scc library

Security Command Center (SCC) v1 / v2 / Management — sources, notification configs, mute configs, custom modules, BigQuery exports, and source IAM. Org/folder factories are apply-excluded.

Classes

AppConstant<T>
A value the Stack hands to application code as a static const in the generated AppExports file — known when synth runs, so the app compiles against it.
AppExports
Where synth writes the Dart file application code imports: the Stack's constants, as the static const members of <name>Constants, and a typed reader of its Terraform outputs, <name>Outputs.
AttributeRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.attribute() may construct instances.
DartDefineOutput
An output whose value is the client build's --dart-define file, registered with Stack.addDartDefineOutput.
Data
Base of every user-instantiable Terraform data block.
DataGoogleSccSourceIamPolicy
Factory wrapper for google_scc_source_iam_policy.
DataGoogleSccV2OrganizationSourceIamPolicy
Factory wrapper for google_scc_v2_organization_source_iam_policy.
DataRef<T>
Public for sealed pattern matching, but constructor is private — only TfRef.data() may construct instances.
EnvironmentConstant
The AppConstant.fromEnvironment choice.
GcsBackend
terraform { backend "gcs" { ... } } configuration.
GoogleSccEventThreatDetectionCustomModule
Factory wrapper for google_scc_event_threat_detection_custom_module.
GoogleSccFolderCustomModule
Factory wrapper for google_scc_folder_custom_module.
GoogleSccFolderNotificationConfig
Factory wrapper for google_scc_folder_notification_config.
GoogleSccFolderSccBigQueryExport
Factory wrapper for google_scc_folder_scc_big_query_export.
GoogleSccManagementFolderSecurityHealthAnalyticsCustomModule
Factory wrapper for google_scc_management_folder_security_health_analytics_custom_module.
GoogleSccManagementOrganizationEventThreatDetectionCustomModule
Factory wrapper for google_scc_management_organization_event_threat_detection_custom_module.
GoogleSccManagementOrganizationSecurityHealthAnalyticsCustomModule
Factory wrapper for google_scc_management_organization_security_health_analytics_custom_module.
GoogleSccManagementProjectSecurityHealthAnalyticsCustomModule
Factory wrapper for google_scc_management_project_security_health_analytics_custom_module.
GoogleSccMuteConfig
Factory wrapper for google_scc_mute_config.
GoogleSccNotificationConfig
Factory wrapper for google_scc_notification_config.
GoogleSccNotificationServiceAccount
Factory wrapper for google_scc_notification_service_account.
GoogleSccOrganizationCustomModule
Factory wrapper for google_scc_organization_custom_module.
GoogleSccOrganizationSccBigQueryExport
Factory wrapper for google_scc_organization_scc_big_query_export.
GoogleSccProjectCustomModule
Factory wrapper for google_scc_project_custom_module.
GoogleSccProjectNotificationConfig
Factory wrapper for google_scc_project_notification_config.
GoogleSccProjectSccBigQueryExport
Factory wrapper for google_scc_project_scc_big_query_export.
GoogleSccSource
Factory wrapper for google_scc_source.
GoogleSccSourceIamBinding
Factory wrapper for google_scc_source_iam_binding.
GoogleSccSourceIamMember
Factory wrapper for google_scc_source_iam_member.
GoogleSccSourceIamPolicy
Factory wrapper for google_scc_source_iam_policy.
GoogleSccV2FolderMuteConfig
Factory wrapper for google_scc_v2_folder_mute_config.
GoogleSccV2FolderNotificationConfig
Factory wrapper for google_scc_v2_folder_notification_config.
GoogleSccV2FolderSccBigQueryExport
Factory wrapper for google_scc_v2_folder_scc_big_query_export.
GoogleSccV2OrganizationMuteConfig
Factory wrapper for google_scc_v2_organization_mute_config.
GoogleSccV2OrganizationNotificationConfig
Factory wrapper for google_scc_v2_organization_notification_config.
GoogleSccV2OrganizationSccBigQueryExport
Factory wrapper for google_scc_v2_organization_scc_big_query_export.
GoogleSccV2OrganizationSccBigQueryExports
Factory wrapper for google_scc_v2_organization_scc_big_query_exports.
GoogleSccV2OrganizationSource
Factory wrapper for google_scc_v2_organization_source.
GoogleSccV2OrganizationSourceIamBinding
Factory wrapper for google_scc_v2_organization_source_iam_binding.
GoogleSccV2OrganizationSourceIamMember
Factory wrapper for google_scc_v2_organization_source_iam_member.
GoogleSccV2OrganizationSourceIamPolicy
Factory wrapper for google_scc_v2_organization_source_iam_policy.
GoogleSccV2ProjectMuteConfig
Factory wrapper for google_scc_v2_project_mute_config.
GoogleSccV2ProjectNotificationConfig
Factory wrapper for google_scc_v2_project_notification_config.
