Skip to content

GCP.Apigee reference

Source: src/GCP/Apigee/AnalyticsDatastore.ts

An Apigee analytics datastore — an export target (Cloud Storage or BigQuery) for organization analytics.

Datastores have no labels field. Alchemy stamps ownership into displayName so list / nuke can find them. The datastore id is server-assigned.

GCS export target

const store = yield* GCP.Apigee.AnalyticsDatastore("Exports", {
targetType: "gcs",
datastoreConfig: {
projectId: "my-project",
bucketName: "apigee-analytics",
path: "exports",
},
});

BigQuery export target

const store = yield* GCP.Apigee.AnalyticsDatastore("BqExports", {
targetType: "bigquery",
datastoreConfig: {
projectId: "my-project",
datasetName: "apigee",
tablePrefix: "analytics",
},
});

Source: src/GCP/Apigee/Api.ts

An Apigee API proxy. The proxy is not serving traffic until a revision is deployed to an environment.

Labels (alchemy-stack / alchemy-stage / alchemy-id) stamp ownership so list / nuke can find proxies. Changing apiId or organizationId replaces the proxy.

Generated name

const proxy = yield* GCP.Apigee.Api("Orders", {});

Explicit id and labels

const proxy = yield* GCP.Apigee.Api("Orders", {
apiId: "orders-v1",
labels: { env: "prod" },
});

Source: src/GCP/Apigee/ApimServiceExtension.ts

An APIM service extension that routes load-balancer traffic to an existing Apigee X instance.

Service extensions have no labels or description. Alchemy stamps ownership as a never-matching alchown extension so list / nuke can find them. Changing the id or organization replaces the resource.

ApimServiceExtension: Creating a Service Extension

Section titled “ApimServiceExtension: Creating a Service Extension”
const extension = yield* GCP.Apigee.ApimServiceExtension("Edge", {
lbForwardingRule:
"projects/my-project/regions/us-central1/forwardingRules/https",
network: "projects/my-project/global/networks/default",
networkConfigs: [{
region: "us-central1",
subnet: "projects/my-project/regions/us-central1/subnetworks/default",
}],
extensionProcessor: "ext-processor",
});

Source: src/GCP/Apigee/Apiproduct.ts

An Apigee API product — a bundle of proxies, resources, quota, and metadata delivered to developers.

Products have no labels field. Alchemy stamps ownership into attributes (alchemy-stack / alchemy-stage / alchemy-id) so list / nuke can find them. The internal name is immutable.

Generated name, auto-approved

const product = yield* GCP.Apigee.Apiproduct("Public", {
displayName: "Public APIs",
approvalType: "auto",
});

Bound to proxies and a quota

const product = yield* GCP.Apigee.Apiproduct("Orders", {
displayName: "Orders",
environments: ["prod"],
proxies: ["orders-v1"],
approvalType: "auto",
quota: "1000",
quotaInterval: "1",
quotaTimeUnit: "hour",
});

Source: src/GCP/Apigee/ApiproductsRateplan.ts

An Apigee rate plan attached to an API product for monetization.

Rate plans have no labels field and their text is shown to portal developers, so Alchemy tracks a plan only by the server-assigned id in its state; nuke cannot discover plans. Only one plan per product can be PUBLISHED.

const plan = yield* GCP.Apigee.ApiproductsRateplan("Standard", {
apiproduct: product.apiproductId,
displayName: "Standard",
billingPeriod: "MONTHLY",
currencyCode: "USD",
state: "DRAFT",
});

Source: src/GCP/Apigee/ApisKeyvaluemap.ts

An API-proxy-scoped Apigee key value map.

KVMs have no labels and no List API. Alchemy writes an ownership sentinel entry (__alchemy) so read can distinguish owned maps. list walks alchemy-labeled API proxies and looks up a map whose id matches the proxy id plus any map named on the sentinel of that lookup; maps whose ids cannot be discovered are still deleted with the parent proxy. Changing mapId, api, or organizationId replaces the map.

const map = yield* GCP.Apigee.ApisKeyvaluemap("Config", {
api: proxy.apiId,
});

Source: src/GCP/Apigee/ApisKeyvaluemapsEntry.ts

A key/value entry in an API-proxy-scoped Apigee key value map.

