Skip to content

GCP.AppEngine reference

Source: src/GCP/AppEngine/ApplicationsAuthorizedCertificate.ts

An SSL certificate uploaded to an App Engine application via the projects.locations.applications.authorizedCertificates API.

App Engine certificates have no labels field, so Alchemy stamps ownership into displayName for list / nuke. Project, location, application id, and server-assigned certificate id are identity. Display name and PEM data update in place.

ApplicationsAuthorizedCertificate: Creating a Certificate

Section titled “ApplicationsAuthorizedCertificate: Creating a Certificate”
const cert = yield* GCP.AppEngine.ApplicationsAuthorizedCertificate(
"FrontendTls",
{
displayName: "frontend",
publicCertificate,
privateKey,
},
);

ApplicationsAuthorizedCertificate: Updating a Certificate

Section titled “ApplicationsAuthorizedCertificate: Updating a Certificate”
const cert = yield* GCP.AppEngine.ApplicationsAuthorizedCertificate(
"FrontendTls",
{
displayName: "frontend-prod",
publicCertificate,
privateKey,
},
);

Source: src/GCP/AppEngine/ApplicationsDomainMapping.ts

A custom domain serving an App Engine application via the projects.locations.applications.domainMappings API.

Domain mappings have no labels field. list / nuke discover owned mappings by joining sslSettings.certificateId to an Alchemy-owned AuthorizedCertificate, or a domain that starts with alchemy-. Project, location, application id, and domain are identity. SSL settings update in place.

ApplicationsDomainMapping: Creating a Domain Mapping

Section titled “ApplicationsDomainMapping: Creating a Domain Mapping”
const mapping = yield* GCP.AppEngine.ApplicationsDomainMapping("Www", {
domain: "www.example.com",
sslSettings: { sslManagementType: "AUTOMATIC" },
});
const mapping = yield* GCP.AppEngine.ApplicationsDomainMapping("Www", {
sslSettings: {
sslManagementType: "MANUAL",
certificateId: cert.certificateId,
},
});

Source: src/GCP/AppEngine/AppsAuthorizedCertificate.ts

An SSL certificate uploaded to an App Engine application.

App Engine certificates have no labels field, so Alchemy stamps ownership into displayName for list / nuke. The application id and server-assigned certificate id are identity — changing either replaces the certificate. Display name and PEM data update in place.

AppsAuthorizedCertificate: Creating a Certificate

Section titled “AppsAuthorizedCertificate: Creating a Certificate”

Upload a self-managed certificate

const cert = yield* GCP.AppEngine.AppsAuthorizedCertificate("FrontendTls", {
displayName: "frontend",
publicCertificate,
privateKey,
});

Nested raw-data payload

const cert = yield* GCP.AppEngine.AppsAuthorizedCertificate("FrontendTls", {
certificateRawData: {
publicCertificate,
privateKey,
},
});

AppsAuthorizedCertificate: Updating a Certificate

Section titled “AppsAuthorizedCertificate: Updating a Certificate”
const cert = yield* GCP.AppEngine.AppsAuthorizedCertificate("FrontendTls", {
displayName: "frontend-prod",
publicCertificate,
privateKey,
});

Source: src/GCP/AppEngine/AppsDomainMapping.ts

A custom domain serving an App Engine application.

Domain mappings have no labels field. list / nuke discover owned mappings by joining sslSettings.certificateId to an Alchemy-owned AuthorizedCertificate, or a domain that starts with alchemy-. The application id and domain are identity — changing either replaces the mapping. SSL settings update in place.

AppsDomainMapping: Creating a Domain Mapping

Section titled “AppsDomainMapping: Creating a Domain Mapping”

Automatic managed SSL

const mapping = yield* GCP.AppEngine.AppsDomainMapping("Www", {
domain: "www.example.com",
sslSettings: { sslManagementType: "AUTOMATIC" },
});

Manual certificate

const mapping = yield* GCP.AppEngine.AppsDomainMapping("Www", {
domain: "www.example.com",
sslSettings: {
sslManagementType: "MANUAL",
certificateId: cert.certificateId,
},
});
const mapping = yield* GCP.AppEngine.AppsDomainMapping("Www", {
sslSettings: {
sslManagementType: "MANUAL",
certificateId: cert.certificateId,
},
});

Source: src/GCP/AppEngine/AppsFirewallIngressRule.ts

An App Engine ingress firewall rule.

Firewall rules have no labels field, so Alchemy stamps ownership into description for list / nuke. Application id and priority are identity — changing either replaces the rule. Action, source range, and description update in place.

Deny a CIDR range

const rule = yield* GCP.AppEngine.AppsFirewallIngressRule("BlockOffice", {
action: "DENY",
sourceRange: "203.0.113.0/24",
description: "office network",
});

Explicit priority

const rule = yield* GCP.AppEngine.AppsFirewallIngressRule("AllowHealth", {
priority: 12000,
action: "ALLOW",
sourceRange: "35.191.0.0/16",
});
const rule = yield* GCP.AppEngine.AppsFirewallIngressRule("BlockOffice", {
action: "ALLOW",
sourceRange: "203.0.113.0/24",
});

Source: src/GCP/AppEngine/AppsServicesVersion.ts

An App Engine service version.

App Engine versions have no labels field, so Alchemy stamps ownership into the ALCHEMY_OWNERSHIP environment variable for list / nuke. Application, service, version id, runtime, environment, and deployment are identity — changing any of them replaces the version. Serving status, instance class, and scaling update in place.

Python 3 standard environment

const version = yield* GCP.AppEngine.AppsServicesVersion("Api", {
runtime: "python311",
deployment: {
zip: { sourceUrl: "https://storage.googleapis.com/bucket/app.zip" },
},
});

Named version with automatic scaling

const version = yield* GCP.AppEngine.AppsServicesVersion("Api", {
versionId: "v1",
serviceId: "default",
runtime: "nodejs20",
automaticScaling: {
standardSchedulerSettings: { minInstances: 0, maxInstances: 1 },
},
deployment: {
zip: { sourceUrl: "https://storage.googleapis.com/bucket/app.zip" },
},
});
const version = yield* GCP.AppEngine.AppsServicesVersion("Api", {
servingStatus: "STOPPED",
deployment: {
zip: { sourceUrl: "https://storage.googleapis.com/bucket/app.zip" },
},
});