GCP.Compute reference
Address
Section titled “Address”Source:
src/GCP/Compute/Address.ts
A regional Compute Engine static IP address.
Reserves a regional internal or external IP. Labels are the only
in-place update (addresses.setLabels); name, region, IP, type,
version, purpose, network, subnetwork, prefix length, and description
replace the address.
Address: Creating an Address
Section titled “Address: Creating an Address”Generated name
const ip = yield* GCP.Compute.Address("Ingress", {});Named address with labels
const ip = yield* GCP.Compute.Address("Ingress", { addressName: "app-ingress", region: "us-central1", addressType: "EXTERNAL", networkTier: "PREMIUM", labels: { env: "prod" },});Address: Internal Addresses
Section titled “Address: Internal Addresses”const ip = yield* GCP.Compute.Address("ServiceIp", { region: "us-central1", addressType: "INTERNAL", subnetwork: "projects/my-project/regions/us-central1/subnetworks/default", purpose: "GCE_ENDPOINT",});Autoscaler
Section titled “Autoscaler”Source:
src/GCP/Compute/Autoscaler.ts
A zonal Compute Engine autoscaler for a managed instance group.
Changing autoscalerName or zone replaces the autoscaler. Policy,
target, description, and labels update in place via autoscalers.patch.
Compute Engine has no labels on this resource, so Alchemy stamps
ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find
them.
Autoscaler: Creating an Autoscaler
Section titled “Autoscaler: Creating an Autoscaler”CPU policy with generated name
const scaler = yield* GCP.Compute.Autoscaler("Web", { target: mig.selfLink, autoscalingPolicy: { minNumReplicas: 1, maxNumReplicas: 5, coolDownPeriodSec: 60, cpuUtilization: { utilizationTarget: 0.6 }, },});Named autoscaler, labels, and OFF mode
const scaler = yield* GCP.Compute.Autoscaler("Web", { autoscalerName: "web-scaler", zone: "us-central1-a", target: "web-mig", description: "scale the web MIG", labels: { env: "prod" }, autoscalingPolicy: { minNumReplicas: 0, maxNumReplicas: 3, mode: "OFF", cpuUtilization: { utilizationTarget: 0.5 }, },});BackendBucket
Section titled “BackendBucket”Source:
src/GCP/Compute/BackendBucket.ts
A global Compute Engine backend bucket that fronts a Cloud Storage bucket for HTTP(S) load balancing.
Compute Engine backend buckets have no labels field, so Alchemy
stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find
them.
BackendBucket: Creating a Backend Bucket
Section titled “BackendBucket: Creating a Backend Bucket”Generated name in front of a Storage bucket
const assets = yield* GCP.Storage.Bucket("assets", { forceDestroy: true,});const backend = yield* GCP.Compute.BackendBucket("cdn", { bucketName: assets.bucketName, description: "static assets",});Explicit name with Cloud CDN
const backend = yield* GCP.Compute.BackendBucket("cdn", { name: "app-static", bucketName: assets.bucketName, enableCdn: true, compressionMode: "AUTOMATIC", customResponseHeaders: ["X-Frame-Options: DENY"],});BackendService
Section titled “BackendService”Source:
src/GCP/Compute/BackendService.ts
A global Compute Engine backend service. Backend services define how Google Cloud load balancers distribute traffic — protocol, timeout, session affinity, health checks, and the backends themselves.
Compute Engine backend services have no labels field, so Alchemy stamps
ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.
BackendService: Creating a Backend Service
Section titled “BackendService: Creating a Backend Service”Generated name
const backend = yield* GCP.Compute.BackendService("web", { protocol: "HTTP",});Explicit name, timeout, and labels
const backend = yield* GCP.Compute.BackendService("web", { name: "web-backend", protocol: "HTTP", loadBalancingScheme: "EXTERNAL", timeoutSec: 30, enableCDN: true, labels: { env: "prod" },});BackendService: Updating a Backend Service
Section titled “BackendService: Updating a Backend Service”const backend = yield* GCP.Compute.BackendService("web", { name: "web-backend", timeoutSec: 60, enableCDN: true,});CrossSiteNetwork
Section titled “CrossSiteNetwork”Source:
src/GCP/Compute/CrossSiteNetwork.ts
A global Compute Engine cross-site network.
Cross-site networks group Wire Groups that connect on-premises and cloud sites through Cross-Cloud Interconnect. The resource itself is a named container — Wire Groups attach later. Compute has no labels field, so Alchemy stamps ownership into the description.
CrossSiteNetwork: Creating a Cross-Site Network
Section titled “CrossSiteNetwork: Creating a Cross-Site Network”Generated name
const network = yield* GCP.Compute.CrossSiteNetwork("backbone", {});Named network with a description
const network = yield* GCP.Compute.CrossSiteNetwork("backbone", { crossSiteNetworkName: "prod-backbone", description: "cross-cloud interconnect fabric",});Source:
src/GCP/Compute/Disk.ts
A zonal Compute Engine persistent disk.
Changing zone, type, diskName, sourceImage, sourceSnapshot,
sourceDisk, architecture, physicalBlockSizeBytes, or
enableConfidentialCompute replaces the disk. Growing sizeGb is
applied in place via disks.resize; shrinking it replaces the disk.
Disk: Creating a Disk
Section titled “Disk: Creating a Disk”Generated name
const disk = yield* GCP.Compute.Disk("data", {});Explicit name, type, size, and labels
const disk = yield* GCP.Compute.Disk("data", { diskName: "app-data", zone: "us-central1-a", type: "pd-balanced", sizeGb: 20, labels: { env: "prod" },});Disk: Resizing a Disk
Section titled “Disk: Resizing a Disk”const disk = yield* GCP.Compute.Disk("data", { diskName: "app-data", sizeGb: 50,});ExternalVpnGateway
Section titled “ExternalVpnGateway”Source:
src/GCP/Compute/ExternalVpnGateway.ts
A global Compute Engine external VPN gateway — the on-premises or other-cloud peer that an HA VPN gateway connects to.
Labels are the only in-place update (externalVpnGateways.setLabels).
Name, description, redundancy type, and interfaces replace the
gateway.
ExternalVpnGateway: Creating an ExternalVpnGateway
Section titled “ExternalVpnGateway: Creating an ExternalVpnGateway”Generated name with two peer IPs
const peer = yield* GCP.Compute.ExternalVpnGateway("Peer", { redundancyType: "TWO_IPS_REDUNDANCY", interfaces: [ { id: 0, ipAddress: "203.0.113.1" }, { id: 1, ipAddress: "203.0.113.2" }, ],});Named gateway with labels
const peer = yield* GCP.Compute.ExternalVpnGateway("Peer", { externalVpnGatewayName: "onprem-vpn", description: "on-prem peer", redundancyType: "SINGLE_IP_INTERNALLY_REDUNDANT", interfaces: [{ id: 0, ipAddress: "203.0.113.10" }], labels: { env: "prod" },});Firewall
Section titled “Firewall”Source:
src/GCP/Compute/Firewall.ts
A VPC firewall rule that allows or denies ingress/egress traffic for instances on a network.
Compute Engine firewalls have no resource labels. Alchemy stamps
ownership (alchemy-stack / alchemy-stage / alchemy-id) into the
description so read and list (and pnpm nuke:gcp) can find them.
Name, network, direction, and allow-vs-deny are immutable — changing any of them replaces the rule.
Firewall: Creating a Firewall
Section titled “Firewall: Creating a Firewall”Generated name, HTTP from a private range
const http = yield* GCP.Compute.Firewall("AllowHttp", { allowed: [{ protocol: "tcp", ports: ["80"] }], sourceRanges: ["10.0.0.0/8"], targetTags: ["web"],});Explicit name, HTTPS deny, logging
const deny = yield* GCP.Compute.Firewall("DenyHttps", { firewallName: "deny-https-egress", direction: "EGRESS", denied: [{ protocol: "tcp", ports: ["443"] }], destinationRanges: ["0.0.0.0/0"], priority: 800, logConfig: { enable: true, metadata: "INCLUDE_ALL_METADATA" },});FirewallPolicy
Section titled “FirewallPolicy”Source:
src/GCP/Compute/FirewallPolicy.ts
A hierarchical firewall policy attached to an organization or folder.
Policies live under locations/global/firewallPolicies and are
identified by a server-assigned numeric id. The user-facing name is
shortName. Parent and shortName are immutable — changing either
replaces the policy. Description updates in place via
firewallPolicies.patch. Rules are synced with addRule /
patchRule / removeRule.
Compute Engine firewall policies have no resource labels. Alchemy
stamps ownership into the description so read / list (and
pnpm nuke:gcp) can find them.
FirewallPolicy: Creating a Firewall Policy
Section titled “FirewallPolicy: Creating a Firewall Policy”Generated name with an allow rule
const policy = yield* GCP.Compute.FirewallPolicy("OrgFw", { description: "allow internal http", rules: [ { action: "allow", priority: 1000, direction: "INGRESS", match: { srcIpRanges: ["10.0.0.0/8"], layer4Configs: [{ ipProtocol: "tcp", ports: ["80"] }], }, }, ],});Named policy under a folder
const policy = yield* GCP.Compute.FirewallPolicy("OrgFw", { shortName: "app-org-fw", parent: "folders/123456789", description: "folder guardrail",});ForwardingRule
Section titled “ForwardingRule”Source:
src/GCP/Compute/ForwardingRule.ts
A regional Compute Engine forwarding rule.
Forwarding rules are the frontend of a Google Cloud load balancer: an
IP address, protocol, and port that send traffic to a target (pool,
instance, HTTP(S)/TCP proxy, VPN gateway) or a backend service. This
resource maps to the regional forwardingRules collection
(globalForwardingRules is a separate resource).
Labels cannot be set on insert — Alchemy applies them with setLabels
after the rule exists. target, allowGlobalAccess, and
allowPscGlobalAccess update in place; name, region, IP, protocol,
ports, scheme, network, subnetwork, backend service, and description
replace the rule.