GoogleSccV2ProjectSccBigQueryExport
Factory wrapper for google_scc_v2_project_scc_big_query_export.
IgnoreAllChanges
IgnoreChanges.all.
IgnoreAttributes
IgnoreChanges.of.
IgnoreChanges
What ignore_changes covers: every attribute, or the listed ones.
InvalidDartDefineOutput
An output of Stack.addDartDefineOutput that cannot carry what it names: an output that is not registered, is sensitive or has no environment value, two outputs read from one variable, or no output at all.
InvalidLifecycle
A lifecycle block Terraform rejects: a data source (or one of its attributes) in replaceTriggeredBy, all inside IgnoreChanges.of, or a condition with an empty error message.
InvalidMoveTarget
A moved block whose to names no resource of the Stack.
InvalidTimeout
A negative timeouts duration.
LifecycleCondition
A precondition or postcondition block: Terraform fails the plan (LifecycleCondition.pre) or the apply (LifecycleCondition.post) with errorMessage when condition is false.
LifecycleOptions
lifecycle { ... } block on a resource.
LocalBackend
terraform { backend "local" { ... } } configuration.
MissingProvider
A block needs a provider configuration the Stack does not register: the provider its type implies (google for google_pubsub_topic), the one its provider meta-argument names, or one a module call passes on.
ModuleCall
A module "<localName>" { ... } call as a Dart value.
NoProviders
The Stack registers no provider, but declares resources or data sources.
ProviderConflict
Two provider registrations Terraform rejects together: two defaults of one name, a repeated alias, an alias that is not an identifier, or configurations of one name with different source / version constraints.
RefConstant<T>
The AppConstant.ref choice.
ReplaceTrigger
What lifecycle.replaceTriggeredBy lists: a resource of the Stack or an attribute getter of one. Resource and TfRef implement it; synth reports a data source or a data-source attribute as an InvalidLifecycle.
Resource
Base of every user-instantiable Terraform resource.
ResourceRef
Public for sealed pattern matching, but constructor is private — only TfRef.resource() may construct instances.
S3Backend
terraform { backend "s3" { ... } } configuration.
SccFolderCustomModuleCustomConfig
Typed helper for the custom_config block of google_scc_folder_custom_module (derived from provider schema).
SccFolderCustomModuleCustomOutput
Typed helper for the custom_config.custom_output block of google_scc_folder_custom_module (derived from provider schema).
SccFolderCustomModulePredicate
Typed helper for the custom_config.predicate block of google_scc_folder_custom_module (derived from provider schema).
SccFolderCustomModuleProperties
Typed helper for the custom_config.custom_output.properties block of google_scc_folder_custom_module (derived from provider schema).
SccFolderCustomModuleResourceSelector
Typed helper for the custom_config.resource_selector block of google_scc_folder_custom_module (derived from provider schema).
SccFolderCustomModuleValueExpression
Typed helper for the custom_config.custom_output.properties.value_expression block of google_scc_folder_custom_module (derived from provider schema).
SccFolderNotificationConfigStreamingConfig
Typed helper for the streaming_config block of google_scc_folder_notification_config (derived from provider schema).
SccManagementFolderSecurityHealthAnalyticsCustomModuleCustomConfig
Typed helper for the custom_config block of google_scc_management_folder_security_health_analytics_custom_module (derived from provider schema).
SccManagementFolderSecurityHealthAnalyticsCustomModuleCustomOutput
Typed helper for the custom_config.custom_output block of google_scc_management_folder_security_health_analytics_custom_module (derived from provider schema).
SccManagementFolderSecurityHealthAnalyticsCustomModulePredicate
Typed helper for the custom_config.predicate block of google_scc_management_folder_security_health_analytics_custom_module (derived from provider schema).
SccManagementFolderSecurityHealthAnalyticsCustomModuleProperties
Typed helper for the custom_config.custom_output.properties block of google_scc_management_folder_security_health_analytics_custom_module (derived from provider schema).
SccManagementFolderSecurityHealthAnalyticsCustomModuleResourceSelector
Typed helper for the custom_config.resource_selector block of google_scc_management_folder_security_health_analytics_custom_module (derived from provider schema).
SccManagementFolderSecurityHealthAnalyticsCustomModuleValueExpression
