Skip to content

GCP.BigQueryDataPolicy reference

Source: src/GCP/BigQueryDataPolicy/DataPolicy.ts

A BigQuery Data Policy (v2) — raw-data access or column data masking.

Data policies have no labels, so Alchemy stamps ownership into the policy id (alch___…) so list / pnpm nuke:gcp can find them. dataPolicyId and location are identity — changing either replaces the policy. Type, masking rule, grantees, and the data-governance tag update in place. Patches send the observed etag.

Raw-data access

const policy = yield* GCP.BigQueryDataPolicy.DataPolicy("Raw", {
dataPolicyType: "RAW_DATA_ACCESS_POLICY",
});

SHA256 masking

const policy = yield* GCP.BigQueryDataPolicy.DataPolicy("Mask", {
location: "us-central1",
dataPolicyType: "DATA_MASKING_POLICY",
dataMaskingPolicy: { predefinedExpression: "SHA256" },
});

Change props on the same logical id; the engine keeps the physical id.

const policy = yield* GCP.BigQueryDataPolicy.DataPolicy("Mask", {
location: "us-central1",
dataPolicyType: "DATA_MASKING_POLICY",
dataMaskingPolicy: { predefinedExpression: "ALWAYS_NULL" },
});