wrapper for google_iap_web_region_backend_service_iam_policy.
DataGoogleIapWebRegionForwardingRuleServiceIamPolicy
Factory wrapper for google_iap_web_region_forwarding_rule_service_iam_policy.
DataGoogleIapWebTypeAppEngineIamPolicy
Factory wrapper for google_iap_web_type_app_engine_iam_policy.
DataGoogleIapWebTypeComputeIamPolicy
Factory wrapper for google_iap_web_type_compute_iam_policy.
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
GcsBackend
terraform { backend "gcs" { ... } } configuration.
GoogleIapAgentRegistryAgentIamBinding
Factory wrapper for google_iap_agent_registry_agent_iam_binding.
GoogleIapAgentRegistryAgentIamMember
Factory wrapper for google_iap_agent_registry_agent_iam_member.
GoogleIapAgentRegistryAgentIamPolicy
Factory wrapper for google_iap_agent_registry_agent_iam_policy.
GoogleIapAgentRegistryEndpointIamBinding
Factory wrapper for google_iap_agent_registry_endpoint_iam_binding.
GoogleIapAgentRegistryEndpointIamMember
Factory wrapper for google_iap_agent_registry_endpoint_iam_member.
GoogleIapAgentRegistryEndpointIamPolicy
Factory wrapper for google_iap_agent_registry_endpoint_iam_policy.
GoogleIapAgentRegistryIamBinding
Factory wrapper for google_iap_agent_registry_iam_binding.
GoogleIapAgentRegistryIamMember
Factory wrapper for google_iap_agent_registry_iam_member.
GoogleIapAgentRegistryIamPolicy
Factory wrapper for google_iap_agent_registry_iam_policy.
GoogleIapAgentRegistryMcpServerIamBinding
Factory wrapper for google_iap_agent_registry_mcp_server_iam_binding.
GoogleIapAgentRegistryMcpServerIamMember
Factory wrapper for google_iap_agent_registry_mcp_server_iam_member.
GoogleIapAgentRegistryMcpServerIamPolicy
Factory wrapper for google_iap_agent_registry_mcp_server_iam_policy.
GoogleIapAppEngineServiceIamBinding
Factory wrapper for google_iap_app_engine_service_iam_binding.
GoogleIapAppEngineServiceIamMember
Factory wrapper for google_iap_app_engine_service_iam_member.
GoogleIapAppEngineServiceIamPolicy
Factory wrapper for google_iap_app_engine_service_iam_policy.
GoogleIapAppEngineVersionIamBinding
Factory wrapper for google_iap_app_engine_version_iam_binding.
GoogleIapAppEngineVersionIamMember
Factory wrapper for google_iap_app_engine_version_iam_member.
GoogleIapAppEngineVersionIamPolicy
Factory wrapper for google_iap_app_engine_version_iam_policy.
GoogleIapLocationWebIamBinding
Factory wrapper for google_iap_location_web_iam_binding.
GoogleIapLocationWebIamMember
Factory wrapper for google_iap_location_web_iam_member.
GoogleIapLocationWebIamPolicy
Factory wrapper for google_iap_location_web_iam_policy.
GoogleIapSettings
Factory wrapper for google_iap_settings.
GoogleIapTunnelDestGroup
Factory wrapper for google_iap_tunnel_dest_group.
GoogleIapTunnelDestGroupIamBinding
Factory wrapper for google_iap_tunnel_dest_group_iam_binding.
GoogleIapTunnelDestGroupIamMember
Factory wrapper for google_iap_tunnel_dest_group_iam_member.
GoogleIapTunnelDestGroupIamPolicy
Factory wrapper for google_iap_tunnel_dest_group_iam_policy.
GoogleIapTunnelIamBinding
Factory wrapper for google_iap_tunnel_iam_binding.
GoogleIapTunnelIamMember
Factory wrapper for google_iap_tunnel_iam_member.
GoogleIapTunnelIamPolicy
Factory wrapper for google_iap_tunnel_iam_policy.
GoogleIapTunnelInstanceIamBinding
Factory wrapper for google_iap_tunnel_instance_iam_binding.
GoogleIapTunnelInstanceIamMember
Factory wrapper for google_iap_tunnel_instance_iam_member.
GoogleIapTunnelInstanceIamPolicy
Factory wrapper for google_iap_tunnel_instance_iam_policy.
GoogleIapWebBackendServiceIamBinding
Factory wrapper for google_iap_web_backend_service_iam_binding.
GoogleIapWebBackendServiceIamMember
Factory wrapper for google_iap_web_backend_service_iam_member.
GoogleIapWebBackendServiceIamPolicy
Factory wrapper for google_iap_web_backend_service_iam_policy.
GoogleIapWebCloudRunServiceIamBinding
Factory wrapper for google_iap_web_cloud_run_service_iam_binding.