Typed helper for the custom_config.custom_output.properties.value_expression block of google_scc_management_folder_security_health_analytics_custom_module (derived from provider schema).
SccManagementOrganizationSecurityHealthAnalyticsCustomModuleCustomConfig
Typed helper for the custom_config block of google_scc_management_organization_security_health_analytics_custom_module (derived from provider schema).
SccManagementOrganizationSecurityHealthAnalyticsCustomModuleCustomOutput
Typed helper for the custom_config.custom_output block of google_scc_management_organization_security_health_analytics_custom_module (derived from provider schema).
SccManagementOrganizationSecurityHealthAnalyticsCustomModulePredicate
Typed helper for the custom_config.predicate block of google_scc_management_organization_security_health_analytics_custom_module (derived from provider schema).
SccManagementOrganizationSecurityHealthAnalyticsCustomModuleProperties
Typed helper for the custom_config.custom_output.properties block of google_scc_management_organization_security_health_analytics_custom_module (derived from provider schema).
SccManagementOrganizationSecurityHealthAnalyticsCustomModuleResourceSelector
Typed helper for the custom_config.resource_selector block of google_scc_management_organization_security_health_analytics_custom_module (derived from provider schema).
SccManagementOrganizationSecurityHealthAnalyticsCustomModuleValueExpression
Typed helper for the custom_config.custom_output.properties.value_expression block of google_scc_management_organization_security_health_analytics_custom_module (derived from provider schema).
SccManagementProjectSecurityHealthAnalyticsCustomModuleCustomConfig
Typed helper for the custom_config block of google_scc_management_project_security_health_analytics_custom_module (derived from provider schema).
SccManagementProjectSecurityHealthAnalyticsCustomModuleCustomOutput
Typed helper for the custom_config.custom_output block of google_scc_management_project_security_health_analytics_custom_module (derived from provider schema).
SccManagementProjectSecurityHealthAnalyticsCustomModulePredicate
Typed helper for the custom_config.predicate block of google_scc_management_project_security_health_analytics_custom_module (derived from provider schema).
SccManagementProjectSecurityHealthAnalyticsCustomModuleProperties
Typed helper for the custom_config.custom_output.properties block of google_scc_management_project_security_health_analytics_custom_module (derived from provider schema).
SccManagementProjectSecurityHealthAnalyticsCustomModuleResourceSelector
Typed helper for the custom_config.resource_selector block of google_scc_management_project_security_health_analytics_custom_module (derived from provider schema).
SccManagementProjectSecurityHealthAnalyticsCustomModuleValueExpression
Typed helper for the custom_config.custom_output.properties.value_expression block of google_scc_management_project_security_health_analytics_custom_module (derived from provider schema).
SccNotificationConfigStreamingConfig
Typed helper for the streaming_config block of google_scc_notification_config (derived from provider schema).
SccOrganizationCustomModuleCustomConfig
Typed helper for the custom_config block of google_scc_organization_custom_module (derived from provider schema).
SccOrganizationCustomModuleCustomOutput
Typed helper for the custom_config.custom_output block of google_scc_organization_custom_module (derived from provider schema).
SccOrganizationCustomModulePredicate
Typed helper for the custom_config.predicate block of google_scc_organization_custom_module (derived from provider schema).
SccOrganizationCustomModuleProperties
Typed helper for the custom_config.custom_output.properties block of google_scc_organization_custom_module (derived from provider schema).
SccOrganizationCustomModuleResourceSelector
Typed helper for the custom_config.resource_selector block of google_scc_organization_custom_module (derived from provider schema).
SccOrganizationCustomModuleValueExpression
Typed helper for the custom_config.custom_output.properties.value_expression block of google_scc_organization_custom_module (derived from provider schema).
SccProjectCustomModuleCustomConfig
Typed helper for the custom_config block of google_scc_project_custom_module (derived from provider schema).
SccProjectCustomModuleCustomOutput
Typed helper for the custom_config.custom_output block of google_scc_project_custom_module (derived from provider schema).
SccProjectCustomModulePredicate
