GoogleServiceAccount class final
Factory wrapper for google_service_account.
Creates an IAM service account on a project. Its principal is the
serviceAccount:<email> an IAM grant takes, so no call site spells the
prefix by hand.
Required identity:
- localName: Terraform local name (the address segment after
google_service_account.). accountId: short ID before the@in the resulting email (e.g.'my-runner'→my-runner@<project>.iam.gserviceaccount.com). Must be 6-30 chars matching[a-z]([-a-z0-9]*[a-z0-9]). ForceNew: changing this destroys and recreates the SA.
Optional knobs:
project: explicit project ID; defaults to the provider'sprojectwhen omitted. ForceNew in the provider.displayName: human-readable name shown in the GCP console.description: free-form text (≤ 256 UTF-8 bytes).createIgnoreAlreadyExists: whentrue, skip creation if an SA with the same email already exists. Useful for shared environments where a peer Terraform stack may have created the SA first.disabled: disables the SA without deleting it. Defaults tofalse.
Example pairing with GooglePubsubTopicIamMember:
final sa = GoogleServiceAccount(
'publisher',
accountId: TfArg.literal('orders-publisher'),
displayName: TfArg.literal('Orders publisher'),
);
final orders = GooglePubsubTopic(
'orders',
name: TfArg.literal('orders-prod'),
);
// `serviceAccount:orders-publisher@<project>.iam.gserviceaccount.com`
GooglePubsubTopicIamMember(
'orders_publisher_binding',
topic: orders.ref,
role: TfArg.literal('roles/pubsub.publisher'),
member: sa.principal,
);
Composition pattern: extends Resource for
runtime behavior, implements $GoogleServiceAccount for the schemantic
schema surface. argMap stores TfArg<dynamic>? entries directly;
synth's JSON-encoding pass walks them and calls arg.toTfJson() to
encode at write time.
Constructors
-
GoogleServiceAccount(String localName, {required TfArg<
String> accountId, TfArg<String> ? deletionPolicy, TfArg<String> ? project, TfArg<String> ? displayName, TfArg<String> ? description, TfArg<bool> ? createIgnoreAlreadyExists, TfArg<bool> ? disabled, LifecycleOptions? lifecycle, List<TfAddressed> ? dependsOn, StackProvider? provider, TfTimeouts? timeouts})
Properties
-
argMap
→ Map<
String, TfArg?> -
Argument-name → TfArg map. Keys are snake_case (Terraform JSON name).
Synth emits these keys directly; the factory is responsible for the
camelCase → snake_case translation at construction time.
finalinherited
- defaultProvider → String
-
The provider name a block without provider uses: by default the
prefix of terraformType (
googleforgoogle_pubsub_topic).no setterinherited -
dependsOn
→ List<
TfAddressed> ? -
Optional
depends_on = [...]: the resources, data sources and module calls this block waits for, e.g.dependsOn: [api, ...apiDeps]. Terraform takes whole blocks only, so an entry is never an attribute.finalinherited -
email
→ TfRef<
String> -
email—<accountId>@<project>.iam.gserviceaccount.com. Use this when you need the bare email (e.g. injecting into an external system's config) — for IAM grants pass principal.no setter - hashCode → int
-
The hash code for this object.
no setterinherited
-
id
→ TfRef<
String> -
id— full resource pathprojects/{project}/serviceAccounts/{email}.no setter - kind → ResourceKind
-
Always
ResourceKind.resource. Overridden byData.no setterinherited - lifecycle → LifecycleOptions?
-
Optional
lifecycle { ... }block.finalinherited - localName → String
-
User-supplied local name within a Stack.
finalinherited
-
name
→ TfRef<
String> -
name— same as id (legacy alias retained by the provider).no setter - principal → IamPrincipal
-
This identity as an IAM principal, for
member/members.no setter - provider → StackProvider?
-
Optional Terraform
providermeta-argument: the provider configuration this block uses, e.g. the aliasedGoogleProvider(alias: 'eu')the Stack registered withaddProvider.finalinherited -
ref
→ RefTo<
GoogleServiceAccount> -
A reference to this resource, for arguments typed
RefTo<GoogleServiceAccount>.no setter - runtimeType → Type
-
A representation of the runtime type of the object.
no setterinherited
-
sensitiveFields
→ Set<
String> -
Field names that are
@Sensitiveper the IR-derived per-resource constant. Curated factories override with a baked-instatic const Set<String>(file-private in v0.5+).no setteroverride - supportsDeletionProtection → bool
-
Capability flag: true when this resource's underlying Terraform
schema has a
deletion_protectionboolean attribute that the synth-time devMode flow can flip tofalse. Defaults to false; the codegen emitter overrides this totruefor wrappers whose schema includes the attribute.no setterinherited - terraformType → String
-
Terraform resource type, e.g.
google_pubsub_topic.finalinherited - tfAddress → String
-
Terraform address
<terraformType>.<localName>, e.g.google_pubsub_topic.orders.no setterinherited - timeouts → TfTimeouts?
-
Optional
timeouts { ... }block: how long Terraform waits for each operation. Provider-neutral like lifecycle — synth copies the duration strings verbatim, andterraform validatedecides whether this resource's schema declares the operations set here.finalinherited -
uniqueId
→ TfRef<
String> -
unique_id— numeric unique identifier assigned by GCP. Stable across rename if you changedisplay_name; differs from id / email.no setter
Methods
-
noSuchMethod(
Invocation invocation) → dynamic -
Invoked when a nonexistent method or property is accessed.
inherited
-
toString(
) → String -
A string representation of this object.
inherited
Operators
-
operator ==(
Object other) → bool -
The equality operator.
inherited