GCP.CloudAsset reference
Source:
src/GCP/CloudAsset/Feed.ts
A Cloud Asset Inventory feed that publishes asset updates to Pub/Sub.
Feeds have no labels field — Alchemy stamps ownership into
condition.description so list / nuke can find them. Feed id and
parent are identity. Asset filters, content type, destination topic,
and condition update in place.
Feed: Creating a Feed
Section titled “Feed: Creating a Feed”Watch storage buckets
const topic = yield* GCP.PubSub.Topic("AssetEvents", {});const feed = yield* GCP.CloudAsset.Feed("Buckets", { pubsubTopic: topic.name, assetTypes: ["storage.googleapis.com/Bucket"], contentType: "RESOURCE",});Named feed with a deletion filter
const feed = yield* GCP.CloudAsset.Feed("Buckets", { feedId: "bucket-deletes", pubsubTopic: topic.name, assetTypes: ["storage.googleapis.com/Bucket"], contentType: "RESOURCE", condition: { expression: "temporal_asset.deleted == true", title: "deletes", description: "publish deletions only", },});Feed: Updating a Feed
Section titled “Feed: Updating a Feed”// Same logical id, changed props: the feed is patched in place.const feed = yield* GCP.CloudAsset.Feed("Buckets", { pubsubTopic: topic.name, assetTypes: [ "storage.googleapis.com/Bucket", "pubsub.googleapis.com/Topic", ], contentType: "RESOURCE",});SavedQuery
Section titled “SavedQuery”Source:
src/GCP/CloudAsset/SavedQuery.ts
A Cloud Asset Inventory saved query, typically an IAM policy analysis that can be rerun later.
Saved query id and parent are identity. Description, labels, and
content update in place. Alchemy ownership is stored in labels so
list / nuke can find the query.
SavedQuery: Creating a Saved Query
Section titled “SavedQuery: Creating a Saved Query”Analyze IAM in the current project
const query = yield* GCP.CloudAsset.SavedQuery("IamAudit", { description: "who can act as service accounts", content: { iamPolicyAnalysisQuery: { scope: `projects/${project}`, accessSelector: { permissions: ["iam.serviceAccounts.actAs"], }, }, },});Generated id with labels
const query = yield* GCP.CloudAsset.SavedQuery("IamAudit", { labels: { env: "dev" },});SavedQuery: Updating a Saved Query
Section titled “SavedQuery: Updating a Saved Query”// Same logical id, changed props: the query is patched in place.const query = yield* GCP.CloudAsset.SavedQuery("IamAudit", { description: "roles and permissions", labels: { env: "prod" }, content: { iamPolicyAnalysisQuery: { scope: `projects/${project}`, accessSelector: { roles: ["roles/owner"], }, }, },});