ForwardingRule: Creating a Forwarding Rule
Section titled “ForwardingRule: Creating a Forwarding Rule”Classic Network Load Balancer frontend
const rule = yield* GCP.Compute.ForwardingRule("Frontend", { region: "us-central1", target: targetPool.selfLink, portRange: "80",});Named rule with labels
const rule = yield* GCP.Compute.ForwardingRule("Frontend", { forwardingRuleName: "app-frontend", region: "us-central1", ipProtocol: "TCP", portRange: "80-80", target: targetPool.selfLink, labels: { env: "prod" },});ForwardingRule: Internal Load Balancing
Section titled “ForwardingRule: Internal Load Balancing”const rule = yield* GCP.Compute.ForwardingRule("Ilb", { region: "us-central1", loadBalancingScheme: "INTERNAL", backendService: backend.selfLink, network: vpc.selfLink, subnetwork: subnet.selfLink, ipProtocol: "TCP", ports: ["80"], allowGlobalAccess: true,});FutureReservation
Section titled “FutureReservation”Source:
src/GCP/Compute/FutureReservation.ts
A zonal Compute Engine future reservation.
Future reservations lock capacity for a later delivery window. Name and
zone replace the resource; description, planning status, and the time
window update in place via futureReservations.patch. Compute has no
labels field, so Alchemy stamps ownership into the description.
Creating a reservation typically requires quota and, for CALENDAR
mode, GPU/TPU SKUs. Draft reservations (planningStatus: "DRAFT") stay
off the procurement queue.
FutureReservation: Creating a Future Reservation
Section titled “FutureReservation: Creating a Future Reservation”const reservation = yield* GCP.Compute.FutureReservation("burst", { planningStatus: "DRAFT", timeWindow: { startTime: "2030-06-01T00:00:00Z", endTime: "2030-06-08T00:00:00Z", }, specificSkuProperties: { totalCount: "1", instanceProperties: { machineType: "n2-standard-2" }, },});GetInstance
Section titled “GetInstance”Source:
src/GCP/Compute/GetInstance.ts
Runtime binding for Compute Engine instances.get.
Bind this operation to an Instance in a Function/Action init phase.
Provide GetInstanceHttp.
GetInstance: Observing Instances
Section titled “GetInstance: Observing Instances”const getInstance = yield* GCP.Compute.GetInstance(vm);const live = yield* getInstance();GetInstanceHttp
Section titled “GetInstanceHttp”Source:
src/GCP/Compute/GetInstanceHttp.tsKind: Layer · Provides:GCP.Compute.GetInstance
HTTP implementation of GetInstance.
GlobalAddress
Section titled “GlobalAddress”Source:
src/GCP/Compute/GlobalAddress.ts
A global Compute Engine address — a reserved anycast IP for global forwarding rules, or an internal range for VPC peering / Private Service Connect.
Labels are the only in-place update. Name, IP, type, version, purpose, network, prefix length, and description replace the address.
GlobalAddress: Creating a Global Address
Section titled “GlobalAddress: Creating a Global Address”Generated name
const ip = yield* GCP.Compute.GlobalAddress("FrontendIp", {});Named address with labels
const ip = yield* GCP.Compute.GlobalAddress("FrontendIp", { addressName: "app-lb-ip", description: "Global anycast IP for the HTTPS load balancer", ipVersion: "IPV4", labels: { env: "prod" },});GlobalAddress: Internal Ranges
Section titled “GlobalAddress: Internal Ranges”const range = yield* GCP.Compute.GlobalAddress("PsaRange", { addressType: "INTERNAL", purpose: "VPC_PEERING", network: "projects/my-project/global/networks/main", prefixLength: 16,});GlobalForwardingRule
Section titled “GlobalForwardingRule”Source:
src/GCP/Compute/GlobalForwardingRule.ts
A global Compute Engine forwarding rule — the frontend of a global load balancer. It binds an IP and port range to a target HTTP/HTTPS proxy (or SSL/TCP/gRPC proxy, or a Private Service Connect bundle).
Labels cannot be set on insert — Alchemy applies them with
setLabels after the rule exists and also stamps ownership into the
description so list / pnpm nuke:gcp can find a rule if labeling
is interrupted. list also includes unlabeled rules whose target
is an Alchemy-owned HTTP(S) proxy. target and networkTier update
in place (setTarget / patch). Name, IP, protocol, port range,
description, network, and load-balancing scheme replace the rule.
GlobalForwardingRule: Creating a Global Forwarding Rule
Section titled “GlobalForwardingRule: Creating a Global Forwarding Rule”HTTP frontend in front of a target HTTP proxy
const map = yield* GCP.Compute.UrlMap("web", { defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "example.com", stripQuery: false, },});const proxy = yield* GCP.Compute.TargetHttpProxy("http", { urlMap: map.urlMapName,});const rule = yield* GCP.Compute.GlobalForwardingRule("frontend", { target: proxy.selfLink, portRange: "80",});Named rule with labels and a reserved IP
const ip = yield* GCP.Compute.GlobalAddress("FrontendIp", {});const rule = yield* GCP.Compute.GlobalForwardingRule("frontend", { forwardingRuleName: "app-http", description: "public HTTP frontend", target: proxy.selfLink, ipAddress: ip.address, portRange: "80", loadBalancingScheme: "EXTERNAL", labels: { env: "prod" },});GlobalForwardingRule: Updating a Global Forwarding Rule
Section titled “GlobalForwardingRule: Updating a Global Forwarding Rule”const rule = yield* GCP.Compute.GlobalForwardingRule("frontend", { forwardingRuleName: "app-http", target: otherProxy.selfLink, portRange: "80", labels: { env: "prod", role: "edge" },});GlobalNetworkEndpointGroup
Section titled “GlobalNetworkEndpointGroup”Source:
src/GCP/Compute/GlobalNetworkEndpointGroup.ts
A global Compute Engine internet network endpoint group.
Global NEGs back internet (INTERNET_FQDN_PORT / INTERNET_IP_PORT)
backends for global external Application Load Balancers. They live in
the global/networkEndpointGroups collection (zonal VM NEGs and
regional serverless/PSC NEGs are separate resources). The collection
has no labels field and no update API — Alchemy stamps ownership into
the description so list / nuke can find leaked groups. Name, type,
default port, annotations, and description are immutable (changing any
of them replaces the group). Endpoints attach and detach in place.
GlobalNetworkEndpointGroup: Creating a GlobalNetworkEndpointGroup
Section titled “GlobalNetworkEndpointGroup: Creating a GlobalNetworkEndpointGroup”FQDN internet NEG
const neg = yield* GCP.Compute.GlobalNetworkEndpointGroup("Internet", { networkEndpointType: "INTERNET_FQDN_PORT", defaultPort: 443,});Explicit name and a single FQDN endpoint
const neg = yield* GCP.Compute.GlobalNetworkEndpointGroup("Internet", { networkEndpointGroupName: "www-neg", networkEndpointType: "INTERNET_FQDN_PORT", defaultPort: 443, networkEndpoints: [{ fqdn: "www.example.com", port: 443 }],});GlobalNetworkEndpointGroup: IP internet NEGs
Section titled “GlobalNetworkEndpointGroup: IP internet NEGs”const neg = yield* GCP.Compute.GlobalNetworkEndpointGroup("IpNeg", { networkEndpointType: "INTERNET_IP_PORT", defaultPort: 443, networkEndpoints: [{ ipAddress: "203.0.113.10", port: 443 }],});GlobalPublicDelegatedPrefix
Section titled “GlobalPublicDelegatedPrefix”Source:
src/GCP/Compute/GlobalPublicDelegatedPrefix.ts
A global Compute Engine public delegated prefix (BYOIP).
Delegates a CIDR from a Public Advertised Prefix so addresses and sub-prefixes can be created. Creating one requires a parent advertised prefix (Bring Your Own IP). Name, parent, CIDR, and mode replace the resource; description updates in place via patch. Compute has no labels field, so Alchemy stamps ownership into the description.
GlobalPublicDelegatedPrefix: Creating a Global Public Delegated Prefix
Section titled “GlobalPublicDelegatedPrefix: Creating a Global Public Delegated Prefix”const prefix = yield* GCP.Compute.GlobalPublicDelegatedPrefix("byoip", { parentPrefix: "projects/my-project/global/publicAdvertisedPrefixes/edge", ipCidrRange: "203.0.113.0/24",});GlobalVmExtensionPolicy
Section titled “GlobalVmExtensionPolicy”Source:
src/GCP/Compute/GlobalVmExtensionPolicy.ts
A project-level Compute Engine VM extension policy.
Global policies roll out guest extensions (Ops Agent, and similar) to matching VMs. Name replaces the resource; description, priority, selectors, extensions, and the rollout plan update in place. Compute has no labels field, so Alchemy stamps ownership into the description.
GlobalVmExtensionPolicy: Creating a Global VM Extension Policy
Section titled “GlobalVmExtensionPolicy: Creating a Global VM Extension Policy”Ops Agent, fast rollout
const policy = yield* GCP.Compute.GlobalVmExtensionPolicy("ops", { extensionPolicies: { "ops-agent": {} }, rolloutOperation: { rolloutInput: { predefinedRolloutPlan: "FAST_ROLLOUT" }, },});Label-selected VMs
const policy = yield* GCP.Compute.GlobalVmExtensionPolicy("ops", { extensionPolicies: { "ops-agent": { pinnedVersion: "2.53.0" } }, instanceSelectors: [ { labelSelector: { inclusionLabels: { role: "web" } } }, ], priority: 100,});HealthCheck
Section titled “HealthCheck”Source:
src/GCP/Compute/HealthCheck.ts
A global Compute Engine health check.
Health checks probe backends for load balancing and managed-instance-group
autohealing. This resource maps to the global healthChecks collection
(regionHealthChecks is a separate resource). Compute HealthCheck has no
labels field — Alchemy ownership is stored in the description so nuke can
find leaked checks.
HealthCheck: Creating a Health Check
Section titled “HealthCheck: Creating a Health Check”Generated name (HTTP on port 80)
const check = yield* GCP.Compute.HealthCheck("api", {});HTTP path and thresholds
const check = yield* GCP.Compute.HealthCheck("api", { description: "frontend /health", checkIntervalSec: 10, timeoutSec: 5, httpHealthCheck: { port: 80, requestPath: "/health" },});TCP health check
const check = yield* GCP.Compute.HealthCheck("tcp", { type: "TCP", tcpHealthCheck: { port: 8080 },});HttpHealthCheck
Section titled “HttpHealthCheck”Source:
src/GCP/Compute/HttpHealthCheck.ts
A legacy global Compute Engine HTTP health check.