Entries have no labels. Alchemy treats entries inside a map that carries the __alchemy sentinel as owned so list / nuke can find them. Changing entryId, map, api, or organizationId replaces the entry. The reserved key __alchemy is used for map ownership and is not a user entry.

const entry = yield* GCP.Apigee.ApisKeyvaluemapsEntry("Timeout", {
api: proxy.apiId,
map: map.mapId,
entryId: "timeout-ms",
value: "5000",
});

Source: src/GCP/Apigee/Appgroup.ts

An Apigee AppGroup — a logical grouping of apps that share credentials.

AppGroups have no labels field. Alchemy stamps ownership into attributes so list / nuke can find them. The name is immutable.

Generated name

const group = yield* GCP.Apigee.Appgroup("Partners", {
displayName: "Partners",
email: "partners@example.com",
});

Inactive group

const group = yield* GCP.Apigee.Appgroup("Partners", {
appgroupId: "partners",
status: "inactive",
});

Source: src/GCP/Apigee/AppgroupsApp.ts

An app belonging to an Apigee AppGroup, with auto-generated API keys for the associated API products.

Apps have no labels field. Alchemy stamps ownership into attributes so list / nuke can find them. The app name is immutable.

const app = yield* GCP.Apigee.AppgroupsApp("Mobile", {
appgroup: group.appgroupId,
apiProducts: [product.apiproductId],
callbackUrl: "https://example.com/oauth",
});

Source: src/GCP/Apigee/AppgroupsAppsKey.ts

A custom consumer key and secret for an Apigee AppGroup app.

Apigee keys have no labels field, so Alchemy stamps ownership into custom attributes for list / nuke. The consumer key is identity — changing it replaces the key. Scopes, API products, status, and attributes update in place.

AppgroupsAppsKey: Creating an AppGroup App Key

Section titled “AppgroupsAppsKey: Creating an AppGroup App Key”

Generated key under an AppGroup app

const key = yield* GCP.Apigee.AppgroupsAppsKey("GroupKey", {
appGroup: "partners",
app: "partner-portal",
});

Custom key and secret

const key = yield* GCP.Apigee.AppgroupsAppsKey("GroupKey", {
appGroup: "partners",
app: "partner-portal",
consumerKey: "partner-key",
consumerSecret: "partner-secret",
});

Source: src/GCP/Apigee/Datacollector.ts

An Apigee data collector used to capture custom analytics dimensions.

Apigee collectors have no labels field, so Alchemy stamps ownership into the description for list / nuke. Name and type are identity — changing dataCollectorId or type replaces the collector. Description updates in place.

Generated dc_ name

const collector = yield* GCP.Apigee.Datacollector("Latency", {
type: "INTEGER",
});

Explicit id and description

const collector = yield* GCP.Apigee.Datacollector("Latency", {
dataCollectorId: "dc_proxy_latency",
type: "INTEGER",
description: "proxy latency in milliseconds",
});

Source: src/GCP/Apigee/Developer.ts

An Apigee developer that can register apps and obtain API keys.

Apigee developers have no labels field, so Alchemy stamps ownership into custom attributes for list / nuke. Email is identity — changing email replaces the developer. Name, attributes, and access type update in place.

Generated email

const developer = yield* GCP.Apigee.Developer("Owner", {
firstName: "Ada",
lastName: "Lovelace",
});

Explicit email and attributes

const developer = yield* GCP.Apigee.Developer("Owner", {
email: "ada@example.com",
firstName: "Ada",
lastName: "Lovelace",
userName: "ada",
attributes: { team: "platform" },
});

Source: src/GCP/Apigee/DevelopersApp.ts

An Apigee app owned by a developer, used to obtain API keys.

