GoogleKmsSecretCiphertext class final

Factory wrapper for google_kms_secret_ciphertext.

Encrypts secret data with Google Cloud KMS and provides access to the ciphertext.

~> NOTE: Using this resource will allow you to conceal secret data within your resource definitions, but it does not take care of protecting that data in the logging output, plan output, or state output. Please take care to secure your secret data outside of resource definitions.

Encrypts plaintext with a GoogleKmsCryptoKey and exposes the resulting base64 ciphertext attribute.

Useful for embedding ciphertext in other resources without storing plaintext in Terraform config forever — but plan/state still see plaintext (schema-sensitive). Prefer Secret Manager for long-lived secrets.

Terraform cannot delete the ciphertext resource from GCP (exclude_delete); destroy removes it from state only.

Example:

GoogleKmsSecretCiphertext(
  'db_password',
  cryptoKey: paymentsKey.ref,
  plaintext: .variable('db_password'),
);
Inheritance

Constructors

GoogleKmsSecretCiphertext(String localName, {required RefTo<GoogleKmsCryptoKey> cryptoKey, required Sensitive<String> plaintext, Sensitive<String>? additionalAuthenticatedData, LifecycleOptions? lifecycle, List<TfAddressed>? dependsOn, StackProvider? provider, TfTimeouts? timeouts})

Properties

additionalAuthenticatedData → TfRef<String>
Reference to additional_authenticated_data attribute.
no setter
argMap → Map<String, TfArg?>
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name). Synth emits these keys directly; the factory is responsible for the camelCase → snake_case translation at construction time.
finalinherited
ciphertext → TfRef<String>
Reference to ciphertext attribute.
no setter
cryptoKey → TfRef<String>
Reference to crypto_key attribute.
no setter
defaultProvider → String
The provider name a block without provider uses: by default the prefix of terraformType (google for google_pubsub_topic).
no setterinherited
dependsOn → List<TfAddressed>?
Optional depends_on = [...]: the resources, data sources and module calls this block waits for, e.g. dependsOn: [api, ...apiDeps]. Terraform takes whole blocks only, so an entry is never an attribute.
finalinherited
hashCode → int
The hash code for this object.
no setterinherited
id → TfRef<String>
Reference to id attribute.
no setter
kind → ResourceKind
Always ResourceKind.resource. Overridden by Data.
no setterinherited
lifecycle → LifecycleOptions?
Optional lifecycle { ... } block.
finalinherited
localName → String
User-supplied local name within a Stack.
finalinherited
plaintext → TfRef<String>
Reference to plaintext attribute.
no setter
provider → StackProvider?
Optional Terraform provider meta-argument: the provider configuration this block uses, e.g. the aliased GoogleProvider(alias: 'eu') the Stack registered with addProvider.
finalinherited
ref → RefTo<GoogleKmsSecretCiphertext>
A reference to this resource, for arguments typed RefTo<GoogleKmsSecretCiphertext>.
no setter
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
sensitiveFields → Set<String>
Field names that are @Sensitive per the IR-derived per-resource constant. Curated factories override with a baked-in static const Set<String> (file-private in v0.5+).
no setteroverride
supportsDeletionProtection → bool
Capability flag: true when this resource's underlying Terraform schema has a deletion_protection boolean attribute that the synth-time devMode flow can flip to false. Defaults to false; the codegen emitter overrides this to true for wrappers whose schema includes the attribute.
no setterinherited
terraformType → String
Terraform resource type, e.g. google_pubsub_topic.
finalinherited
tfAddress → String
Terraform address <terraformType>.<localName>, e.g. google_pubsub_topic.orders.
no setterinherited
timeouts → TfTimeouts?
Optional timeouts { ... } block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, and terraform validate decides whether this resource's schema declares the operations set here.
finalinherited

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Constants

tfType → const String