Legacy HTTP health checks are required by target-pool network load
balancers. Other load balancers and MIG autohealing should use
HealthCheck. Compute HttpHealthCheck has no labels field — Alchemy
ownership is stored in the description so nuke can find leaked checks.
HttpHealthCheck: Creating an HTTP Health Check
Section titled “HttpHealthCheck: Creating an HTTP Health Check”Generated name
const check = yield* GCP.Compute.HttpHealthCheck("api", {});Path, port, and interval
const check = yield* GCP.Compute.HttpHealthCheck("api", { description: "frontend /health", port: 80, requestPath: "/health", checkIntervalSec: 10, timeoutSec: 5,});HttpHealthCheck: Target Pools
Section titled “HttpHealthCheck: Target Pools”const check = yield* GCP.Compute.HttpHealthCheck("api", { requestPath: "/health",});const pool = yield* GCP.Compute.TargetPool("backends", { healthChecks: [check.httpHealthCheckName],});HttpsHealthCheck
Section titled “HttpsHealthCheck”Source:
src/GCP/Compute/HttpsHealthCheck.ts
A legacy global Compute Engine HTTPS health check.
Legacy HTTPS health checks are deprecated for most load balancers —
prefer HealthCheck with httpsHealthCheck. Compute HttpsHealthCheck
has no labels field — Alchemy ownership is stored in the description so
nuke can find leaked checks.
HttpsHealthCheck: Creating an HTTPS Health Check
Section titled “HttpsHealthCheck: Creating an HTTPS Health Check”Generated name
const check = yield* GCP.Compute.HttpsHealthCheck("api", {});Path, port, and interval
const check = yield* GCP.Compute.HttpsHealthCheck("api", { description: "frontend /health", port: 443, requestPath: "/health", checkIntervalSec: 10, timeoutSec: 5,});Source:
src/GCP/Compute/Image.ts
A Compute Engine custom image used to create boot disks for VMs.
Create from a disk, another image, a snapshot, or a GCS tarball.
family and description update in place; labels are synced via
setLabels. Source, size, architecture, licenses, and storage
locations replace the image.
Image: Creating an Image
Section titled “Image: Creating an Image”Image from a disk
const image = yield* GCP.Compute.Image("boot", { sourceDisk: "projects/my-project/zones/us-central1-a/disks/my-disk", family: "app-boot", labels: { env: "prod" },});Clone a public image family
const image = yield* GCP.Compute.Image("debian", { sourceImage: "projects/debian-cloud/global/images/family/debian-12", storageLocations: ["us-central1"],});Image: Updating an Image
Section titled “Image: Updating an Image”const image = yield* GCP.Compute.Image("boot", { imageName: "app-boot-v2", sourceDisk: "projects/my-project/zones/us-central1-a/disks/my-disk", family: "app-boot", description: "golden image", labels: { env: "prod", role: "boot" },});Instance
Section titled “Instance”Source:
src/GCP/Compute/Instance.ts
A Google Compute Engine VM instance.
Instance: Creating an Instance
Section titled “Instance: Creating an Instance”Generated name
const vm = yield* GCP.Compute.Instance("web", { zone: "us-central1-a", machineType: "e2-micro",});Explicit name, labels, and metadata
const vm = yield* GCP.Compute.Instance("web", { instanceName: "web-1", zone: "us-central1-a", machineType: "e2-micro", sourceImage: "projects/debian-cloud/global/images/family/debian-12", labels: { env: "prod" }, tags: ["http-server"], metadata: { "enable-oslogin": "TRUE" },});Instance: Static IPs and Extra Disks
Section titled “Instance: Static IPs and Extra Disks”const ip = yield* GCP.Compute.Address("web-ip", { region: "us-central1" });const data = yield* GCP.Compute.Disk("web-data", { zone: "us-central1-a", sizeGb: 10,});const vm = yield* GCP.Compute.Instance("web", { zone: "us-central1-a", natIP: ip.address, attachedDisks: [{ source: data.selfLink, deviceName: "data" }], tags: ["http-server"], metadata: { "startup-script": "#!/bin/bash\ncd /tmp && python3 -m http.server 80", },});Instance: Starting and Stopping
Section titled “Instance: Starting and Stopping”const start = yield* GCP.Compute.StartInstance(vm);yield* start();InstanceGroup
Section titled “InstanceGroup”Source:
src/GCP/Compute/InstanceGroup.ts
A zonal unmanaged Compute Engine instance group.
Unmanaged groups hold an explicit list of VMs and optional named ports
for load balancing. They have no labels API — Alchemy records ownership
in the description so list / pnpm nuke:gcp can find them.
InstanceGroup: Creating an Instance Group
Section titled “InstanceGroup: Creating an Instance Group”Generated name
const group = yield* GCP.Compute.InstanceGroup("web", { namedPorts: [{ name: "http", port: 80 }],});Explicit name, zone, and named ports
const group = yield* GCP.Compute.InstanceGroup("web", { instanceGroupName: "web-backends", zone: "us-central1-a", description: "HTTP backends", namedPorts: [ { name: "http", port: 80 }, { name: "https", port: 443 }, ],});InstanceGroupManager
Section titled “InstanceGroupManager”Source:
src/GCP/Compute/InstanceGroupManager.ts
A zonal Compute Engine managed instance group (MIG).
The group creates VMs from an instance template and maintains
targetSize. Alchemy records ownership in the description so
list / pnpm nuke:gcp can find groups (MIGs have no labels API).
Changing managerName, zone, or baseInstanceName replaces the
group.
InstanceGroupManager: Creating a Managed Instance Group
Section titled “InstanceGroupManager: Creating a Managed Instance Group”Generated name, empty group
const template = yield* GCP.Compute.InstanceTemplate("web", {});const group = yield* GCP.Compute.InstanceGroupManager("web", { instanceTemplate: template.templateName,});Named ports and target size
const template = yield* GCP.Compute.InstanceTemplate("web", {});const group = yield* GCP.Compute.InstanceGroupManager("web", { managerName: "web-mig", zone: "us-central1-a", instanceTemplate: template.templateName, targetSize: 2, namedPorts: [{ name: "http", port: 80 }],});InstanceGroupManagerResizeRequest
Section titled “InstanceGroupManagerResizeRequest”Source:
src/GCP/Compute/InstanceGroupManagerResizeRequest.ts
A zonal queued resize request on a managed instance group.
Resize requests provision additional MIG VMs immediately or by queueing
until capacity is available (typically GPU / queued-provisioning
machine types). Name, zone, MIG, resizeBy, and run duration replace
the request — there is no in-place update. Compute has no labels
field, so Alchemy stamps ownership into the description.
Delete cancels an ACCEPTED / CREATING request first, then removes
the record.
InstanceGroupManagerResizeRequest: Creating a Resize Request
Section titled “InstanceGroupManagerResizeRequest: Creating a Resize Request”const template = yield* GCP.Compute.InstanceTemplate("web", {});const group = yield* GCP.Compute.InstanceGroupManager("web", { instanceTemplate: template.templateName, targetSize: 0,});const request = yield* GCP.Compute.InstanceGroupManagerResizeRequest( "burst", { instanceGroupManager: group.managerName, zone: group.zone, resizeBy: 1, requestedRunDuration: { seconds: "3600" }, },);InstanceTemplate
Section titled “InstanceTemplate”Source:
src/GCP/Compute/InstanceTemplate.ts
A global Compute Engine instance template.
Instance templates are immutable. Changing machine type, disks, labels, network interfaces, or other properties replaces the template. Use the template to create VMs, managed instance groups, and reservations.
InstanceTemplate: Creating a Template
Section titled “InstanceTemplate: Creating a Template”Generated name with defaults
const template = yield* GCP.Compute.InstanceTemplate("web", {});Explicit machine type, disk, and labels
const template = yield* GCP.Compute.InstanceTemplate("web", { machineType: "e2-micro", labels: { env: "prod" }, disks: [ { boot: true, autoDelete: true, sourceImage: "projects/debian-cloud/global/images/family/debian-12", diskSizeGb: 10, }, ], networkInterfaces: [{ network: "global/networks/default" }],});InstantSnapshot
Section titled “InstantSnapshot”Source:
src/GCP/Compute/InstantSnapshot.ts
A zonal Compute Engine instant snapshot.
Instant snapshots capture a disk’s point-in-time state in the same zone
(Hyperdisk and some persistent-disk types). Name, zone, source disk, and
description are immutable — changing them replaces the snapshot. Labels
update in place via instantSnapshots.setLabels.
InstantSnapshot: Creating an Instant Snapshot
Section titled “InstantSnapshot: Creating an Instant Snapshot”Snapshot of a disk
const disk = yield* GCP.Compute.Disk("data", { zone: "us-central1-a", type: "pd-balanced", sizeGb: 10,});const snap = yield* GCP.Compute.InstantSnapshot("checkpoint", { sourceDisk: disk.selfLink, zone: disk.zone,});Named snapshot with labels
const snap = yield* GCP.Compute.InstantSnapshot("checkpoint", { instantSnapshotName: "app-data-now", zone: "us-central1-a", sourceDisk: "zones/us-central1-a/disks/app-data", labels: { env: "prod" },});InstantSnapshotGroup
Section titled “InstantSnapshotGroup”Source:
src/GCP/Compute/InstantSnapshotGroup.ts
A zonal Compute Engine instant snapshot group.
Captures a point-in-time state of every disk in a consistency group. Name, zone, and source policy replace the group. Compute has no labels field, so Alchemy stamps ownership into the description.
InstantSnapshotGroup: Creating an Instant Snapshot Group
Section titled “InstantSnapshotGroup: Creating an Instant Snapshot Group”const policy = yield* GCP.Compute.ResourcePolicy("consistent", { diskConsistencyGroupPolicy: {},});const group = yield* GCP.Compute.InstantSnapshotGroup("checkpoint", { zone: "us-central1-a", sourceConsistencyGroup: policy.selfLink,});Interconnect
Section titled “Interconnect”Source:
src/GCP/Compute/Interconnect.ts
A global Compute Engine Dedicated Interconnect.