Apigee developer apps have no labels field, so Alchemy stamps ownership into custom attributes for list / nuke. Name and parent developer are identity — changing appName or developer replaces the app. Callback URL, products, scopes, status, and attributes update in place.

App under an existing developer

const app = yield* GCP.Apigee.DevelopersApp("Portal", {
developer: developer.email,
callbackUrl: "https://example.com/callback",
});

Named app with attributes

const app = yield* GCP.Apigee.DevelopersApp("Portal", {
developer: "ada@example.com",
appName: "portal-app",
attributes: { team: "platform" },
});

Source: src/GCP/Apigee/DevelopersAppsKey.ts

A custom consumer key and secret for an Apigee developer app.

Apigee keys have no labels field, so Alchemy stamps ownership into custom attributes for list / nuke. The consumer key is identity — changing it replaces the key. Scopes, API products, status, and attributes update in place.

DevelopersAppsKey: Creating a Developer App Key

Section titled “DevelopersAppsKey: Creating a Developer App Key”

Generated key under a developer app

const key = yield* GCP.Apigee.DevelopersAppsKey("PortalKey", {
developer: developer.email,
app: app.appName,
});

Custom key and secret

const key = yield* GCP.Apigee.DevelopersAppsKey("PortalKey", {
developer: "ada@example.com",
app: "portal-app",
consumerKey: "portal-key",
consumerSecret: "portal-secret",
status: "approved",
});

Source: src/GCP/Apigee/DnsZone.ts

An Apigee DNS peering zone that lets runtime instances resolve hostnames in a peered VPC.

Apigee DNS zones have no labels field, so Alchemy stamps ownership into the description for list / nuke. Name, domain, and peering config are identity — changing them replaces the zone. Description updates in place only if the API later exposes a patch; today the resource is existence-only besides identity.

const zone = yield* GCP.Apigee.DnsZone("PrivateDns", {
domain: "internal.example.com.",
peeringConfig: {
targetNetworkId: "default",
targetProjectId: "my-project",
},
description: "runtime DNS peering",
});

Source: src/GCP/Apigee/EndpointAttachment.ts

An Apigee endpoint attachment for southbound Private Service Connect.

The API has no labels or description, so Alchemy prefixes generated ids with alc- so list / nuke can find them. All properties are identity — changing any of them replaces the attachment.

EndpointAttachment: Creating an Endpoint Attachment

Section titled “EndpointAttachment: Creating an Endpoint Attachment”
const attachment = yield* GCP.Apigee.EndpointAttachment("Backend", {
location: "us-central1",
serviceAttachment:
"projects/my-project/regions/us-central1/serviceAttachments/backend",
});

Source: src/GCP/Apigee/Envgroup.ts

An Apigee environment group that maps hostnames to one or more environments.

The API has no labels or description, so Alchemy identifies its groups by the generated envgroupId: read reports a group with an explicit envgroupId as unowned (adopt it with --adopt), and nuke cannot discover groups. Name is identity — changing envgroupId replaces the group. Hostnames update in place.

Group with a hostname

const group = yield* GCP.Apigee.Envgroup("Api", {
hostnames: ["api.example.com"],
});

Named group

const group = yield* GCP.Apigee.Envgroup("Api", {
envgroupId: "prod-group",
hostnames: ["api.example.com", "api.example.net"],
});

Source: src/GCP/Apigee/EnvgroupsAttachment.ts

An attachment of an Apigee environment to an environment group.

Existence-only: the identity is the (envgroup, environment) pair. The API has no labels or description, so list / nuke returns attachments whose attached environment carries an Alchemy description marker.

EnvgroupsAttachment: Creating an Environment Group Attachment

Section titled “EnvgroupsAttachment: Creating an Environment Group Attachment”
const attachment = yield* GCP.Apigee.EnvgroupsAttachment("ProdApi", {
envgroup: group.envgroupId,
environment: environment.environmentId,
});

Source: src/GCP/Apigee/Environment.ts

An Apigee environment that hosts API proxies and shared flows.

