Skip to content

GCP.AssuredWorkloads reference

Source: src/GCP/AssuredWorkloads/Workload.ts

An organization-scoped Assured Workloads folder that applies a compliance regime (FedRAMP, IL4, regional data boundary, …) to the projects created under it.

Workload ids are assigned by Google. Alchemy stamps ownership into labels so list / pnpm nuke:gcp can find them. organization, location, complianceRegime, billing accounts, partner settings, and resource settings are identity — changing them replaces the workload. displayName, labels, violationNotificationsEnabled, and partnerPermissions update in place.

Creating a workload provisions a folder (and optionally projects and key rings) under the organization. Delete first marks those children DELETE_REQUESTED, then deletes the workload.

US regional access with generated display name

const workload = yield* GCP.AssuredWorkloads.Workload("Regulated", {
complianceRegime: "US_REGIONAL_ACCESS",
billingAccount: "billingAccounts/000000-000000-000000",
labels: { env: "test" },
});

Named FedRAMP Moderate workload

const workload = yield* GCP.AssuredWorkloads.Workload("Fedramp", {
organization: "organizations/123456789",
location: "us-central1",
displayName: "fedramp moderate",
complianceRegime: "FEDRAMP_MODERATE",
billingAccount: "billingAccounts/000000-000000-000000",
});
const workload = yield* GCP.AssuredWorkloads.Workload("Regulated", {
complianceRegime: "US_REGIONAL_ACCESS",
displayName: "regulated prod",
labels: { env: "prod" },
violationNotificationsEnabled: false,
});