GCP.AccessContextManager reference
AccessPoliciesAccessLevel
Section titled “AccessPoliciesAccessLevel”Source:
src/GCP/AccessContextManager/AccessPoliciesAccessLevel.ts
An Access Context Manager access level.
Access levels label requests to Google Cloud services with a set of
requirements (IP ranges, device policy, members, regions, or a custom
CEL expression). They live under an AccessPolicy.
Access levels have no labels. Alchemy stamps ownership into
description so list / pnpm nuke:gcp can find them. policy and
accessLevelId are immutable — changing them replaces the level.
Title, description, basic, and custom update in place.
AccessPoliciesAccessLevel: Creating an Access Level
Section titled “AccessPoliciesAccessLevel: Creating an Access Level”Basic level that allows the US
const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", { scopes: ["projects/123456789"],});const level = yield* GCP.AccessContextManager.AccessPoliciesAccessLevel( "CorpUsers", { policy: policy.name, title: "corp users", basic: { conditions: [{ regions: ["US"] }] }, },);Custom CEL level
const level = yield* GCP.AccessContextManager.AccessPoliciesAccessLevel( "Employees", { policy: policy.name, title: "employees", custom: { expr: { expression: "request.time.getHours() >= 9" }, }, },);AccessPoliciesAccessLevel: Updating an Access Level
Section titled “AccessPoliciesAccessLevel: Updating an Access Level”const level = yield* GCP.AccessContextManager.AccessPoliciesAccessLevel( "CorpUsers", { policy: policy.name, title: "corp users", basic: { conditions: [{ ipSubnetworks: ["203.0.113.0/24"] }], }, },);AccessPoliciesAuthorizedOrgsDesc
Section titled “AccessPoliciesAuthorizedOrgsDesc”Source:
src/GCP/AccessContextManager/AccessPoliciesAuthorizedOrgsDesc.ts
An Access Context Manager authorized-orgs descriptor.
Authorized-orgs descriptors configure cross-organization authorization
for device or credential-strength evaluation. They live under an
AccessPolicy. The API has no labels or description field —
Alchemy uses the generated resource id as identity, and list returns
descriptors under Alchemy-owned access policies so pnpm nuke:gcp
can find them.
policy, authorizedOrgsDescId, authorizationDirection,
assetType, and authorizationType are immutable. orgs updates in
place.
AccessPoliciesAuthorizedOrgsDesc: Creating an Authorized Orgs Descriptor
Section titled “AccessPoliciesAuthorizedOrgsDesc: Creating an Authorized Orgs Descriptor”const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", { scopes: ["projects/123456789"],});const desc = yield* GCP.AccessContextManager.AccessPoliciesAuthorizedOrgsDesc( "Partner", { policy: policy.name, authorizationDirection: "AUTHORIZATION_DIRECTION_FROM", assetType: "ASSET_TYPE_DEVICE", authorizationType: "AUTHORIZATION_TYPE_TRUST", orgs: ["organizations/987654321"], },);AccessPoliciesAuthorizedOrgsDesc: Updating an Authorized Orgs Descriptor
Section titled “AccessPoliciesAuthorizedOrgsDesc: Updating an Authorized Orgs Descriptor”const desc = yield* GCP.AccessContextManager.AccessPoliciesAuthorizedOrgsDesc( "Partner", { policy: policy.name, authorizationDirection: "AUTHORIZATION_DIRECTION_FROM", assetType: "ASSET_TYPE_DEVICE", authorizationType: "AUTHORIZATION_TYPE_TRUST", orgs: ["organizations/111", "organizations/222"], },);AccessPoliciesServicePerimeter
Section titled “AccessPoliciesServicePerimeter”Source:
src/GCP/AccessContextManager/AccessPoliciesServicePerimeter.ts
An Access Context Manager service perimeter.
A service perimeter groups Google Cloud resources that can freely exchange data with each other but not with the outside. Regular perimeters cannot overlap; bridges can share projects.
Service perimeters have no labels. Alchemy stamps ownership into
description so list / pnpm nuke:gcp can find them. policy,
servicePerimeterId, and perimeterType are immutable. Title,
description, status, spec, and useExplicitDryRunSpec update in
place.
AccessPoliciesServicePerimeter: Creating a Service Perimeter
Section titled “AccessPoliciesServicePerimeter: Creating a Service Perimeter”const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", { scopes: ["projects/123456789"],});const perimeter = yield* GCP.AccessContextManager.AccessPoliciesServicePerimeter( "Storage", { policy: policy.name, title: "storage perimeter", status: { restrictedServices: ["storage.googleapis.com"], }, },);AccessPoliciesServicePerimeter: Updating a Service Perimeter
Section titled “AccessPoliciesServicePerimeter: Updating a Service Perimeter”const perimeter = yield* GCP.AccessContextManager.AccessPoliciesServicePerimeter( "Storage", { policy: policy.name, title: "data perimeter", status: { restrictedServices: [ "storage.googleapis.com", "bigquery.googleapis.com", ], }, },);AccessPolicy
Section titled “AccessPolicy”Source:
src/GCP/AccessContextManager/AccessPolicy.ts
An Access Context Manager access policy.
An access policy is the container for access levels, service
perimeters, and authorized-orgs descriptors. One unscoped
(organization-wide) policy is allowed per organization; additional
policies must set scopes to a folder or project.
Access policies have no labels. Alchemy stamps ownership into title
so list / pnpm nuke:gcp can find them. parent and scopes are
immutable — changing them replaces the policy. title updates in
place. The policy id is assigned by the API.
AccessPolicy: Creating an Access Policy
Section titled “AccessPolicy: Creating an Access Policy”Scoped to the current project
const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", { title: "corp access policy", scopes: ["projects/123456789"],});Organization-wide default policy
const policy = yield* GCP.AccessContextManager.AccessPolicy("Default", { parent: "organizations/123456789", title: "default policy",});AccessPolicy: Updating an Access Policy
Section titled “AccessPolicy: Updating an Access Policy”const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", { title: "corp access policy (prod)", scopes: ["projects/123456789"],});GcpUserAccessBinding
Section titled “GcpUserAccessBinding”Source:
src/GCP/AccessContextManager/GcpUserAccessBinding.ts
A Context-Aware Access binding of Cloud Console / API restrictions to a Google Group.
Bindings live on an organization. The API assigns the resource name
and has no labels or description field. Identity is
(organization, groupKey) — Alchemy treats existence at that pair as
ownership, and list returns every binding on the current
organization so pnpm nuke:gcp can clean leaks.
organization and groupKey are immutable. Access levels, dry-run
levels, session settings, restricted applications, and scoped settings
update in place.
GcpUserAccessBinding: Creating a Binding
Section titled “GcpUserAccessBinding: Creating a Binding”const binding = yield* GCP.AccessContextManager.GcpUserAccessBinding( "Engineers", { groupKey: "01d520gv4vjcrht", accessLevels: ["accessPolicies/9522/accessLevels/device_trusted"], },);GcpUserAccessBinding: Updating a Binding
Section titled “GcpUserAccessBinding: Updating a Binding”const binding = yield* GCP.AccessContextManager.GcpUserAccessBinding( "Engineers", { groupKey: "01d520gv4vjcrht", accessLevels: ["accessPolicies/9522/accessLevels/corp_network"], },);