Apigee environments have no labels field, so Alchemy stamps ownership into the description (and properties) for list / nuke. Name, type, API proxy type, and deployment type are identity — changing them replaces the environment. Display name, description, forward proxy, IP resolution, properties, and node config update in place.

Generated name

const environment = yield* GCP.Apigee.Environment("Runtime", {
displayName: "runtime",
});

Named environment with description

const environment = yield* GCP.Apigee.Environment("Runtime", {
environmentId: "prod",
displayName: "Production",
description: "production API runtime",
apiProxyType: "PROGRAMMABLE",
});

Source: src/GCP/Apigee/EnvironmentsApisRevisionsDebugsession.ts

An Apigee debug session for a deployed API proxy revision.

Sessions are short-lived (max 15s validity) and have no labels. Alchemy generates a stable session id from the stack so list can match it. Delete clears captured data (debugsessions.deleteData); it does not cancel an already-running session.

EnvironmentsApisRevisionsDebugsession: Creating a Debug Session

Section titled “EnvironmentsApisRevisionsDebugsession: Creating a Debug Session”
const session = yield* GCP.Apigee.EnvironmentsApisRevisionsDebugsession("Trace", {
environment: "eval",
api: "hello",
revision: "1",
count: 10,
});

Source: src/GCP/Apigee/EnvironmentsArchiveDeployment.ts

An Apigee archive deployment — a zip of API proxies deployed as a unit to an archive-mode environment.

Labels carry Alchemy ownership so list / nuke can find leaked rows. Name is identity; labels update in place. Creating an archive is a long-running operation.

EnvironmentsArchiveDeployment: Creating an Archive Deployment

Section titled “EnvironmentsArchiveDeployment: Creating an Archive Deployment”
const archive = yield* GCP.Apigee.EnvironmentsArchiveDeployment("Bundle", {
environment: "eval",
archiveZip: zipBase64,
labels: { env: "test" },
});

Source: src/GCP/Apigee/EnvironmentsKeystore.ts

An Apigee environment keystore or truststore for TLS certificates.

Keystores have no labels or description, so list enumerates every keystore in Apigee environments mapped to this GCP project for pnpm nuke:gcp. Name is identity — changing keystoreId, organization, or environment replaces the keystore. Aliases are managed by EnvironmentsKeystoresAlias.

Generated name

const keystore = yield* GCP.Apigee.EnvironmentsKeystore("Tls", {
environment: "eval",
});

Named keystore

const keystore = yield* GCP.Apigee.EnvironmentsKeystore("Tls", {
environment: "eval",
keystoreId: "app-tls",
});

Source: src/GCP/Apigee/EnvironmentsKeystoresAlias.ts

An alias in an Apigee environment keystore — a certificate or key/certificate pair used for TLS.

Aliases have no labels or description, so list enumerates every alias in keystores of Apigee environments mapped to this GCP project. Name, keystore, organization, and environment are identity. Certificate material can be rotated with an in-place update.

EnvironmentsKeystoresAlias: Creating a Self-Signed Alias

Section titled “EnvironmentsKeystoresAlias: Creating a Self-Signed Alias”
const keystore = yield* GCP.Apigee.EnvironmentsKeystore("Tls", {
environment: "eval",
});
const alias = yield* GCP.Apigee.EnvironmentsKeystoresAlias("Server", {
environment: "eval",
keystore: keystore.keystoreId,
subject: { commonName: "api.example.com" },
});

Source: src/GCP/Apigee/EnvironmentsKeyvaluemap.ts

An environment-scoped Apigee key value map.

Maps have no labels or description, so list enumerates every map in Apigee environments mapped to this GCP project. Name is identity. encrypted is create-only (always true on Apigee X); maskedValues updates in place.