Dedicated Interconnect is a physical connection between your on-premises
network and Google’s network at a colocation facility. Name, location,
interconnect type, link type, customer name, remote location, and
requested features are immutable. Description, admin status, link count,
NOC email, and MACsec update in place via interconnects.patch. Labels
are applied with setLabels after the interconnect exists.
Interconnect: Creating an Interconnect
Section titled “Interconnect: Creating an Interconnect”Dedicated 10G interconnect
const interconnect = yield* GCP.Compute.Interconnect("OnPrem", { location: "iad-zone1-1", interconnectType: "DEDICATED", linkType: "LINK_TYPE_ETHERNET_10G_LR", requestedLinkCount: 1, customerName: "Example Corp", description: "prod interconnect",});Named interconnect with labels
const interconnect = yield* GCP.Compute.Interconnect("OnPrem", { interconnectName: "app-ix", location: "iad-zone1-1", customerName: "Example Corp", labels: { env: "prod" },});InterconnectAttachment
Section titled “InterconnectAttachment”Source:
src/GCP/Compute/InterconnectAttachment.ts
A regional Compute Engine Interconnect VLAN attachment.
VLAN attachments connect a Cloud Router to a Dedicated or Partner
Interconnect. Name, region, router, type, interconnect, encryption,
VLAN tag, and availability domain are immutable. Description, admin
status, bandwidth, MTU, and stack type update in place via
interconnectAttachments.patch. Labels are applied with setLabels
after the attachment exists.
InterconnectAttachment: Creating an Interconnect Attachment
Section titled “InterconnectAttachment: Creating an Interconnect Attachment”Partner attachment
const attachment = yield* GCP.Compute.InterconnectAttachment("Vlan", { region: "us-central1", router: router.routerName, type: "PARTNER", edgeAvailabilityDomain: "AVAILABILITY_DOMAIN_1", mtu: 1500,});Dedicated attachment
const attachment = yield* GCP.Compute.InterconnectAttachment("Vlan", { interconnectAttachmentName: "app-vlan", router: router.selfLink, type: "DEDICATED", interconnect: interconnect.selfLink, vlanTag8021q: 100, bandwidth: "BPS_1G",});InterconnectAttachmentGroup
Section titled “InterconnectAttachmentGroup”Source:
src/GCP/Compute/InterconnectAttachmentGroup.ts
A global Compute Engine Interconnect attachment group.
Groups collect VLAN attachments so GCP can report the availability SLA
they actually provide. Name is immutable. Description, intent, member
attachments, and the optional InterconnectGroup URL update in place via
interconnectAttachmentGroups.patch. Compute InterconnectAttachmentGroup
has no labels field — Alchemy stamps ownership into the description so
nuke can find leaked groups.
InterconnectAttachmentGroup: Creating an Attachment Group
Section titled “InterconnectAttachmentGroup: Creating an Attachment Group”Generated name, no SLA
const group = yield* GCP.Compute.InterconnectAttachmentGroup("Vlans", { description: "dev vlan attachments", intent: { availabilitySla: "NO_SLA" },});Named group with a member attachment
const group = yield* GCP.Compute.InterconnectAttachmentGroup("Vlans", { interconnectAttachmentGroupName: "app-vlan-group", intent: { availabilitySla: "PRODUCTION_NON_CRITICAL" }, attachments: { primary: { attachment: attachment.selfLink }, },});InterconnectGroup
Section titled “InterconnectGroup”Source:
src/GCP/Compute/InterconnectGroup.ts
A global Compute Engine Interconnect group.
Groups collect Dedicated Interconnects so GCP can report the topology
capability (SLA) they actually provide. Name is immutable. Description,
intent, and member interconnects update in place via
interconnectGroups.patch. Compute InterconnectGroup has no labels
field — Alchemy stamps ownership into the description so nuke can find
leaked groups.
InterconnectGroup: Creating an Interconnect Group
Section titled “InterconnectGroup: Creating an Interconnect Group”Generated name, no SLA
const group = yield* GCP.Compute.InterconnectGroup("Bundle", { description: "dev interconnects", intent: { topologyCapability: "NO_SLA" },});Named group with a member interconnect
const group = yield* GCP.Compute.InterconnectGroup("Bundle", { interconnectGroupName: "app-ix-group", intent: { topologyCapability: "PRODUCTION_NON_CRITICAL" }, interconnects: { primary: { interconnect: interconnect.selfLink }, },});License
Section titled “License”Source:
src/GCP/Compute/License.ts
A global Compute Engine License.
Licenses are intended for third-party partners who publish Cloud
Marketplace images. Name and osLicense are immutable. Description and
the attachability flags update in place via licenses.update. Compute
License has no labels field — Alchemy stamps ownership into the
description so nuke can find leaked licenses.
License: Creating a License
Section titled “License: Creating a License”Generated name
const license = yield* GCP.Compute.License("ImageLicense", { description: "marketplace os", transferable: true,});Named OS license
const license = yield* GCP.Compute.License("ImageLicense", { licenseName: "app-os", osLicense: true, transferable: false, removableFromDisk: false,});MachineImage
Section titled “MachineImage”Source:
src/GCP/Compute/MachineImage.ts
A Compute Engine machine image capturing a VM’s disks, metadata, and configuration so it can be used to create new instances.
Create from a source instance. Name, source instance, description, and
storage locations replace the machine image. Labels are synced in place
via setLabels.
MachineImage: Creating a Machine Image
Section titled “MachineImage: Creating a Machine Image”Machine image from an instance
const vm = yield* GCP.Compute.Instance("web", { zone: "us-central1-a", machineType: "e2-micro",});const image = yield* GCP.Compute.MachineImage("backup", { sourceInstance: vm.selfLink, labels: { env: "prod" },});Explicit name and regional storage
const image = yield* GCP.Compute.MachineImage("backup", { machineImageName: "web-golden", sourceInstance: "projects/{project}/zones/us-central1-a/instances/web", description: "golden image of web", storageLocations: ["us-central1"],});MachineImage: Updating a Machine Image
Section titled “MachineImage: Updating a Machine Image”const image = yield* GCP.Compute.MachineImage("backup", { machineImageName: "web-golden", sourceInstance: "projects/{project}/zones/us-central1-a/instances/web", labels: { env: "prod", role: "golden" },});Network
Section titled “Network”Source:
src/GCP/Compute/Network.ts
A Google Compute Engine VPC network.
VPC networks have no labels field. Alchemy stamps
alchemy-stack / alchemy-stage / alchemy-id into the description so
list and pnpm nuke:gcp can still identify owned networks.
Network: Creating a Network
Section titled “Network: Creating a Network”Custom-mode VPC (generated name)
const network = yield* GCP.Compute.Network("Vpc", {});Explicit name, MTU, and routing mode
const network = yield* GCP.Compute.Network("Vpc", { networkName: "app-vpc", description: "application vpc", autoCreateSubnetworks: false, mtu: 1500, routingMode: "GLOBAL",});Network: Auto-mode VPC
Section titled “Network: Auto-mode VPC”const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: true,});Auto mode is slower to create and delete (one subnet per region). Prefer
custom mode (autoCreateSubnetworks: false, the default) unless you
specifically want the pre-created ranges.
NetworkAttachment
Section titled “NetworkAttachment”Source:
src/GCP/Compute/NetworkAttachment.ts
A regional Compute Engine Private Service Connect network attachment.
A network attachment lets a producer VPC initiate connections into a consumer VPC through a PSC interface. It lists consumer subnets and admits producers either automatically or via accept/reject lists. Compute NetworkAttachment has no labels field — Alchemy ownership is stored in the description so nuke can find leaked attachments.
NetworkAttachment: Creating a Network Attachment
Section titled “NetworkAttachment: Creating a Network Attachment”Generated name, automatic accept
const attachment = yield* GCP.Compute.NetworkAttachment("Consumer", { region: "us-central1", subnetworks: [subnet.selfLink], connectionPreference: "ACCEPT_AUTOMATIC",});Manual admission
const attachment = yield* GCP.Compute.NetworkAttachment("Consumer", { networkAttachmentName: "app-na", subnetworks: [subnet.selfLink], connectionPreference: "ACCEPT_MANUAL", producerAcceptLists: ["my-producer-project"],});NetworkEdgeSecurityService
Section titled “NetworkEdgeSecurityService”Source:
src/GCP/Compute/NetworkEdgeSecurityService.ts
A regional Compute Engine network edge security service.
Network edge security services attach a Cloud Armor network (L3/L4)
security policy to a region. Name and region are immutable. Description
and securityPolicy update in place via
networkEdgeSecurityServices.patch. Compute NetworkEdgeSecurityService
has no labels field — Alchemy stamps ownership into the description so
nuke can find leaked services.
NetworkEdgeSecurityService: Creating a Network Edge Security Service
Section titled “NetworkEdgeSecurityService: Creating a Network Edge Security Service”Generated name
const ness = yield* GCP.Compute.NetworkEdgeSecurityService("EdgeArmor", { region: "us-central1", description: "regional network armor",});Attach a network security policy
const ness = yield* GCP.Compute.NetworkEdgeSecurityService("EdgeArmor", { networkEdgeSecurityServiceName: "app-ness", securityPolicy: policy.selfLink,});NetworkEndpointGroup
Section titled “NetworkEndpointGroup”Source:
src/GCP/Compute/NetworkEndpointGroup.ts
A zonal Compute Engine network endpoint group (NEG).
Zonal NEGs hold VM IP/port endpoints (or hybrid NON_GCP_PRIVATE_IP_PORT
endpoints) for load balancing. They have no labels API — Alchemy records
ownership in the description so list / pnpm nuke:gcp can find them.
Serverless, PSC, and internet NEGs use the regional/global collections
and are not this resource.
NetworkEndpointGroup: Creating a Network Endpoint Group
Section titled “NetworkEndpointGroup: Creating a Network Endpoint Group”Generated name
const neg = yield* GCP.Compute.NetworkEndpointGroup("web", { defaultPort: 80,});Explicit name, zone, and default port
const neg = yield* GCP.Compute.NetworkEndpointGroup("web", { networkEndpointGroupName: "web-neg", zone: "us-central1-a", network: "default", defaultPort: 80, description: "HTTP backends",});NetworkEndpointGroup: Endpoints
Section titled “NetworkEndpointGroup: Endpoints”const neg = yield* GCP.Compute.NetworkEndpointGroup("web", { zone: "us-central1-a", defaultPort: 80, networkEndpoints: [ { instance: vm.instanceName, port: 80 }, ],});NetworkFirewallPolicy
Section titled “NetworkFirewallPolicy”Source:
src/GCP/Compute/NetworkFirewallPolicy.ts
A global Compute Engine network firewall policy.
Network firewall policies live at the project level under
global/firewallPolicies and are identified by the user-provided
name. Name and policy type are immutable. Description updates in
place via networkFirewallPolicies.patch. Rules are synced with
addRule / patchRule / removeRule. Associations are synced with
addAssociation / removeAssociation. Compute network firewall
policies have no labels field — Alchemy stamps ownership into the
description so nuke can find leaked policies.
NetworkFirewallPolicy: Creating a Network Firewall Policy
Section titled “NetworkFirewallPolicy: Creating a Network Firewall Policy”Generated name with an allow rule
const policy = yield* GCP.Compute.NetworkFirewallPolicy("VpcFw", { description: "allow internal http", rules: [ { action: "allow", priority: 1000, direction: "INGRESS", match: { srcIpRanges: ["10.0.0.0/8"], layer4Configs: [{ ipProtocol: "tcp", ports: ["80"] }], }, }, ],});Associate with a VPC
const policy = yield* GCP.Compute.NetworkFirewallPolicy("VpcFw", { networkFirewallPolicyName: "app-nfw", associations: [{ name: "vpc", attachmentTarget: network.selfLink }],});NodeGroup
Section titled “NodeGroup”Source:
src/GCP/Compute/NodeGroup.ts
A zonal Compute Engine sole-tenant node group.
Node groups allocate dedicated physical servers from a node template.
Name and zone are immutable. Description, maintenance policy, window,
interval, autoscaling, and share settings update in place via
nodeGroups.patch. The node template is swapped with
setNodeTemplate. Compute NodeGroup has no labels field — Alchemy
stamps ownership into the description so nuke can find leaked groups.
NodeGroup: Creating a Node Group
Section titled “NodeGroup: Creating a Node Group”Generated name from a template
const group = yield* GCP.Compute.NodeGroup("SoleTenant", { zone: "us-central1-a", nodeTemplate: template.selfLink, initialNodeCount: 1, description: "prod sole tenant",});Autoscaled group
const group = yield* GCP.Compute.NodeGroup("SoleTenant", { nodeTemplate: template.nodeTemplateName, initialNodeCount: 0, autoscalingPolicy: { mode: "ON", minNodes: 0, maxNodes: 3 },});NodeTemplate
Section titled “NodeTemplate”Source:
src/GCP/Compute/NodeTemplate.ts
A regional Compute Engine sole-tenant node template.
Node templates define the properties of sole-tenant nodes created in a node group (node type, CPU overcommit, affinity labels, local disks). There is no in-place update API — changing any property replaces the template. Compute NodeTemplate has no labels field — Alchemy stamps ownership into the description so nuke can find leaked templates.
NodeTemplate: Creating a Node Template
Section titled “NodeTemplate: Creating a Node Template”Generated name with a node type
const template = yield* GCP.Compute.NodeTemplate("SoleTenant", { region: "us-central1", nodeType: "n2-node-80-640", description: "prod sole tenant",});Flexible node type
const template = yield* GCP.Compute.NodeTemplate("SoleTenant", { nodeTypeFlexibility: { cpus: "80", memory: "640GB" }, cpuOvercommitType: "ENABLED",});OrganizationSecurityPolicy
Section titled “OrganizationSecurityPolicy”Source:
src/GCP/Compute/OrganizationSecurityPolicy.ts
An organization-scoped Cloud Armor security policy.
Organization security policies live under
locations/global/securityPolicies and are identified by a
server-assigned numeric id. The user-facing name is shortName. Parent
and type are immutable. Description and WAF options update in place via
organizationSecurityPolicies.patch. Rules are synced with addRule /
patchRule / removeRule.
OrganizationSecurityPolicy: Creating an Organization Security Policy
Section titled “OrganizationSecurityPolicy: Creating an Organization Security Policy”Generated name with a deny rule
const policy = yield* GCP.Compute.OrganizationSecurityPolicy("OrgArmor", { description: "deny a scanner", rules: [ { action: "deny(403)", priority: 1000, match: { versionedExpr: "SRC_IPS_V1", config: { srcIpRanges: ["9.9.9.0/24"] }, }, }, ],});Named policy under an organization
const policy = yield* GCP.Compute.OrganizationSecurityPolicy("OrgArmor", { shortName: "app-org-armor", parent: "organizations/123456789", description: "org WAF",});PacketMirroring
Section titled “PacketMirroring”Source:
src/GCP/Compute/PacketMirroring.ts
A regional Compute Engine packet mirroring policy.
Packet Mirroring copies traffic from selected VMs, subnets, or network
tags in a VPC and sends it to a collector internal passthrough Network
Load Balancer (ForwardingRule with isMirroringCollector: true).
Compute PacketMirroring has no labels field — Alchemy ownership is
stored in the description so nuke can find leaked resources.
Name, region, network, and description are immutable; collector ILB, mirrored sources, filter, enable, and priority update in place.
PacketMirroring: Creating a Packet Mirroring Policy
Section titled “PacketMirroring: Creating a Packet Mirroring Policy”Mirror VMs by network tag
const policy = yield* GCP.Compute.PacketMirroring("Capture", { network: vpc.selfLink, collectorIlb: collector.selfLink, mirroredResources: { tags: ["mirror-me"] },});Named policy with a traffic filter
const policy = yield* GCP.Compute.PacketMirroring("Capture", { packetMirroringName: "app-capture", region: "us-central1", description: "tcp to the collector", network: "default", collectorIlb: collector.selfLink, mirroredResources: { subnetworks: [subnet.selfLink], tags: ["web"], }, filter: { direction: "BOTH", ipProtocols: ["tcp"], cidrRanges: ["0.0.0.0/0"], }, priority: 800,});PacketMirroring: Updating a Policy
Section titled “PacketMirroring: Updating a Policy”const policy = yield* GCP.Compute.PacketMirroring("Capture", { packetMirroringName: "app-capture", network: vpc.selfLink, collectorIlb: collector.selfLink, mirroredResources: { tags: ["mirror-me"] }, enable: false,});PublicAdvertisedPrefix
Section titled “PublicAdvertisedPrefix”Source:
src/GCP/Compute/PublicAdvertisedPrefix.ts
A global public advertised prefix (BYOIP).
A public advertised prefix is an aggregated IP prefix you bring to
Google Cloud. Creating one requires a prefix you own and reverse-DNS
verification. Name, CIDR, verification IP, and PDP scope are immutable.
Description updates in place via publicAdvertisedPrefixes.patch.
PublicAdvertisedPrefix: Creating a Public Advertised Prefix
Section titled “PublicAdvertisedPrefix: Creating a Public Advertised Prefix”Regional-scope IPv4 prefix
const prefix = yield* GCP.Compute.PublicAdvertisedPrefix("Byoip", { ipCidrRange: "203.0.113.0/24", dnsVerificationIp: "203.0.113.1", pdpScope: "REGIONAL", description: "lab prefix",});Explicit name
const prefix = yield* GCP.Compute.PublicAdvertisedPrefix("Byoip", { prefixName: "lab-pap", ipCidrRange: "203.0.113.0/24", pdpScope: "REGIONAL",});PublicDelegatedPrefix
Section titled “PublicDelegatedPrefix”Source:
src/GCP/Compute/PublicDelegatedPrefix.ts
A regional public delegated prefix (BYOIP).
A public delegated prefix is an IP block carved from a public advertised
prefix and scoped to one region (or global). Creating one requires a
parent advertised prefix. Name, region, parent, CIDR, and mode are
immutable. Description and sub-prefixes update in place via
publicDelegatedPrefixes.patch.
PublicDelegatedPrefix: Creating a Public Delegated Prefix
Section titled “PublicDelegatedPrefix: Creating a Public Delegated Prefix”Regional IPv4 sub-prefix
const pap = yield* GCP.Compute.PublicAdvertisedPrefix("Byoip", { ipCidrRange: "203.0.113.0/24", pdpScope: "REGIONAL",});const pdp = yield* GCP.Compute.PublicDelegatedPrefix("Delegate", { parentPrefix: pap.selfLink, ipCidrRange: "203.0.113.0/26", description: "us-central1 block",});Explicit name
const pdp = yield* GCP.Compute.PublicDelegatedPrefix("Delegate", { prefixName: "lab-pdp", region: "us-central1", parentPrefix: pap.selfLink, ipCidrRange: "203.0.113.0/26",});RegionAutoscaler
Section titled “RegionAutoscaler”Source:
src/GCP/Compute/RegionAutoscaler.ts
A regional Compute Engine autoscaler for a managed instance group.
Changing autoscalerName or region replaces the autoscaler. Policy,
target, description, and labels update in place via
regionAutoscalers.patch. Compute Engine has no labels on this
resource, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list /
pnpm nuke:gcp can find them.
RegionAutoscaler: Creating a Region Autoscaler
Section titled “RegionAutoscaler: Creating a Region Autoscaler”CPU policy with generated name
const scaler = yield* GCP.Compute.RegionAutoscaler("Web", { target: mig.selfLink, autoscalingPolicy: { minNumReplicas: 1, maxNumReplicas: 5, coolDownPeriodSec: 60, cpuUtilization: { utilizationTarget: 0.6 }, },});Named autoscaler, labels, and OFF mode
const scaler = yield* GCP.Compute.RegionAutoscaler("Web", { autoscalerName: "web-scaler", region: "us-central1", target: "projects/{project}/regions/us-central1/instanceGroupManagers/web", description: "scale the web MIG", labels: { env: "prod" }, autoscalingPolicy: { minNumReplicas: 0, maxNumReplicas: 3, mode: "OFF", cpuUtilization: { utilizationTarget: 0.5 }, },});RegionAutoscaler: Updating Policy
Section titled “RegionAutoscaler: Updating Policy”const scaler = yield* GCP.Compute.RegionAutoscaler("Web", { autoscalerName: "web-scaler", target: mig.selfLink, autoscalingPolicy: { minNumReplicas: 1, maxNumReplicas: 10, cpuUtilization: { utilizationTarget: 0.5 }, },});RegionBackendBucket
Section titled “RegionBackendBucket”Source:
src/GCP/Compute/RegionBackendBucket.ts
A regional Compute Engine backend bucket that fronts a Cloud Storage bucket for HTTP(S) load balancing.