Typed helper for the custom_config.predicate block of google_scc_project_custom_module (derived from provider schema).
SccProjectCustomModuleProperties
Typed helper for the custom_config.custom_output.properties block of google_scc_project_custom_module (derived from provider schema).
SccProjectCustomModuleResourceSelector
Typed helper for the custom_config.resource_selector block of google_scc_project_custom_module (derived from provider schema).
SccProjectCustomModuleValueExpression
Typed helper for the custom_config.custom_output.properties.value_expression block of google_scc_project_custom_module (derived from provider schema).
SccProjectNotificationConfigStreamingConfig
Typed helper for the streaming_config block of google_scc_project_notification_config (derived from provider schema).
SccSourceIamBindingCondition
Typed helper for the condition block of google_scc_source_iam_binding (derived from provider schema).
SccSourceIamMemberCondition
Typed helper for the condition block of google_scc_source_iam_member (derived from provider schema).
SccV2FolderNotificationConfigStreamingConfig
Typed helper for the streaming_config block of google_scc_v2_folder_notification_config (derived from provider schema).
SccV2OrganizationNotificationConfigStreamingConfig
Typed helper for the streaming_config block of google_scc_v2_organization_notification_config (derived from provider schema).
SccV2OrganizationSourceIamBindingCondition
Typed helper for the condition block of google_scc_v2_organization_source_iam_binding (derived from provider schema).
SccV2OrganizationSourceIamMemberCondition
Typed helper for the condition block of google_scc_v2_organization_source_iam_member (derived from provider schema).
SccV2ProjectNotificationConfigStreamingConfig
Typed helper for the streaming_config block of google_scc_v2_project_notification_config (derived from provider schema).
Sensitive<T>
What an argument Terraform marks sensitive takes: a variable, an expression or an attribute getter — a value Terraform resolves, never a Dart literal that would be written into main.tf.json.
SensitiveLiteral
A sensitive field is set to a literal, which would write the secret in plain text into main.tf.json.
Stack
User-extended IaC composition root.
StackBackend
Lightweight backend hook. Core ships GcsBackend, S3Backend, and LocalBackend; anything else implements this interface in the caller. The Stack only stores the value and exposes a discriminator for synth's terraform { backend ... } emitter.
StackProvider
Coordination interface between Stack (in this package) and concrete providers (e.g. GoogleProvider in terradart_google). Concrete providers implement every getter using their baked-in constants from Stage 2 codegen.
SynthIssue
One reason a Stack cannot be synthesized.
SynthResult
Bundle returned by StackSynth.synth.
TfAddressed
Anything that exposes a Terraform address, e.g. google_pubsub_topic.orders.
TfArg<T>
A Terraform argument: a Dart-side literal, a reference to another block's attribute (TfRef), a variable or a raw expression.
TfArgExpression<T>
A raw Terraform expression — the tf.json template string, verbatim.
TfArgLiteral<T>
TfArgVariable<T>
TfCollectionType
list(...), set(...) or map(...).
TfMoved
One moved { from = ... to = ... } block: the state object at from now belongs to the resource at to, so a rename does not become a destroy-and-create.
TfObjectType
object({ ... }).
TfOptionalType
optional(<type>[, <default>]).
TfOutput<T>
An output "<name>" { value = ... } block, registered with Stack.addOutput.
TfPrimitiveType
string, number, bool or any.
TfRef<T>
A Terraform-side reference: an attribute of a resource (AttributeRef) or a data source (DataRef), or a whole resource (ResourceRef).
TfTimeouts
timeouts { ... } on a resource or data source: how long Terraform waits for each operation before giving up.
TfTupleType
tuple([...]).
TfType
A Terraform type constraint: string, list(number), object({ name = string }).
TfVariable
One variable "<name>" { ... } declaration.
UndeclaredVariable
A TfArg.variable or var.<name> in an expression names a variable the Stack does not declare.
UnregisteredReference
A block references another block that was never registered on the Stack: built, but not passed to add(...) / addModule(...).
UnresolvableConstant
An AppConstant.ref whose value is not known at synth: the attribute is not set to a literal, is sensitive, does not match the constant's type, or belongs to a block that is not registered.
ValueConstant<T>
The AppConstant.value choice.

