Skip to content

GCP.AccessContextManager reference

Source: src/GCP/AccessContextManager/AccessPoliciesAccessLevel.ts

An Access Context Manager access level.

Access levels label requests to Google Cloud services with a set of requirements (IP ranges, device policy, members, regions, or a custom CEL expression). They live under an AccessPolicy.

Access levels have no labels. Alchemy stamps ownership into description so list / pnpm nuke:gcp can find them. policy and accessLevelId are immutable — changing them replaces the level. Title, description, basic, and custom update in place.

AccessPoliciesAccessLevel: Creating an Access Level

Section titled “AccessPoliciesAccessLevel: Creating an Access Level”

Basic level that allows the US

const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", {
scopes: ["projects/123456789"],
});
const level = yield* GCP.AccessContextManager.AccessPoliciesAccessLevel(
"CorpUsers",
{
policy: policy.name,
title: "corp users",
basic: { conditions: [{ regions: ["US"] }] },
},
);

Custom CEL level

const level = yield* GCP.AccessContextManager.AccessPoliciesAccessLevel(
"Employees",
{
policy: policy.name,
title: "employees",
custom: {
expr: { expression: "request.time.getHours() >= 9" },
},
},
);

AccessPoliciesAccessLevel: Updating an Access Level

Section titled “AccessPoliciesAccessLevel: Updating an Access Level”
const level = yield* GCP.AccessContextManager.AccessPoliciesAccessLevel(
"CorpUsers",
{
policy: policy.name,
title: "corp users",
basic: {
conditions: [{ ipSubnetworks: ["203.0.113.0/24"] }],
},
},
);

Source: src/GCP/AccessContextManager/AccessPoliciesAuthorizedOrgsDesc.ts

An Access Context Manager authorized-orgs descriptor.

Authorized-orgs descriptors configure cross-organization authorization for device or credential-strength evaluation. They live under an AccessPolicy. The API has no labels or description field — Alchemy uses the generated resource id as identity, and list returns descriptors under Alchemy-owned access policies so pnpm nuke:gcp can find them.

policy, authorizedOrgsDescId, authorizationDirection, assetType, and authorizationType are immutable. orgs updates in place.

AccessPoliciesAuthorizedOrgsDesc: Creating an Authorized Orgs Descriptor

Section titled “AccessPoliciesAuthorizedOrgsDesc: Creating an Authorized Orgs Descriptor”
const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", {
scopes: ["projects/123456789"],
});
const desc = yield* GCP.AccessContextManager.AccessPoliciesAuthorizedOrgsDesc(
"Partner",
{
policy: policy.name,
authorizationDirection: "AUTHORIZATION_DIRECTION_FROM",
assetType: "ASSET_TYPE_DEVICE",
authorizationType: "AUTHORIZATION_TYPE_TRUST",
orgs: ["organizations/987654321"],
},
);

AccessPoliciesAuthorizedOrgsDesc: Updating an Authorized Orgs Descriptor

Section titled “AccessPoliciesAuthorizedOrgsDesc: Updating an Authorized Orgs Descriptor”
const desc = yield* GCP.AccessContextManager.AccessPoliciesAuthorizedOrgsDesc(
"Partner",
{
policy: policy.name,
authorizationDirection: "AUTHORIZATION_DIRECTION_FROM",
assetType: "ASSET_TYPE_DEVICE",
authorizationType: "AUTHORIZATION_TYPE_TRUST",
orgs: ["organizations/111", "organizations/222"],
},
);

Source: src/GCP/AccessContextManager/AccessPoliciesServicePerimeter.ts

An Access Context Manager service perimeter.

A service perimeter groups Google Cloud resources that can freely exchange data with each other but not with the outside. Regular perimeters cannot overlap; bridges can share projects.

Service perimeters have no labels. Alchemy stamps ownership into description so list / pnpm nuke:gcp can find them. policy, servicePerimeterId, and perimeterType are immutable. Title, description, status, spec, and useExplicitDryRunSpec update in place.

AccessPoliciesServicePerimeter: Creating a Service Perimeter

Section titled “AccessPoliciesServicePerimeter: Creating a Service Perimeter”
const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", {
scopes: ["projects/123456789"],
});
const perimeter = yield* GCP.AccessContextManager.AccessPoliciesServicePerimeter(
"Storage",
{
policy: policy.name,
title: "storage perimeter",
status: {
restrictedServices: ["storage.googleapis.com"],
},
},
);

AccessPoliciesServicePerimeter: Updating a Service Perimeter

Section titled “AccessPoliciesServicePerimeter: Updating a Service Perimeter”
const perimeter = yield* GCP.AccessContextManager.AccessPoliciesServicePerimeter(
"Storage",
{
policy: policy.name,
title: "data perimeter",
status: {
restrictedServices: [
"storage.googleapis.com",
"bigquery.googleapis.com",
],
},
},
);

Source: src/GCP/AccessContextManager/AccessPolicy.ts

An Access Context Manager access policy.

An access policy is the container for access levels, service perimeters, and authorized-orgs descriptors. One unscoped (organization-wide) policy is allowed per organization; additional policies must set scopes to a folder or project.

Access policies have no labels. Alchemy stamps ownership into title so list / pnpm nuke:gcp can find them. parent and scopes are immutable — changing them replaces the policy. title updates in place. The policy id is assigned by the API.

Scoped to the current project

const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", {
title: "corp access policy",
scopes: ["projects/123456789"],
});

Organization-wide default policy

const policy = yield* GCP.AccessContextManager.AccessPolicy("Default", {
parent: "organizations/123456789",
title: "default policy",
});
const policy = yield* GCP.AccessContextManager.AccessPolicy("Corp", {
title: "corp access policy (prod)",
scopes: ["projects/123456789"],
});

Source: src/GCP/AccessContextManager/GcpUserAccessBinding.ts

A Context-Aware Access binding of Cloud Console / API restrictions to a Google Group.

Bindings live on an organization. The API assigns the resource name and has no labels or description field. Identity is (organization, groupKey) — Alchemy treats existence at that pair as ownership, and list returns every binding on the current organization so pnpm nuke:gcp can clean leaks.

organization and groupKey are immutable. Access levels, dry-run levels, session settings, restricted applications, and scoped settings update in place.

const binding = yield* GCP.AccessContextManager.GcpUserAccessBinding(
"Engineers",
{
groupKey: "01d520gv4vjcrht",
accessLevels: ["accessPolicies/9522/accessLevels/device_trusted"],
},
);
const binding = yield* GCP.AccessContextManager.GcpUserAccessBinding(
"Engineers",
{
groupKey: "01d520gv4vjcrht",
accessLevels: ["accessPolicies/9522/accessLevels/corp_network"],
},
);