Generated name

const map = yield* GCP.Apigee.EnvironmentsKeyvaluemap("Config", {
environment: "eval",
});

Named map with masked values

const map = yield* GCP.Apigee.EnvironmentsKeyvaluemap("Config", {
environment: "eval",
keyvaluemapId: "app-config",
maskedValues: true,
});

Source: src/GCP/Apigee/EnvironmentsKeyvaluemapsEntry.ts

An entry in an environment-scoped Apigee key value map.

Entries have no labels. list walks every map in Apigee environments mapped to this GCP project. Key, map, organization, and environment are identity; value updates in place.

EnvironmentsKeyvaluemapsEntry: Creating an Entry

Section titled “EnvironmentsKeyvaluemapsEntry: Creating an Entry”
const map = yield* GCP.Apigee.EnvironmentsKeyvaluemap("Config", {
environment: "eval",
});
const entry = yield* GCP.Apigee.EnvironmentsKeyvaluemapsEntry("ApiKey", {
environment: "eval",
keyvaluemap: map.keyvaluemapId,
value: "secret",
});

Source: src/GCP/Apigee/EnvironmentsReference.ts

An Apigee environment reference to a keystore or truststore.

References have no labels, so Alchemy stamps ownership into description for list / nuke. Name is identity; refers, resourceType, and description update in place.

EnvironmentsReference: Creating a Reference

Section titled “EnvironmentsReference: Creating a Reference”
const keystore = yield* GCP.Apigee.EnvironmentsKeystore("Tls", {
environment: "eval",
});
const reference = yield* GCP.Apigee.EnvironmentsReference("TlsRef", {
environment: "eval",
refers: keystore.keystoreId,
resourceType: "KeyStore",
});

Source: src/GCP/Apigee/EnvironmentsResourcefile.ts

An environment-scoped Apigee resource file (JavaScript, Java, XSL, …).

Resource files have no labels. list enumerates files in Apigee environments mapped to this GCP project. Type and name are identity; content updates in place.

EnvironmentsResourcefile: Creating a JavaScript File

Section titled “EnvironmentsResourcefile: Creating a JavaScript File”
const file = yield* GCP.Apigee.EnvironmentsResourcefile("Helper", {
environment: "eval",
fileType: "js",
content: "function helper() { return 1; }",
});

Source: src/GCP/Apigee/EnvironmentsSecurityAction.ts

An environment-level Apigee SecurityAction — allow, deny, or flag requests that match a condition.

Security actions have no labels, so Alchemy stamps ownership into description for list / nuke. Name is identity; description, state, conditions, and the allow/deny/flag payload update in place.

EnvironmentsSecurityAction: Creating a Deny Action

Section titled “EnvironmentsSecurityAction: Creating a Deny Action”
const action = yield* GCP.Apigee.EnvironmentsSecurityAction("BlockProbe", {
environment: "eval",
conditionConfig: { ipAddressRanges: ["192.0.2.1"] },
deny: { responseCode: 403 },
});

Source: src/GCP/Apigee/EnvironmentsTargetserver.ts

An Apigee environment TargetServer — a named backend host:port used by proxy TargetEndpoints.

Target servers have no labels, so Alchemy stamps ownership into description for list / nuke. Name and protocol are identity; host, port, enabled flag, description, and TLS settings update in place.

EnvironmentsTargetserver: Creating a Target Server

Section titled “EnvironmentsTargetserver: Creating a Target Server”
const backend = yield* GCP.Apigee.EnvironmentsTargetserver("Api", {
environment: "eval",
host: "backend.example.com",
port: 443,
protocol: "HTTP",
sSLInfo: { enabled: true },
});

Source: src/GCP/Apigee/EnvironmentsTraceConfigOverride.ts

A distributed-trace configuration override for one API proxy in an Apigee environment.

Overrides have no labels; list enumerates every override in Apigee environments mapped to this GCP project. The override id is assigned by Apigee. Organization and environment are identity; apiProxy and samplingConfig update in place.