GoogleIapWebCloudRunServiceIamMember
Factory wrapper for google_iap_web_cloud_run_service_iam_member.
GoogleIapWebCloudRunServiceIamPolicy
Factory wrapper for google_iap_web_cloud_run_service_iam_policy.
GoogleIapWebForwardingRuleServiceIamBinding
Factory wrapper for google_iap_web_forwarding_rule_service_iam_binding.
GoogleIapWebForwardingRuleServiceIamMember
Factory wrapper for google_iap_web_forwarding_rule_service_iam_member.
GoogleIapWebForwardingRuleServiceIamPolicy
Factory wrapper for google_iap_web_forwarding_rule_service_iam_policy.
GoogleIapWebIamBinding
Factory wrapper for google_iap_web_iam_binding.
GoogleIapWebIamMember
Factory wrapper for google_iap_web_iam_member.
GoogleIapWebIamPolicy
Factory wrapper for google_iap_web_iam_policy.
GoogleIapWebRegionBackendServiceIamBinding
Factory wrapper for google_iap_web_region_backend_service_iam_binding.
GoogleIapWebRegionBackendServiceIamMember
Factory wrapper for google_iap_web_region_backend_service_iam_member.
GoogleIapWebRegionBackendServiceIamPolicy
Factory wrapper for google_iap_web_region_backend_service_iam_policy.
GoogleIapWebRegionForwardingRuleServiceIamBinding
Factory wrapper for google_iap_web_region_forwarding_rule_service_iam_binding.
GoogleIapWebRegionForwardingRuleServiceIamMember
Factory wrapper for google_iap_web_region_forwarding_rule_service_iam_member.
GoogleIapWebRegionForwardingRuleServiceIamPolicy
Factory wrapper for google_iap_web_region_forwarding_rule_service_iam_policy.
GoogleIapWebTypeAppEngineIamBinding
Factory wrapper for google_iap_web_type_app_engine_iam_binding.
GoogleIapWebTypeAppEngineIamMember
Factory wrapper for google_iap_web_type_app_engine_iam_member.
GoogleIapWebTypeAppEngineIamPolicy
Factory wrapper for google_iap_web_type_app_engine_iam_policy.
GoogleIapWebTypeComputeIamBinding
Factory wrapper for google_iap_web_type_compute_iam_binding.
GoogleIapWebTypeComputeIamMember
Factory wrapper for google_iap_web_type_compute_iam_member.
GoogleIapWebTypeComputeIamPolicy
Factory wrapper for google_iap_web_type_compute_iam_policy.
IapAgentRegistryAgentIamBindingCondition
Typed helper for the condition block of google_iap_agent_registry_agent_iam_binding (derived from provider schema).
IapAgentRegistryAgentIamMemberCondition
Typed helper for the condition block of google_iap_agent_registry_agent_iam_member (derived from provider schema).
IapAgentRegistryEndpointIamBindingCondition
Typed helper for the condition block of google_iap_agent_registry_endpoint_iam_binding (derived from provider schema).
IapAgentRegistryEndpointIamMemberCondition
Typed helper for the condition block of google_iap_agent_registry_endpoint_iam_member (derived from provider schema).
IapAgentRegistryIamBindingCondition
Typed helper for the condition block of google_iap_agent_registry_iam_binding (derived from provider schema).
IapAgentRegistryIamMemberCondition
Typed helper for the condition block of google_iap_agent_registry_iam_member (derived from provider schema).
IapAgentRegistryMcpServerIamBindingCondition
Typed helper for the condition block of google_iap_agent_registry_mcp_server_iam_binding (derived from provider schema).
IapAgentRegistryMcpServerIamMemberCondition
Typed helper for the condition block of google_iap_agent_registry_mcp_server_iam_member (derived from provider schema).
IapAppEngineServiceIamBindingCondition
Typed helper for the condition block of google_iap_app_engine_service_iam_binding (derived from provider schema).
IapAppEngineServiceIamMemberCondition
Typed helper for the condition block of google_iap_app_engine_service_iam_member (derived from provider schema).
IapAppEngineVersionIamBindingCondition
Typed helper for the condition block of google_iap_app_engine_version_iam_binding (derived from provider schema).
IapAppEngineVersionIamMemberCondition
Typed helper for the condition block of google_iap_app_engine_version_iam_member (derived from provider schema).
IapLocationWebIamBindingCondition
Typed helper for the condition block of google_iap_location_web_iam_binding (derived from provider schema).
IapLocationWebIamMemberCondition
Typed helper for the condition block of google_iap_location_web_iam_member (derived from provider schema).
IapSettingsAccessDeniedPageSettings
Typed helper for the application_settings.access_denied_page_settings block of google_iap_settings (derived from provider schema).
IapSettingsAccessSettings
Typed helper for the access_settings block of google_iap_settings (derived from provider schema).
