GoogleKmsSecretCiphertext class final
Factory wrapper for google_kms_secret_ciphertext.
Encrypts secret data with Google Cloud KMS and provides access to the ciphertext.
~> NOTE: Using this resource will allow you to conceal secret data within your resource definitions, but it does not take care of protecting that data in the logging output, plan output, or state output. Please take care to secure your secret data outside of resource definitions.
Encrypts plaintext with a GoogleKmsCryptoKey and exposes the resulting base64 ciphertext attribute.
Useful for embedding ciphertext in other resources without storing plaintext in Terraform config forever — but plan/state still see plaintext (schema-sensitive). Prefer Secret Manager for long-lived secrets.
Terraform cannot delete the ciphertext resource from GCP (exclude_delete);
destroy removes it from state only.
Example:
GoogleKmsSecretCiphertext(
'db_password',
cryptoKey: paymentsKey.ref,
plaintext: .variable('db_password'),
);
Constructors
-
GoogleKmsSecretCiphertext(String localName, {required RefTo<
GoogleKmsCryptoKey> cryptoKey, required Sensitive<String> plaintext, Sensitive<String> ? additionalAuthenticatedData, LifecycleOptions? lifecycle, List<TfAddressed> ? dependsOn, StackProvider? provider, TfTimeouts? timeouts})
Properties
-
additionalAuthenticatedData
→ TfRef<
String> -
Reference to
additional_authenticated_dataattribute.no setter -
argMap
→ Map<
String, TfArg?> -
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name).
Synth emits these keys directly; the factory is responsible for the
camelCase → snake_case translation at construction time.
finalinherited
-
ciphertext
→ TfRef<
String> -
Reference to
ciphertextattribute.no setter -
cryptoKey
→ TfRef<
String> -
Reference to
crypto_keyattribute.no setter - defaultProvider → String
-
The provider name a block without provider uses: by default the
prefix of terraformType (
googleforgoogle_pubsub_topic).no setterinherited -
dependsOn
→ List<
TfAddressed> ? -
Optional
depends_on = [...]: the resources, data sources and module calls this block waits for, e.g.dependsOn: [api, ...apiDeps]. Terraform takes whole blocks only, so an entry is never an attribute.finalinherited - hashCode → int
-
The hash code for this object.
no setterinherited
-
id
→ TfRef<
String> -
Reference to
idattribute.no setter - kind → ResourceKind
-
Always
ResourceKind.resource. Overridden byData.no setterinherited - lifecycle → LifecycleOptions?
-
Optional
lifecycle { ... }block.finalinherited - localName → String
-
User-supplied local name within a Stack.
finalinherited
-
plaintext
→ TfRef<
String> -
Reference to
plaintextattribute.no setter - provider → StackProvider?
-
Optional Terraform
providermeta-argument: the provider configuration this block uses, e.g. the aliasedGoogleProvider(alias: 'eu')the Stack registered withaddProvider.finalinherited -
ref
→ RefTo<
GoogleKmsSecretCiphertext> -
A reference to this resource, for arguments typed
RefTo<GoogleKmsSecretCiphertext>.no setter - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
sensitiveFields
→ Set<
String> -
Field names that are
@Sensitiveper the IR-derived per-resource constant. Curated factories override with a baked-instatic const Set<String>(file-private in v0.5+).no setteroverride - supportsDeletionProtection → bool
-
Capability flag: true when this resource's underlying Terraform
schema has a
deletion_protectionboolean attribute that the synth-time devMode flow can flip tofalse. Defaults to false; the codegen emitter overrides this totruefor wrappers whose schema includes the attribute.no setterinherited - terraformType → String
-
Terraform resource type, e.g.
google_pubsub_topic.finalinherited - tfAddress → String
-
Terraform address
<terraformType>.<localName>, e.g.google_pubsub_topic.orders.no setterinherited - timeouts → TfTimeouts?
-
Optional
timeouts { ... }block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, andterraform validatedecides whether this resource's schema declares the operations set here.finalinherited
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited