GoogleComputeBackendBucket class final

Factory wrapper for google_compute_backend_bucket.

Backend buckets allow you to use Google Cloud Storage buckets with HTTP(S) load balancing.

An HTTP(S) load balancer can direct traffic to specified URLs to a backend bucket rather than a backend service. It can send requests for static content to a Cloud Storage bucket and requests for dynamic content to a virtual machine instance.

A global backend bucket — the load-balancing target that points an HTTPS load balancer at a Google Cloud Storage bucket of static objects. Use this when the load balancer needs to serve static content (images, JS/CSS bundles, downloadable assets) directly out of GCS without routing through a VM or serverless backend. Pair it with a URL map (a google_compute_url_map path_matcher typically has the form default_service = backendService and path_rule = backendBucket for a /static/* prefix).

Required identity:

  • localName: Terraform local name (the address segment after google_compute_backend_bucket.).
  • name: GCP resource name (1-63 chars, lowercase RFC1035).
  • bucket_name: the name of an existing Cloud Storage bucket (e.g. 'my-static-assets'). This is the bucket name only — not a gs:// URI and not the bucket's self-link. The bucket must exist in the same project and be readable by the load balancer's service identity (allUsers-readable for public CDN serving, or granted via the Cloud CDN signed-URL key for private content).

Cross-resource references:

  • edgeSecurityPolicy is the self-link of a google_compute_security_policy of type CLOUD_ARMOR_EDGE (distinct from a regular Cloud Armor policy — edge policies attach at the load balancer's edge, ahead of the cache). Use var.security_policy_id in real configs: edgeSecurityPolicy: TfArg.literal('projects/p/global/securityPolicies/edge-deny-all').
  • The compositional inverse is at a URL map: a google_compute_url_map.path_rule.service references this bucket's selfLink.

Example (CDN-fronted static assets with custom cache headers):

final assets = GoogleComputeBackendBucket(
  'static_assets',
  name: TfArg.literal('static-assets'),
  bucketName: .literal('my-static-assets'),
  enableCdn: TfArg.literal(true),
  cdnPolicy: ComputeBackendBucketCdnPolicy(
    cacheMode: BackendBucketCacheMode.cacheAllStatic,
    defaultTtl: .literal(3600),
    maxTtl: .literal(86400),
    clientTtl: .literal(3600),
    negativeCaching: .literal(true),
    negativeCachingPolicy: [
      .new(code: .literal(404), ttl: .literal(120)),
      .new(code: .literal(410), ttl: .literal(120)),
    ],
    serveWhileStale: .literal(60),
  ),
  customResponseHeaders: TfArg.literal([
    'X-Cache: \$(cache_status)',
  ]),
  compressionMode:
      BackendBucketCompressionMode.automatic,
);

Example (private bucket fronted by Cloud Armor edge policy):

final secured = GoogleComputeBackendBucket(
  'secured_assets',
  name: TfArg.literal('secured-assets'),
  bucketName: .literal('private-static-assets'),
  enableCdn: TfArg.literal(true),
  edgeSecurityPolicy: TfArg.literal(
    // var.security_policy_id — a CLOUD_ARMOR_EDGE-typed
    // google_compute_security_policy self-link.
    'projects/p/global/securityPolicies/edge-rate-limit',
  ),
);

Nested-type prefix: every helper class for a cdn_policy sub-block is BackendBucket-prefixed (e.g. ComputeBackendBucketCdnPolicy, ComputeBackendBucketCdnCacheKeyPolicy, ComputeBackendBucketCdnNegativeCachingPolicy, ComputeBackendBucketCdnBypassCacheOnRequestHeader). The shape mirrors the BackendService* family but is a distinct type — the bucket and service CDN configurations are not interchangeable, even where the schema field names agree.

Composition pattern: extends Resource for runtime behavior.

Inheritance

Constructors

GoogleComputeBackendBucket(String localName, {required TfArg<String> name, required RefTo<GoogleStorageBucket> bucketName, TfArg<String>? description, TfArg<bool>? enableCdn, BackendBucketCompressionMode? compressionMode, TfArg<List<String>>? customResponseHeaders, TfArg<String>? edgeSecurityPolicy, BackendBucketLoadBalancingScheme? loadBalancingScheme, ComputeBackendBucketCdnPolicy? cdnPolicy, ComputeBackendBucketParams? params, TfArg<String>? project, LifecycleOptions? lifecycle, List<TfAddressed>? dependsOn, StackProvider? provider, TfTimeouts? timeouts})

Properties

argMap → Map<String, TfArg?>
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name). Synth emits these keys directly; the factory is responsible for the camelCase → snake_case translation at construction time.
finalinherited
bucketName → TfRef<String>
Reference to bucket_name attribute.
no setter
compressionMode → TfRef<String>
Reference to compression_mode attribute.
no setter
creationTimestamp → TfRef<String>
Reference to creation_timestamp attribute.
no setter
customResponseHeaders → TfRef<List<String>>
Reference to custom_response_headers attribute.
no setter
defaultProvider → String
The provider name a block without provider uses: by default the prefix of terraformType (google for google_pubsub_topic).
no setterinherited
deletionPolicy → TfRef<String>
Reference to deletion_policy attribute.
no setter
dependsOn → List<TfAddressed>?
Optional depends_on = [...]: the resources, data sources and module calls this block waits for, e.g. dependsOn: [api, ...apiDeps]. Terraform takes whole blocks only, so an entry is never an attribute.
finalinherited
description → TfRef<String>
Reference to description attribute.
no setter
edgeSecurityPolicy → TfRef<String>
Reference to edge_security_policy attribute.
no setter
enableCdn → TfRef<bool>
Reference to enable_cdn attribute.
no setter
hashCode → int
The hash code for this object.
no setterinherited
id → TfRef<String>
Reference to id attribute.
no setter
kind → ResourceKind
Always ResourceKind.resource. Overridden by Data.
no setterinherited
lifecycle → LifecycleOptions?
Optional lifecycle { ... } block.
finalinherited
loadBalancingScheme → TfRef<String>
Reference to load_balancing_scheme attribute.
no setter
localName → String
User-supplied local name within a Stack.
finalinherited
name → TfRef<String>
Reference to name attribute.
no setter
project → TfRef<String>
Reference to project attribute.
no setter
provider → StackProvider?
Optional Terraform provider meta-argument: the provider configuration this block uses, e.g. the aliased GoogleProvider(alias: 'eu') the Stack registered with addProvider.
finalinherited
ref → RefTo<GoogleComputeBackendBucket>
A reference to this resource, for arguments typed RefTo<GoogleComputeBackendBucket>.
no setter
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
Reference to self_link attribute.
no setter
sensitiveFields → Set<String>
Field names that are @Sensitive per the IR-derived per-resource constant. Curated factories override with a baked-in static const Set<String> (file-private in v0.5+).
no setteroverride
supportsDeletionProtection → bool
Capability flag: true when this resource's underlying Terraform schema has a deletion_protection boolean attribute that the synth-time devMode flow can flip to false. Defaults to false; the codegen emitter overrides this to true for wrappers whose schema includes the attribute.
no setterinherited
terraformType → String
Terraform resource type, e.g. google_pubsub_topic.
finalinherited
tfAddress → String
Terraform address <terraformType>.<localName>, e.g. google_pubsub_topic.orders.
no setterinherited
timeouts → TfTimeouts?
Optional timeouts { ... } block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, and terraform validate decides whether this resource's schema declares the operations set here.
finalinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Constants

tfType → const String