Compute Engine backend buckets have no labels field, so Alchemy
stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find
them.
RegionBackendBucket: Creating a Region Backend Bucket
Section titled “RegionBackendBucket: Creating a Region Backend Bucket”Generated name in front of a Storage bucket
const assets = yield* GCP.Storage.Bucket("assets", { forceDestroy: true,});const backend = yield* GCP.Compute.RegionBackendBucket("cdn", { bucketName: assets.bucketName, description: "static assets",});Explicit name with Cloud CDN
const backend = yield* GCP.Compute.RegionBackendBucket("cdn", { name: "app-static", region: "us-central1", bucketName: assets.bucketName, enableCdn: true, compressionMode: "AUTOMATIC",});RegionBackendService
Section titled “RegionBackendService”Source:
src/GCP/Compute/RegionBackendService.ts
A regional Compute Engine backend service. Backend services define how Google Cloud load balancers distribute traffic — protocol, timeout, session affinity, health checks, and the backends themselves.
Compute Engine backend services have no labels field, so Alchemy stamps
ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them. Changing
name, region, loadBalancingScheme, or network replaces the
resource.
RegionBackendService: Creating a Region Backend Service
Section titled “RegionBackendService: Creating a Region Backend Service”Generated name
const backend = yield* GCP.Compute.RegionBackendService("web", { protocol: "HTTP", loadBalancingScheme: "INTERNAL_MANAGED",});Explicit name, timeout, and labels
const backend = yield* GCP.Compute.RegionBackendService("web", { name: "web-backend", region: "us-central1", protocol: "HTTP", loadBalancingScheme: "INTERNAL_MANAGED", timeoutSec: 30, localityLbPolicy: "ROUND_ROBIN", labels: { env: "prod" },});RegionBackendService: Updating a Region Backend Service
Section titled “RegionBackendService: Updating a Region Backend Service”const backend = yield* GCP.Compute.RegionBackendService("web", { name: "web-backend", timeoutSec: 60,});RegionCompositeHealthCheck
Section titled “RegionCompositeHealthCheck”Source:
src/GCP/Compute/RegionCompositeHealthCheck.ts
A regional Compute Engine composite health check.
Composite health checks AND the results of one or more HealthSource
resources and publish the aggregate to a destination ForwardingRule.
Name and region are immutable. Destination, sources, and description
update in place via regionCompositeHealthChecks.patch.
RegionCompositeHealthCheck: Creating a Composite Health Check
Section titled “RegionCompositeHealthCheck: Creating a Composite Health Check”Generated name
const check = yield* GCP.Compute.RegionCompositeHealthCheck("Comp", { healthDestination: rule.selfLink, healthSources: [source.selfLink], description: "and backends",});Named check
const check = yield* GCP.Compute.RegionCompositeHealthCheck("Comp", { healthCheckName: "app-composite", region: "us-central1", healthDestination: rule.selfLink, healthSources: [source.selfLink],});RegionDisk
Section titled “RegionDisk”Source:
src/GCP/Compute/RegionDisk.ts
A regional Compute Engine persistent disk.
Regional disks replicate across two zones in a region and require a
minimum size of 200 GB. Changing
region, replicaZones, type, diskName, sourceImage,
sourceSnapshot, sourceDisk, architecture,
physicalBlockSizeBytes, or enableConfidentialCompute replaces the
disk. Growing sizeGb is applied in place via regionDisks.resize;
shrinking it replaces the disk.
RegionDisk: Creating a RegionDisk
Section titled “RegionDisk: Creating a RegionDisk”Generated name
const disk = yield* GCP.Compute.RegionDisk("data", {});Explicit name, replica zones, type, size, and labels
const disk = yield* GCP.Compute.RegionDisk("data", { diskName: "app-data", region: "us-central1", replicaZones: ["us-central1-a", "us-central1-b"], type: "pd-balanced", sizeGb: 200, labels: { env: "prod" },});RegionDisk: Resizing a RegionDisk
Section titled “RegionDisk: Resizing a RegionDisk”const disk = yield* GCP.Compute.RegionDisk("data", { diskName: "app-data", region: "us-central1", sizeGb: 250,});RegionHealthAggregationPolicy
Section titled “RegionHealthAggregationPolicy”Source:
src/GCP/Compute/RegionHealthAggregationPolicy.ts
A regional Compute Engine health aggregation policy.
Health aggregation policies define how endpoint health is rolled up for
backend services used by composite health checks. Type is immutable —
changing it replaces the policy. Thresholds and description update in
place via regionHealthAggregationPolicies.patch.
RegionHealthAggregationPolicy: Creating a Health Aggregation Policy
Section titled “RegionHealthAggregationPolicy: Creating a Health Aggregation Policy”Generated name with defaults
const policy = yield* GCP.Compute.RegionHealthAggregationPolicy( "Agg", {},);Custom thresholds
const policy = yield* GCP.Compute.RegionHealthAggregationPolicy( "Agg", { description: "backend rollup", minHealthyThreshold: 2, healthyPercentThreshold: 80, },);RegionHealthCheck
Section titled “RegionHealthCheck”Source:
src/GCP/Compute/RegionHealthCheck.ts
A regional Compute Engine health check.
Health checks probe backends for load balancing and managed-instance-group
autohealing. This resource maps to the regional regionHealthChecks
collection (the global healthChecks resource is
GCP.Compute.HealthCheck). Compute HealthCheck has no labels field —
Alchemy ownership is stored in the description so nuke can find leaked
checks.
Changing healthCheckName, region, or type replaces the resource.
RegionHealthCheck: Creating a Region Health Check
Section titled “RegionHealthCheck: Creating a Region Health Check”Generated name (HTTP on port 80)
const check = yield* GCP.Compute.RegionHealthCheck("api", {});HTTP path and thresholds
const check = yield* GCP.Compute.RegionHealthCheck("api", { region: "us-central1", description: "frontend /health", checkIntervalSec: 10, timeoutSec: 5, httpHealthCheck: { port: 80, requestPath: "/health" },});TCP health check
const check = yield* GCP.Compute.RegionHealthCheck("tcp", { type: "TCP", tcpHealthCheck: { port: 8080 },});RegionHealthCheckService
Section titled “RegionHealthCheckService”Source:
src/GCP/Compute/RegionHealthCheckService.ts
A regional Compute Engine Health Check as a Service (HCSS) resource.
Health check services publish endpoint health from NEGs to notification
endpoints. Name and region are immutable. Health checks, NEGs,
notification endpoints, aggregation policy, and description update in
place via regionHealthCheckServices.patch.
RegionHealthCheckService: Creating a Health Check Service
Section titled “RegionHealthCheckService: Creating a Health Check Service”Generated name with a regional HTTP health check
const check = yield* GCP.Compute.RegionHealthCheck("api", { httpHealthCheck: { port: 80, portSpecification: "USE_FIXED_PORT" },});const service = yield* GCP.Compute.RegionHealthCheckService("Hcss", { healthChecks: [check.selfLink], description: "endpoint health",});AND aggregation
const service = yield* GCP.Compute.RegionHealthCheckService("Hcss", { healthChecks: [check.selfLink], healthStatusAggregationPolicy: "AND",});RegionHealthSource
Section titled “RegionHealthSource”Source:
src/GCP/Compute/RegionHealthSource.ts
A regional Compute Engine health source.
A health source names the backend resources whose health is aggregated
by a HealthAggregationPolicy (used by composite health checks). Type is
immutable. Sources, aggregation policy, and description update in place
via regionHealthSources.patch.
RegionHealthSource: Creating a Health Source
Section titled “RegionHealthSource: Creating a Health Source”Backend-service source
const policy = yield* GCP.Compute.RegionHealthAggregationPolicy( "Agg", {},);const backend = yield* GCP.Compute.RegionBackendService("Web", { protocol: "TCP", loadBalancingScheme: "INTERNAL",});const source = yield* GCP.Compute.RegionHealthSource("Src", { sources: [backend.selfLink], healthAggregationPolicy: policy.selfLink,});Named source
const source = yield* GCP.Compute.RegionHealthSource("Src", { sourceName: "web-health", sources: [backend.selfLink], healthAggregationPolicy: policy.selfLink, description: "internal backends",});RegionInstanceGroupManager
Section titled “RegionInstanceGroupManager”Source:
src/GCP/Compute/RegionInstanceGroupManager.ts
A regional Compute Engine managed instance group.
The manager creates and heals VMs from an instance template, spread
across zones in a region. Compute Engine has no labels on this
resource, so Alchemy stamps ownership into the description
([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list /
pnpm nuke:gcp can find them.
Name, region, baseInstanceName, and distributionPolicy.zones are
immutable — changing them replaces the manager. targetSize,
instanceTemplate / versions, description, autohealing, and update
policy patch in place. Named ports are synced onto the complementary
regional instance group.
RegionInstanceGroupManager: Creating a Regional MIG
Section titled “RegionInstanceGroupManager: Creating a Regional MIG”Generated name, no running VMs
const template = yield* GCP.Compute.InstanceTemplate("web", {});const mig = yield* GCP.Compute.RegionInstanceGroupManager("web", { instanceTemplate: template.selfLink, targetSize: 0,});Named group with named ports
const mig = yield* GCP.Compute.RegionInstanceGroupManager("web", { managerName: "web-mig", region: "us-central1", instanceTemplate: "projects/{project}/global/instanceTemplates/web", baseInstanceName: "web", targetSize: 3, namedPorts: [{ name: "http", port: 80 }],});RegionInstanceGroupManagerResizeRequest
Section titled “RegionInstanceGroupManagerResizeRequest”Source:
src/GCP/Compute/RegionInstanceGroupManagerResizeRequest.ts
A regional managed instance group resize request.
