GoogleMonitoringNotificationChannel class final

Factory wrapper for google_monitoring_notification_channel.

A NotificationChannel is a medium through which an alert is delivered when a policy violation is detected. Examples of channels include email, SMS, and third-party messaging applications. Fields containing sensitive information like authentication tokens or contact info are only partially populated on retrieval.

Notification Channels are designed to be flexible and are made up of a supported type and labels to configure that channel. Each type has specific labels that need to be present for that channel to be correctly configured. The labels that are required to be present for one channel type are often different than those required for another. Due to these loose constraints it's often best to set up a channel through the UI and import to Terraform when setting up a brand new channel type to determine which labels are required.

A list of supported channels per project the list endpoint can be accessed programmatically or through the api explorer at https://cloud.google.com/monitoring/api/ref_v3/rest/v3/projects.notificationChannelDescriptors/list . This provides the channel type and all of the required labels that must be passed.

type is the notification channel type registry key. Google maintains the canonical list server-side (the API returns it from projects.notificationChannelDescriptors.list) and adds new transports asynchronously, so this slot is intentionally a free-form String rather than a Dart enum — pinning an enum here would force a terradart release every time Google ships a new descriptor.

Common type values and the channel-specific keys they expect in labels (the canonical reference is the NotificationChannelDescriptor for each type):

  • "email" — labels: {'email_address': 'oncall@example.com'}.
  • "slack" — labels: {'channel_name': '#alerts', 'team': 'T01234ABCD'}. The bot OAuth token goes in sensitiveLabels as credential: .authToken(...) (NOT in labels).
  • "pagerduty" — labels: {'service_name': 'prod-oncall'}. The integration service key goes in credential: .serviceKey(...).
  • "sms" — labels: {'number': '+15551234567'} (E.164 format, pre-verified phone numbers only).
  • "webhook_basicauth" — labels: {'url': 'https://...'} + credential: .password(...) (with the basic-auth username embedded in the URL or in labels).
  • "webhook_tokenauth" — labels: {'url': 'https://...'} + credential: .authToken(...) for the bearer token.
  • "pubsub" — labels: {'topic': 'projects/<p>/topics/<t>'}. The service account that posts to the topic is managed via IAM, not via this resource.

Credentials handling: any value containing a secret (Slack token, PagerDuty service key, webhook auth token / basic-auth password) MUST be placed in sensitiveLabels rather than labels. The provider rejects configurations that supply the same logical secret in both places, and only sensitiveLabels entries are masked from plan output. sensitiveLabels.credential is sealed — exactly one of the 3 plaintext variants (.authToken, .password, .serviceKey, flagged sensitive by the provider schema) or their write-only siblings (.authTokenWo, .passwordWo, .serviceKeyWo), which keep the plaintext out of Terraform state entirely on Terraform 1.11+ — prefer them when your CLI version supports it, bumping the matching *WoVersion field to force rotation.

Verification: verificationStatus reflects whether the channel has passed Google's out-of-band verification step (e.g. clicking a link in a confirmation email, replying to an SMS). Channels in the UNVERIFIED state do not deliver notifications. Verification cannot be triggered through this resource — call gcloud alpha monitoring channels verify or the projects.notificationChannels.verify REST endpoint after apply.

Example (Slack channel):

final slack = GoogleMonitoringNotificationChannel(
  'oncall_slack',
  displayName: .literal('#oncall alerts'),
  type: .literal('slack'),
  labels: .literal(const {
    'channel_name': '#oncall',
    'team': 'T01234ABCD',
  }),
  sensitiveLabels: MonitoringNotificationChannelSensitiveLabels(
    credential: .authTokenWo(slackBotTokenSecret.version),
    authTokenWoVersion: .literal('1'),
  ),
  userLabels: .literal(const {'team': 'platform'}),
);
Inheritance

Constructors

GoogleMonitoringNotificationChannel(String localName, {TfArg<String>? displayName, required TfArg<String> type, TfArg<Map<String, String>>? labels, MonitoringNotificationChannelSensitiveLabels? sensitiveLabels, TfArg<Map<String, String>>? userLabels, TfArg<String>? description, TfArg<bool>? enabled, TfArg<bool>? forceDelete, TfArg<String>? project, LifecycleOptions? lifecycle, List<TfAddressed>? dependsOn, StackProvider? provider, TfTimeouts? timeouts})

Properties

argMap → Map<String, TfArg?>
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name). Synth emits these keys directly; the factory is responsible for the camelCase → snake_case translation at construction time.
finalinherited
defaultProvider → String
The provider name a block without provider uses: by default the prefix of terraformType (google for google_pubsub_topic).
no setterinherited
deletionPolicy → TfRef<String>
Reference to deletion_policy attribute.
no setter
dependsOn → List<TfAddressed>?
Optional depends_on = [...]: the resources, data sources and module calls this block waits for, e.g. dependsOn: [api, ...apiDeps]. Terraform takes whole blocks only, so an entry is never an attribute.
finalinherited
description → TfRef<String>
Reference to description attribute.
no setter
displayName → TfRef<String>
Reference to display_name attribute.
no setter
enabled → TfRef<bool>
Reference to enabled attribute.
no setter
forceDelete → TfRef<bool>
Reference to force_delete attribute.
no setter
hashCode → int
The hash code for this object.
no setterinherited
id → TfRef<String>
Reference to id attribute.
no setter
kind → ResourceKind
Always ResourceKind.resource. Overridden by Data.
no setterinherited
labels → TfRef<Map<String, String>>
Reference to labels attribute.
no setter
lifecycle → LifecycleOptions?
Optional lifecycle { ... } block.
finalinherited
localName → String
User-supplied local name within a Stack.
finalinherited
name → TfRef<String>
Reference to name attribute.
no setter
project → TfRef<String>
Reference to project attribute.
no setter
provider → StackProvider?
Optional Terraform provider meta-argument: the provider configuration this block uses, e.g. the aliased GoogleProvider(alias: 'eu') the Stack registered with addProvider.
finalinherited
ref → RefTo<GoogleMonitoringNotificationChannel>
A reference to this resource, for arguments typed RefTo<GoogleMonitoringNotificationChannel>.
no setter
runtimeType → Type
A representation of the runtime type of the object.
no setterinherited
sensitiveFields → Set<String>
Field names that are @Sensitive per the IR-derived per-resource constant. Curated factories override with a baked-in static const Set<String> (file-private in v0.5+).
no setteroverride
supportsDeletionProtection → bool
Capability flag: true when this resource's underlying Terraform schema has a deletion_protection boolean attribute that the synth-time devMode flow can flip to false. Defaults to false; the codegen emitter overrides this to true for wrappers whose schema includes the attribute.
no setterinherited
terraformType → String
Terraform resource type, e.g. google_pubsub_topic.
finalinherited
tfAddress → String
Terraform address <terraformType>.<localName>, e.g. google_pubsub_topic.orders.
no setterinherited
timeouts → TfTimeouts?
Optional timeouts { ... } block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, and terraform validate decides whether this resource's schema declares the operations set here.
finalinherited
type → TfRef<String>
Reference to type attribute.
no setter
userLabels → TfRef<Map<String, String>>
Reference to user_labels attribute.
no setter
verificationStatus → TfRef<String>
Reference to verification_status attribute.
no setter

Methods

noSuchMethod(Invocation invocation) → dynamic
Invoked when a nonexistent method or property is accessed.
inherited
toString() → String
A string representation of this object.
inherited

Operators

operator ==(Object other) → bool
The equality operator.
inherited

Constants

tfType → const String