EnvironmentsTraceConfigOverride: Creating an Override

Section titled “EnvironmentsTraceConfigOverride: Creating an Override”
const override = yield* GCP.Apigee.EnvironmentsTraceConfigOverride("ProxyTrace", {
environment: "eval",
apiProxy: "hello",
samplingConfig: { sampler: "PROBABILITY", samplingRate: 0.1 },
});

Source: src/GCP/Apigee/Instance.ts

An Apigee runtime instance.

Apigee instances have no labels field, so Alchemy stamps ownership into the description for list / nuke. Name, organization, location, peering CIDR, IP range, and CMEK are identity — changing them replaces the instance. Description, display name, consumer accept list, access logging, and maintenance policy update in place.

Provisioning typically takes 20–40 minutes. Live lifecycle tests are skipIf-gated (GCP_TEST_APIGEE_INSTANCE).

Generated name in us-central1

const runtime = yield* GCP.Apigee.Instance("Runtime", {});

Explicit id, description, and access logging

const runtime = yield* GCP.Apigee.Instance("Runtime", {
instanceId: "app-runtime",
location: "us-central1",
description: "production runtime",
accessLoggingConfig: {
enabled: true,
filter: "status_code >= 400",
},
});
const runtime = yield* GCP.Apigee.Instance("Runtime", {
displayName: "app-runtime-prod",
maintenanceUpdatePolicy: {
maintenanceWindows: [{
day: "SUNDAY",
startTime: { hours: 2, minutes: 0 },
}],
},
});

Source: src/GCP/Apigee/InstancesAttachment.ts

An attachment of an Apigee environment onto a runtime instance.

Attachments have no labels or description. list enumerates attachments on alchemy-owned instances so pnpm nuke:gcp can find leaked rows. Organization, instance, and environment are identity — changing them replaces the attachment. There is nothing else to update in place.

InstancesAttachment: Creating an Attachment

Section titled “InstancesAttachment: Creating an Attachment”
const runtime = yield* GCP.Apigee.Instance("Runtime", {});
const attachment = yield* GCP.Apigee.InstancesAttachment("Eval", {
instance: runtime.name,
environment: "eval",
});

Source: src/GCP/Apigee/InstancesNatAddress.ts

A static NAT address on an Apigee runtime instance.

NAT addresses have no labels or description. list enumerates addresses on alchemy-owned instances so pnpm nuke:gcp can find leaked rows. Organization, instance, and name are identity — changing them replaces the address. activate updates in place (RESERVED → ACTIVE) and cannot be reversed.

InstancesNatAddress: Creating a NAT Address

Section titled “InstancesNatAddress: Creating a NAT Address”

Reserve a NAT address on a runtime instance

const runtime = yield* GCP.Apigee.Instance("Runtime", {});
const nat = yield* GCP.Apigee.InstancesNatAddress("Egress", {
instance: runtime.name,
});

Reserve and activate

const nat = yield* GCP.Apigee.InstancesNatAddress("Egress", {
instance: runtime.name,
natAddressId: "app-egress",
activate: true,
});

Source: src/GCP/Apigee/Keyvaluemap.ts

An organization-scoped Apigee key value map.

Org-level KVMs have no labels, description, or list API. Alchemy stamps ownership into a reserved __alchemy entry so read can detect foreign maps, and list walks maps referenced by that entry when the parent is known from state. mapId and organization are identity — changing them replaces the map. maskedValues updates in place. Entries are always encrypted on Apigee X.

Generated name

const kv = yield* GCP.Apigee.Keyvaluemap("Config", {});

Named map with masked values

const kv = yield* GCP.Apigee.Keyvaluemap("Config", {
mapId: "app-config",
maskedValues: true,
});

Source: src/GCP/Apigee/KeyvaluemapsEntry.ts

An organization-scoped Apigee key value map entry.

Entries have no labels field and the value is read by proxies, so Alchemy stores it verbatim and identifies its entries by the generated key: read reports an entry with an explicit entryId as unowned (adopt it with --adopt). Organization, map, and key are identity — changing them replaces the entry. value updates in place.