Resize requests provision (or queue) additional VMs on a regional MIG.
They are immutable after create — changing resizeBy, duration, the
parent group, or the name replaces the request. Delete cancels an
in-flight request first when the API requires it.
RegionInstanceGroupManagerResizeRequest: Creating a Resize Request
Section titled “RegionInstanceGroupManagerResizeRequest: Creating a Resize Request”Queue one extra VM
const request = yield* GCP.Compute.RegionInstanceGroupManagerResizeRequest( "Burst", { instanceGroupManager: manager.managerName, resizeBy: 1, requestedRunDuration: { seconds: "3600" }, description: "burst capacity", },);Timed run
const request = yield* GCP.Compute.RegionInstanceGroupManagerResizeRequest( "Burst", { instanceGroupManager: manager.managerName, resizeBy: 1, requestedRunDuration: { seconds: "3600" }, },);RegionInstanceTemplate
Section titled “RegionInstanceTemplate”Source:
src/GCP/Compute/RegionInstanceTemplate.ts
A regional Compute Engine instance template.
Regional instance templates are immutable. Changing machine type, disks, labels, network interfaces, or other properties replaces the template. Use the template to create regional managed instance groups.
RegionInstanceTemplate: Creating a Regional Template
Section titled “RegionInstanceTemplate: Creating a Regional Template”Generated name with defaults
const template = yield* GCP.Compute.RegionInstanceTemplate("web", {});Explicit machine type, disk, and labels
const template = yield* GCP.Compute.RegionInstanceTemplate("web", { region: "us-central1", machineType: "e2-micro", labels: { env: "prod" }, disks: [ { boot: true, autoDelete: true, sourceImage: "projects/debian-cloud/global/images/family/debian-12", diskSizeGb: 10, }, ],});RegionInstantSnapshot
Section titled “RegionInstantSnapshot”Source:
src/GCP/Compute/RegionInstantSnapshot.ts
A regional Compute Engine instant snapshot.
Instant snapshots are crash-consistent rollback points of a regional
disk. Name, source disk, description, and region are immutable —
changing them replaces the snapshot. Labels are updated in place via
regionInstantSnapshots.setLabels.
RegionInstantSnapshot: Creating a Regional Instant Snapshot
Section titled “RegionInstantSnapshot: Creating a Regional Instant Snapshot”const disk = yield* GCP.Compute.RegionDisk("data", { region: "us-central1", sizeGb: 200,});const snapshot = yield* GCP.Compute.RegionInstantSnapshot("checkpoint", { region: "us-central1", sourceDisk: disk.selfLink,});RegionInstantSnapshotGroup
Section titled “RegionInstantSnapshotGroup”Source:
src/GCP/Compute/RegionInstantSnapshotGroup.ts
A regional Compute Engine instant snapshot group.
An instant snapshot group is a crash-consistent set of instant snapshots
taken from every disk in a disk consistency group (a ResourcePolicy
with diskConsistencyGroupPolicy). There is no update API and no
labels field — Alchemy stamps ownership into the description so nuke
can find leaked groups, and every user-facing field change replaces
the resource.
RegionInstantSnapshotGroup: Creating a Regional Instant Snapshot Group
Section titled “RegionInstantSnapshotGroup: Creating a Regional Instant Snapshot Group”const policy = yield* GCP.Compute.ResourcePolicy("cg", { region: "us-central1", diskConsistencyGroupPolicy: {},});const group = yield* GCP.Compute.RegionInstantSnapshotGroup("ckpt", { region: "us-central1", sourceConsistencyGroup: policy.resourcePolicyName,});RegionNetworkEndpointGroup
Section titled “RegionNetworkEndpointGroup”Source:
src/GCP/Compute/RegionNetworkEndpointGroup.ts
A regional Compute Engine network endpoint group.
Regional NEGs back serverless (Cloud Run, App Engine, Cloud Functions),
internet (INTERNET_IP_PORT / INTERNET_FQDN_PORT), and Private Service
Connect load-balancing backends. The regional collection has no labels
field and no update API — Alchemy stamps ownership into the description
so list / nuke can find leaked groups. Name, region, type, network,
serverless config, PSC target, port, annotations, and description are
all immutable (changing any of them replaces the group).
RegionNetworkEndpointGroup: Creating a RegionNetworkEndpointGroup
Section titled “RegionNetworkEndpointGroup: Creating a RegionNetworkEndpointGroup”Cloud Run serverless NEG with a URL mask
const neg = yield* GCP.Compute.RegionNetworkEndpointGroup("RunNeg", { region: "us-central1", networkEndpointType: "SERVERLESS", cloudRun: { urlMask: "<service>" },});Cloud Run service backend
const neg = yield* GCP.Compute.RegionNetworkEndpointGroup("RunNeg", { cloudRun: { service: "api" },});RegionNetworkEndpointGroup: Internet NEGs
Section titled “RegionNetworkEndpointGroup: Internet NEGs”const neg = yield* GCP.Compute.RegionNetworkEndpointGroup("Internet", { network: "default", networkEndpointType: "INTERNET_IP_PORT", defaultPort: 443,});RegionNetworkEndpointGroup: Private Service Connect
Section titled “RegionNetworkEndpointGroup: Private Service Connect”const neg = yield* GCP.Compute.RegionNetworkEndpointGroup("Kms", { networkEndpointType: "PRIVATE_SERVICE_CONNECT", pscTargetService: "us-central1-cloudkms.googleapis.com", subnetwork: "projects/{project}/regions/us-central1/subnetworks/default",});RegionNetworkFirewallPolicy
Section titled “RegionNetworkFirewallPolicy”Source:
src/GCP/Compute/RegionNetworkFirewallPolicy.ts
A regional network firewall policy attached to a VPC network.
Policies live under projects/{project}/regions/{region}/firewallPolicies
and are identified by a user-provided RFC1035 name. Name, region, and
policyType are immutable — changing any of them replaces the policy.
Description updates in place via regionNetworkFirewallPolicies.patch.
Rules are synced with addRule / patchRule / removeRule.
Compute Engine network firewall policies have no resource labels.
Alchemy stamps ownership into the description so read / list (and
pnpm nuke:gcp) can find them.
RegionNetworkFirewallPolicy: Creating a Regional Network Firewall Policy
Section titled “RegionNetworkFirewallPolicy: Creating a Regional Network Firewall Policy”const policy = yield* GCP.Compute.RegionNetworkFirewallPolicy("VpcFw", { region: "us-central1", description: "allow internal http", rules: [ { action: "allow", priority: 1000, direction: "INGRESS", match: { srcIpRanges: ["10.0.0.0/8"], layer4Configs: [{ ipProtocol: "tcp", ports: ["80"] }], }, }, ],});RegionNotificationEndpoint
Section titled “RegionNotificationEndpoint”Source:
src/GCP/Compute/RegionNotificationEndpoint.ts
A regional Compute Engine notification endpoint.
Notification endpoints receive gRPC callbacks when a health-check
service detects backend status changes. This resource maps to the
regionNotificationEndpoints collection. There is no update API and
no labels field — Alchemy stamps ownership into the description so
nuke can find leaked endpoints. Changing any user-facing field
replaces the resource.
RegionNotificationEndpoint: Creating a Notification Endpoint
Section titled “RegionNotificationEndpoint: Creating a Notification Endpoint”Generated name
const endpoint = yield* GCP.Compute.RegionNotificationEndpoint("Health", { region: "us-central1", grpcSettings: { endpoint: "health.example.com:443" },});Named endpoint with retry settings
const endpoint = yield* GCP.Compute.RegionNotificationEndpoint("Health", { notificationEndpointName: "app-health", region: "us-central1", description: "regional health callbacks", grpcSettings: { endpoint: "health.example.com:443", retryDurationSec: 30, },});RegionSecurityPolicy
Section titled “RegionSecurityPolicy”Source:
src/GCP/Compute/RegionSecurityPolicy.ts
A regional Cloud Armor security policy that filters HTTP(S) requests targeting regional backend services.
Type and region are immutable — changing either replaces the policy.
Description, advanced options, Adaptive Protection, reCAPTCHA, DDoS
config, and user-defined fields update in place via
regionSecurityPolicies.patch. Rules are synced with addRule /
patchRule / removeRule (not patch). Labels are applied with
setLabels after the policy exists.
RegionSecurityPolicy: Creating a Regional Security Policy
Section titled “RegionSecurityPolicy: Creating a Regional Security Policy”const policy = yield* GCP.Compute.RegionSecurityPolicy("Armor", { region: "us-central1", description: "deny a scanner", rules: [ { action: "deny(403)", priority: 1000, description: "block scanner", match: { versionedExpr: "SRC_IPS_V1", config: { srcIpRanges: ["9.9.9.0/24"] }, }, }, ],});RegionSnapshot
Section titled “RegionSnapshot”Source:
src/GCP/Compute/RegionSnapshot.ts
A regional Compute Engine persistent-disk snapshot.
Regional snapshots are created from a regional disk (or instant
snapshot) and stored in the same region. Name, source, type, storage
locations, chain name, description, and region are immutable —
changing them replaces the snapshot. Labels are updated in place via
regionSnapshots.setLabels.
RegionSnapshot: Creating a Regional Snapshot
Section titled “RegionSnapshot: Creating a Regional Snapshot”const disk = yield* GCP.Compute.RegionDisk("data", { region: "us-central1", sizeGb: 200,});const snapshot = yield* GCP.Compute.RegionSnapshot("nightly", { region: "us-central1", sourceDisk: disk.selfLink,});RegionSslCertificate
Section titled “RegionSslCertificate”Source:
src/GCP/Compute/RegionSslCertificate.ts
A regional Compute Engine SSL certificate for HTTPS load balancing.
Maps to the regionSslCertificates collection (the global
sslCertificates collection is GCP.Compute.SslCertificate).
Certificates cannot be updated in place — every user-facing field is
immutable and changing it replaces the resource. Compute SSL
certificates have no labels field, so Alchemy stamps ownership into
the description for list / nuke.