IapSettingsAllowedDomainsSettings
Typed helper for the access_settings.allowed_domains_settings block of google_iap_settings (derived from provider schema).
IapSettingsApplicationSettings
Typed helper for the application_settings block of google_iap_settings (derived from provider schema).
IapSettingsAttributePropagationSettings
Typed helper for the application_settings.attribute_propagation_settings block of google_iap_settings (derived from provider schema).
IapSettingsCorsSettings
Typed helper for the access_settings.cors_settings block of google_iap_settings (derived from provider schema).
IapSettingsCsmSettings
Typed helper for the application_settings.csm_settings block of google_iap_settings (derived from provider schema).
IapSettingsGcipSettings
Typed helper for the access_settings.gcip_settings block of google_iap_settings (derived from provider schema).
IapSettingsOauth2
Typed helper for the access_settings.workforce_identity_settings.oauth2 block of google_iap_settings (derived from provider schema).
IapSettingsOauthSettings
Typed helper for the access_settings.oauth_settings block of google_iap_settings (derived from provider schema).
IapSettingsReauthSettings
Typed helper for the access_settings.reauth_settings block of google_iap_settings (derived from provider schema).
IapSettingsWorkforceIdentitySettings
Typed helper for the access_settings.workforce_identity_settings block of google_iap_settings (derived from provider schema).
IapTunnelDestGroupIamBindingCondition
Typed helper for the condition block of google_iap_tunnel_dest_group_iam_binding (derived from provider schema).
IapTunnelDestGroupIamMemberCondition
Typed helper for the condition block of google_iap_tunnel_dest_group_iam_member (derived from provider schema).
IapTunnelIamBindingCondition
Typed helper for the condition block of google_iap_tunnel_iam_binding (derived from provider schema).
IapTunnelIamMemberCondition
Typed helper for the condition block of google_iap_tunnel_iam_member (derived from provider schema).
IapTunnelInstanceIamBindingCondition
Typed helper for the condition block of google_iap_tunnel_instance_iam_binding (derived from provider schema).
IapTunnelInstanceIamMemberCondition
Typed helper for the condition block of google_iap_tunnel_instance_iam_member (derived from provider schema).
IapWebBackendServiceIamBindingCondition
Typed helper for the condition block of google_iap_web_backend_service_iam_binding (derived from provider schema).
IapWebBackendServiceIamMemberCondition
Typed helper for the condition block of google_iap_web_backend_service_iam_member (derived from provider schema).
IapWebCloudRunServiceIamBindingCondition
Typed helper for the condition block of google_iap_web_cloud_run_service_iam_binding (derived from provider schema).
IapWebCloudRunServiceIamMemberCondition
Typed helper for the condition block of google_iap_web_cloud_run_service_iam_member (derived from provider schema).
IapWebForwardingRuleServiceIamBindingCondition
Typed helper for the condition block of google_iap_web_forwarding_rule_service_iam_binding (derived from provider schema).
IapWebForwardingRuleServiceIamMemberCondition
Typed helper for the condition block of google_iap_web_forwarding_rule_service_iam_member (derived from provider schema).
IapWebIamBindingCondition
Typed helper for the condition block of google_iap_web_iam_binding (derived from provider schema).
IapWebIamMemberCondition
Typed helper for the condition block of google_iap_web_iam_member (derived from provider schema).
IapWebRegionBackendServiceIamBindingCondition
Typed helper for the condition block of google_iap_web_region_backend_service_iam_binding (derived from provider schema).
IapWebRegionBackendServiceIamMemberCondition
Typed helper for the condition block of google_iap_web_region_backend_service_iam_member (derived from provider schema).
IapWebRegionForwardingRuleServiceIamBindingCondition
Typed helper for the condition block of google_iap_web_region_forwarding_rule_service_iam_binding (derived from provider schema).
IapWebRegionForwardingRuleServiceIamMemberCondition
Typed helper for the condition block of google_iap_web_region_forwarding_rule_service_iam_member (derived from provider schema).
IapWebTypeAppEngineIamBindingCondition
Typed helper for the condition block of google_iap_web_type_app_engine_iam_binding (derived from provider schema).
IapWebTypeAppEngineIamMemberCondition
Typed helper for the condition block of google_iap_web_type_app_engine_iam_member (derived from provider schema).
IapWebTypeComputeIamBindingCondition
Typed helper for the condition block of google_iap_web_type_compute_iam_binding (derived from provider schema).
IapWebTypeComputeIamMemberCondition
Typed helper for the condition block of google_iap_web_type_compute_iam_member (derived from provider schema).
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

IapSettingsMethod
method — derived from the provider schema description.
IapSettingsOutputCredentials
output_credentials — derived from the provider schema description.
IapSettingsPolicyType
policy_type — derived from the provider schema description.
OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.