Generated key on a map

const kv = yield* GCP.Apigee.Keyvaluemap("Config", {});
const entry = yield* GCP.Apigee.KeyvaluemapsEntry("ApiKey", {
map: kv.name,
value: "secret-value",
});

Explicit key

const entry = yield* GCP.Apigee.KeyvaluemapsEntry("ApiKey", {
map: kv.name,
entryId: "api-key",
value: "secret-value",
});

Source: src/GCP/Apigee/Organization.ts

An Apigee X organization, 1:1 with a Google Cloud project.

Organizations have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Creating an organization is slow and entitlement-gated; live tests skip unless GCP_TEST_APIGEE=1.

Changing organizationId, analyticsRegion, runtimeType, billingType, or CMEK keys replaces the organization.

Evaluation org in us-central1

const org = yield* GCP.Apigee.Organization("Org", {
analyticsRegion: "us-central1",
runtimeType: "CLOUD",
billingType: "EVALUATION",
disableVpcPeering: true,
});

Description and add-ons

const org = yield* GCP.Apigee.Organization("Org", {
description: "api platform",
addonsConfig: { monetizationConfig: { enabled: true } },
});

Source: src/GCP/Apigee/Report.ts

An Apigee custom analytics report.

Custom reports have no labels field, so Alchemy stamps ownership into a leading comments entry ([alchemy …]) for list / nuke. Name and organization are identity — changing them replaces the report. Metrics, dimensions, filter, chart type, and comments update in place.

Generated name, message count by proxy

const report = yield* GCP.Apigee.Report("Traffic", {
metrics: [{ name: "message_count", function: "sum" }],
dimensions: ["apiproxy"],
});

Named report with a filter

const report = yield* GCP.Apigee.Report("Errors", {
reportId: "app-errors",
displayName: "application errors",
metrics: [{ name: "error_count", function: "sum" }],
dimensions: ["apiproxy"],
filter: "response_status_code ge 400",
});

Source: src/GCP/Apigee/SecurityFeedback.ts

An Advanced API Security customer feedback report.

Feedback reports have no labels field, so Alchemy stamps ownership into the comment for list / nuke. Name and organization are identity — changing them replaces the report. Display name, type, reason, contexts, and comment update in place.

const feedback = yield* GCP.Apigee.SecurityFeedback("PenTest", {
reason: "PENETRATION_TEST",
feedbackContexts: [{
attribute: "ATTRIBUTE_ENVIRONMENTS",
values: ["eval"],
}],
});

Source: src/GCP/Apigee/SecurityMonitoringCondition.ts

An Advanced API Security monitoring condition (risk assessment v2).

Conditions have no labels or description. Generated ids are prefixed alc- so list / nuke can distinguish Alchemy rows from Google-defined conditions. Organization and id are identity — changing them replaces the condition. Profile, scope, include, and include-all update in place.

SecurityMonitoringCondition: Creating a Condition

Section titled “SecurityMonitoringCondition: Creating a Condition”
const profile = yield* GCP.Apigee.SecurityProfilesV2("Default", {});
const condition = yield* GCP.Apigee.SecurityMonitoringCondition("Eval", {
profile: profile.name,
scope: "eval",
includeAllResources: true,
});

Source: src/GCP/Apigee/SecurityProfile.ts

An Advanced API Security profile (v1).

Profiles have no labels field, so Alchemy stamps ownership into the description for list / nuke. Name and organization are identity — changing them replaces the profile. Description and profile config update in place (each update creates a new revision).

Generated name with authorization and threat categories

const profile = yield* GCP.Apigee.SecurityProfile("Baseline", {
profileConfig: {
categories: [{ authorization: true, threat: true }],
},
});

Named profile

const profile = yield* GCP.Apigee.SecurityProfile("Baseline", {
securityProfileId: "app-baseline",
description: "default scoring",
profileConfig: {
categories: [{ authorization: true, cors: true, threat: true }],
},
});

Source: src/GCP/Apigee/SecurityProfilesV2.ts

An Advanced API Security profile (risk assessment v2).