Enums

ResourceKind
Whether a Stack entry is a resource block or a data block in Terraform JSON.

Extension Types

OutputEnvironment
The environment Stack.outputEnvironment returns: each variable and its value, in registration order.
RefTo
A reference to a resource of type R, for an argument that names another resource (network, vpc_id, role_arn, ...).
SccEventThreatDetectionCustomModuleEnablementState
Scc Event Threat Detection Custom Module Enablement enum for enablement_state.
SccFolderCustomModuleEnablementState
Scc Folder Custom Module Enablement enum for enablement_state.
SccFolderCustomModuleSeverity
severity — derived from the provider schema description.
SccManagementFolderSecurityHealthAnalyticsCustomModuleEnablementState
Scc Management Folder Security Health Analytics Custom Module Enablement enum for enablement_state.
SccManagementFolderSecurityHealthAnalyticsCustomModuleSeverity
severity — derived from the provider schema description.
SccManagementOrganizationEventThreatDetectionCustomModuleEnablementState
Scc Management Organization Event Threat Detection Custom Module Enablement enum for enablement_state.
SccManagementOrganizationSecurityHealthAnalyticsCustomModuleEnablementState
Scc Management Organization Security Health Analytics Custom Module Enablement enum for enablement_state.
SccManagementOrganizationSecurityHealthAnalyticsCustomModuleSeverity
severity — derived from the provider schema description.
SccManagementProjectSecurityHealthAnalyticsCustomModuleEnablementState
Scc Management Project Security Health Analytics Custom Module Enablement enum for enablement_state.
SccManagementProjectSecurityHealthAnalyticsCustomModuleSeverity
severity — derived from the provider schema description.
SccMuteConfigType
Scc Mute Config enum for type.
SccOrganizationCustomModuleEnablementState
Scc Organization Custom Module Enablement enum for enablement_state.
SccOrganizationCustomModuleSeverity
severity — derived from the provider schema description.
SccProjectCustomModuleEnablementState
Scc Project Custom Module Enablement enum for enablement_state.
SccProjectCustomModuleSeverity
severity — derived from the provider schema description.

Extensions

RefToList on TfArg<List<RefTo<R>>>
A list-valued reference argument (security_group_ids, subnet_ids): a literal list of RefTos, or one value that is the whole list (TfArg.variable('subnet_ids'), TfArg.expression(...)).
TerraformDurationExt on Duration
Converts a Dart Duration into a Terraform duration string ("604800s").

Constants

terradartManifestVariable → const String
The environment variable the terradart command sets to the file runStack and runEnvironments describe what they wrote in.

Functions

runEnvironments<E extends Enum>(List<String> args, List<E> environments, Stack build(E env), {String dir(E env)?, String? workspace(E env)?, List<String> backendConfig(E env)?, E? defaultEnv}) → Future<void>
The entry point of a project with one Stack per environment. The environments are the members of an enum of the project's own — any names, each carrying its values — so the Stack takes a typed env and derives everything per environment from it, its backend included:
runStack(List<String> args, Stack build(), {String out = 'tf-out'}) → Future<void>
The entry point of a project with one Stack: writes it to out.

Exceptions / Errors

DuplicateModuleError
A ModuleCall registered twice under one name.
DuplicateResourceError
Thrown by Stack.add when an entry with the same (kind, terraformType, localName) triple is registered twice.
SynthException
Thrown by Stack.synth() and Stack.writeTo() when the Stack has one or more SynthIssues. Nothing is written.