Skip to content

GCP.BeyondCorp reference

Source: src/GCP/BeyondCorp/AppConnection.ts

A BeyondCorp AppConnection that links a remote application endpoint to an AppGateway and optional AppConnectors.

Changing appConnectionId, location, type, or gateway.appGateway replaces the connection. Display name, labels, application endpoint, and connectors update in place.

TCP proxy through an AppGateway

const connection = yield* GCP.BeyondCorp.AppConnection("App", {
applicationEndpoint: { host: "10.0.0.4", port: 8080 },
gateway: { appGateway: gateway.name },
connectors: [connector.name],
});

Explicit id and labels

const connection = yield* GCP.BeyondCorp.AppConnection("App", {
appConnectionId: "app-tcp",
type: "TCP_PROXY",
applicationEndpoint: { host: "app.internal", port: 443 },
gateway: { appGateway: gateway.name },
displayName: "prod app",
labels: { env: "prod" },
});

Source: src/GCP/BeyondCorp/AppConnector.ts

A BeyondCorp AppConnector that represents the application-facing component used to reach remote endpoints.

Changing appConnectorId, location, or the service account email replaces the connector. Display name and labels update in place.

Generated name

const connector = yield* GCP.BeyondCorp.AppConnector("Agent", {
principalInfo: {
serviceAccount: { email: "connector@my-project.iam.gserviceaccount.com" },
},
});

Explicit id and labels

const connector = yield* GCP.BeyondCorp.AppConnector("Agent", {
appConnectorId: "app-agent",
serviceAccountEmail: "connector@my-project.iam.gserviceaccount.com",
displayName: "prod connector",
labels: { env: "prod" },
});

Source: src/GCP/BeyondCorp/AppGateway.ts

A BeyondCorp AppGateway that provisions the GCP components used to reach a remote application.

Changing appGatewayId, location, type, or hostType replaces the gateway. The API has no patch method — display name and labels are applied at create only.

Generated name

const gateway = yield* GCP.BeyondCorp.AppGateway("Edge", {});

Explicit id, type, and labels

const gateway = yield* GCP.BeyondCorp.AppGateway("Edge", {
appGatewayId: "app-edge",
location: "us-central1",
type: "TCP_PROXY",
hostType: "GCP_REGIONAL_MIG",
displayName: "edge gateway",
labels: { env: "prod" },
});

Source: src/GCP/BeyondCorp/SecurityGateway.ts

A BeyondCorp Security Gateway that fronts Chrome Enterprise Premium applications.

The API has no labels field, so Alchemy stamps ownership into displayName for list / nuke. Changing securityGatewayId or location replaces the gateway. Display name and hubs update in place.

SecurityGateway: Creating a SecurityGateway

Section titled “SecurityGateway: Creating a SecurityGateway”

Generated name with a us-central1 hub

const gateway = yield* GCP.BeyondCorp.SecurityGateway("Pep", {});

Explicit id and display name

const gateway = yield* GCP.BeyondCorp.SecurityGateway("Pep", {
securityGatewayId: "app-pep",
displayName: "prod gateway",
hubs: {
"us-central1": { internetGateway: {} },
},
});

Source: src/GCP/BeyondCorp/SecurityGatewaysApplication.ts

A BeyondCorp Security Gateway application that matches host and port combinations and forwards traffic to upstreams.

The API has no labels field, so Alchemy stamps ownership into displayName for list / nuke. Changing the parent gateway, application id, or location replaces the application. Display name, endpoint matchers, schema, and upstreams update in place.

SecurityGatewaysApplication: Creating a SecurityGatewaysApplication

Section titled “SecurityGatewaysApplication: Creating a SecurityGatewaysApplication”

Match HTTPS for a hostname

const app = yield* GCP.BeyondCorp.SecurityGatewaysApplication("Web", {
securityGateway: gateway.name,
endpointMatchers: [{ hostname: "app.example.com", ports: [443] }],
});

External upstreams

const app = yield* GCP.BeyondCorp.SecurityGatewaysApplication("Web", {
securityGateway: gateway.name,
applicationId: "app-web",
displayName: "prod web",
endpointMatchers: [{ hostname: "app.example.com", ports: [80, 443] }],
upstreams: [
{
external: {
endpoints: [{ hostname: "origin.example.com", port: 443 }],
},
},
],
});