Profiles have no labels field, so Alchemy stamps ownership into the description for list / nuke. Google-defined profiles are ignored by list. Name and organization are identity — changing them replaces the profile. Description and assessment configs update in place.

Generated name with default assessments

const profile = yield* GCP.Apigee.SecurityProfilesV2("Baseline", {});

Named profile with explicit weights

const profile = yield* GCP.Apigee.SecurityProfilesV2("Baseline", {
securityProfileV2Id: "app-baseline",
description: "production scoring",
profileAssessmentConfigs: {
authorization: { weight: "MAJOR" },
threat: { weight: "MODERATE" },
cors: { weight: "MINOR" },
},
});

Source: src/GCP/Apigee/Sharedflow.ts

An Apigee shared flow — a reusable sequence of policies that API proxies (or other shared flows) invoke with a FlowCallout.

Shared flows have no labels field, so Alchemy stamps ownership into the bundle Description for list / nuke. sharedflowId and organization are identity — changing either replaces the shared flow. Uploading a bundle or changing description creates a new revision. space is moved in place.

Generated empty bundle

const flow = yield* GCP.Apigee.Sharedflow("Traffic", {
description: "rate limit and spike arrest",
});

Explicit id and space

const flow = yield* GCP.Apigee.Sharedflow("Traffic", {
sharedflowId: "traffic-management",
space: team.spaceId,
description: "rate limit and spike arrest",
});
const flow = yield* GCP.Apigee.Sharedflow("Traffic", {
description: "rate limit only",
});

Source: src/GCP/Apigee/SitesApicategory.ts

An API category on an Apigee integrated portal. Catalog items can be tagged with categories so portal users can browse by topic.

API categories have no labels field and the name is shown to portal users, so Alchemy finds its category by name: read reports a category as owned only when it carries the generated name (an explicit name is reported as unowned — adopt it with --adopt), and nuke cannot discover categories. siteId and organization are identity — changing either replaces the category. The display name updates in place.

SitesApicategory: Creating an API Category

Section titled “SitesApicategory: Creating an API Category”
const category = yield* GCP.Apigee.SitesApicategory("Payments", {
siteId: portal.siteId,
name: "Payments",
});

SitesApicategory: Updating an API Category

Section titled “SitesApicategory: Updating an API Category”
const category = yield* GCP.Apigee.SitesApicategory("Payments", {
siteId: portal.siteId,
name: "Billing",
});

Source: src/GCP/Apigee/SitesApidoc.ts

An Apigee integrated-portal catalog item (apidoc). Catalog items present API documentation and link a portal to a backing API product.

API docs have no labels field and every text field is shown to portal users, so Alchemy finds its item by API product: read reports an item as owned only when it carries the generated title (an explicit title is reported as unowned — adopt it with --adopt), and nuke cannot discover items. siteId, organization, and apiProductName are identity — changing any of them replaces the item. Title, description, publish flags, image, and categories update in place.

const doc = yield* GCP.Apigee.SitesApidoc("Checkout", {
siteId: portal.siteId,
apiProductName: product.name,
title: "Checkout API",
description: "place orders",
});
const doc = yield* GCP.Apigee.SitesApidoc("Checkout", {
siteId: portal.siteId,
apiProductName: product.name,
title: "Checkout API",
description: "place orders",
published: true,
categoryIds: [payments.categoryId],
});

Source: src/GCP/Apigee/Space.ts

An Apigee organization space used to group API proxies, shared flows, and products for IAM.

Spaces have no labels field, so Alchemy stamps ownership into displayName for list / nuke. spaceId and organization are identity — changing either replaces the space. displayName updates in place.

Generated id

const space = yield* GCP.Apigee.Space("Payments", {
displayName: "payments team",
});

Explicit id

const space = yield* GCP.Apigee.Space("Payments", {
spaceId: "payments",
displayName: "payments team",
});
const space = yield* GCP.Apigee.Space("Payments", {
displayName: "payments and billing",
});