RegionSslCertificate: Creating a Self-Managed Certificate
Section titled “RegionSslCertificate: Creating a Self-Managed Certificate”Generated name
const cert = yield* GCP.Compute.RegionSslCertificate("Frontend", { region: "us-central1", certificate: pemCertificate, privateKey: pemPrivateKey,});Named certificate with a description
const cert = yield* GCP.Compute.RegionSslCertificate("Frontend", { sslCertificateName: "app-frontend-tls", region: "us-central1", description: "prod frontend", certificate: pemCertificate, privateKey: pemPrivateKey,});RegionSslPolicy
Section titled “RegionSslPolicy”Source:
src/GCP/Compute/RegionSslPolicy.ts
A regional Compute Engine SSL policy for HTTPS and SSL load balancing.
SSL policies control the TLS versions and cipher suites offered by
regional Application Load Balancers and proxy Network Load Balancers.
This resource maps to the regionSslPolicies collection (the global
sslPolicies collection is GCP.Compute.SslPolicy). Compute SslPolicy
has no labels field — Alchemy ownership is stored in the description
so nuke can find leaked policies.
RegionSslPolicy: Creating a Regional SSL Policy
Section titled “RegionSslPolicy: Creating a Regional SSL Policy”Generated name (COMPATIBLE, TLS 1.0)
const policy = yield* GCP.Compute.RegionSslPolicy("Frontend", { region: "us-central1",});Modern profile and TLS 1.2
const policy = yield* GCP.Compute.RegionSslPolicy("Frontend", { region: "us-central1", description: "prod frontend", profile: "MODERN", minTlsVersion: "TLS_1_2",});RegionTargetHttpProxy
Section titled “RegionTargetHttpProxy”Source:
src/GCP/Compute/RegionTargetHttpProxy.ts
A regional Compute Engine target HTTP proxy.
Regional target HTTP proxies are referenced by regional forwarding rules
and point at a regional URL map that routes host/path to a backend
service or redirect. This resource maps to the regionTargetHttpProxies
collection (targetHttpProxies is GCP.Compute.TargetHttpProxy).
Compute RegionTargetHttpProxy has no labels field — Alchemy ownership is
stored in the description so nuke can find leaked proxies. The only
in-place mutation is setUrlMap; name, region, description,
proxyBind, and httpKeepAliveTimeoutSec replace the proxy.
RegionTargetHttpProxy: Creating a Regional Target HTTP Proxy
Section titled “RegionTargetHttpProxy: Creating a Regional Target HTTP Proxy”Generated name in front of a regional URL map
const map = yield* GCP.Compute.RegionUrlMap("web", { region: "us-central1", defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "example.com", stripQuery: false, },});const proxy = yield* GCP.Compute.RegionTargetHttpProxy("http", { region: "us-central1", urlMap: map.urlMapName,});Explicit name and description
const proxy = yield* GCP.Compute.RegionTargetHttpProxy("http", { targetHttpProxyName: "app-http", region: "us-central1", description: "public http frontend", urlMap: map.selfLink,});RegionTargetHttpsProxy
Section titled “RegionTargetHttpsProxy”Source:
src/GCP/Compute/RegionTargetHttpsProxy.ts
A regional Compute Engine target HTTPS proxy.
Regional target HTTPS proxies terminate HTTPS for regional Application Load Balancers. A forwarding rule points at the proxy; the proxy points at a regional URL map and one or more regional SSL certificates.
This resource maps to the regionTargetHttpsProxies collection (the
global targetHttpsProxies collection is GCP.Compute.TargetHttpsProxy).
Compute RegionTargetHttpsProxy has no labels field — Alchemy ownership
is stored in the description so nuke can find leaked proxies. Url map
and certificates update in place; name and region replace.
RegionTargetHttpsProxy: Creating a Regional Target HTTPS Proxy
Section titled “RegionTargetHttpsProxy: Creating a Regional Target HTTPS Proxy”const map = yield* GCP.Compute.RegionUrlMap("web", { region: "us-central1", defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "example.com", stripQuery: false, },});const cert = yield* GCP.Compute.RegionSslCertificate("tls", { region: "us-central1", certificate: pemCertificate, privateKey: pemPrivateKey,});const proxy = yield* GCP.Compute.RegionTargetHttpsProxy("https", { region: "us-central1", urlMap: map.urlMapName, sslCertificates: [cert.sslCertificateName],});RegionTargetTcpProxy
Section titled “RegionTargetTcpProxy”Source:
src/GCP/Compute/RegionTargetTcpProxy.ts
A regional Compute Engine target TCP proxy.
Regional target TCP proxies are referenced by regional forwarding rules
and point at a regional backend service. They are a component of
regional proxy Network Load Balancers. This resource maps to the
regionTargetTcpProxies collection (the global targetTcpProxies
collection is GCP.Compute.TargetTcpProxy). Compute RegionTargetTcpProxy
has no labels field and no in-place update API (setBackendService exists
only on the global collection). Alchemy ownership is stored in the
description so nuke can find leaked proxies. Changing the backend,
proxy header, description, proxyBind, or load-balancing scheme
deletes and recreates the proxy so the observed backend always matches.
RegionTargetTcpProxy: Creating a Regional Target TCP Proxy
Section titled “RegionTargetTcpProxy: Creating a Regional Target TCP Proxy”const backend = yield* GCP.Compute.RegionBackendService("tcp", { region: "us-central1", protocol: "TCP", loadBalancingScheme: "INTERNAL_MANAGED",});const proxy = yield* GCP.Compute.RegionTargetTcpProxy("tcp", { region: "us-central1", service: backend.name,});RegionUrlMap
Section titled “RegionUrlMap”Source:
src/GCP/Compute/RegionUrlMap.ts
A regional Compute Engine URL map.
Regional URL maps route hostnames and URL paths to a regional backend
service or HTTP redirect. They back internal Application Load Balancers
and regional external / internal Application Load Balancers. This
resource maps to the regionUrlMaps collection (the global urlMaps
collection is GCP.Compute.UrlMap). Compute RegionUrlMap has no labels
field — Alchemy ownership is stored in the description so nuke can find
leaked maps.
One of defaultService, defaultUrlRedirect, or
defaultRouteAction.weightedBackendServices is required.
RegionUrlMap: Creating a Regional URL Map
Section titled “RegionUrlMap: Creating a Regional URL Map”Generated name with a default HTTPS redirect
const map = yield* GCP.Compute.RegionUrlMap("web", { region: "us-central1", defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "example.com", stripQuery: false, },});Host rules and path matchers
const map = yield* GCP.Compute.RegionUrlMap("web", { description: "public https", defaultUrlRedirect: { httpsRedirect: true, stripQuery: false, }, hostRules: [{ hosts: ["example.com"], pathMatcher: "all" }], pathMatchers: [ { name: "all", defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "www.example.com", stripQuery: false, }, }, ],});Default regional backend service
const map = yield* GCP.Compute.RegionUrlMap("web", { defaultService: backend.selfLink,});Reservation
Section titled “Reservation”Source:
src/GCP/Compute/Reservation.ts
A zonal Compute Engine capacity reservation.
Reservations hold VM capacity in a zone even when the reserved VMs are
not running. Compute Engine has no labels on this resource, so Alchemy
stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find
them.
Name, zone, machine shape, specificReservationRequired, and
deploymentType are immutable — changing them replaces the reservation.
specificReservation.count resizes in place. Description and share
settings update in place via reservations.patch.
Reservation: Creating a Reservation
Section titled “Reservation: Creating a Reservation”One n1-standard-1 in the default zone
const reserved = yield* GCP.Compute.Reservation("Burst", { specificReservation: { count: 1, instanceProperties: { machineType: "n1-standard-1" }, }, specificReservationRequired: true,});Named reservation with a description
const reserved = yield* GCP.Compute.Reservation("Burst", { reservationName: "app-burst", zone: "us-central1-a", description: "on-demand burst capacity", specificReservation: { count: 2, instanceProperties: { machineType: "n1-standard-1" }, },});Reservation: Resizing a Reservation
Section titled “Reservation: Resizing a Reservation”const reserved = yield* GCP.Compute.Reservation("Burst", { reservationName: "app-burst", specificReservation: { count: 4, instanceProperties: { machineType: "n1-standard-1" }, },});ResourcePolicy
Section titled “ResourcePolicy”Source:
src/GCP/Compute/ResourcePolicy.ts
A regional Compute Engine resource policy.
Resource policies schedule snapshots, start/stop VMs, or describe
placement. Compute Engine has no labels on this resource, so Alchemy
stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find
them.
Name, region, and policy kind (snapshotSchedulePolicy vs
instanceSchedulePolicy vs placement/workload/consistency) are
immutable — changing them replaces the policy. Description and the
nested snapshot / instance schedules update in place via
resourcePolicies.patch.
ResourcePolicy: Creating a Resource Policy
Section titled “ResourcePolicy: Creating a Resource Policy”Daily snapshot schedule
const nightly = yield* GCP.Compute.ResourcePolicy("Nightly", { snapshotSchedulePolicy: { schedule: { dailySchedule: { daysInCycle: 1, startTime: "04:00" }, }, retentionPolicy: { maxRetentionDays: 7 }, },});Named policy with labels in the snapshot properties
const backups = yield* GCP.Compute.ResourcePolicy("Backups", { resourcePolicyName: "app-disk-nightly", region: "us-central1", description: "nightly disk snapshots", snapshotSchedulePolicy: { schedule: { dailySchedule: { daysInCycle: 1, startTime: "04:00" }, }, retentionPolicy: { maxRetentionDays: 14, onSourceDiskDelete: "KEEP_AUTO_SNAPSHOTS", }, snapshotProperties: { storageLocations: ["us"], labels: { env: "prod" }, }, },});ResourcePolicy: Instance Schedules
Section titled “ResourcePolicy: Instance Schedules”const hours = yield* GCP.Compute.ResourcePolicy("OfficeHours", { instanceSchedulePolicy: { timeZone: "America/Chicago", vmStartSchedule: { schedule: "0 8 * * 1-5" }, vmStopSchedule: { schedule: "0 18 * * 1-5" }, },});RolloutPlan
Section titled “RolloutPlan”Source:
src/GCP/Compute/RolloutPlan.ts
A project-global Compute Engine rollout plan.
Rollout plans divide a large change (for example a global VM extension policy) into waves. Compute Engine has no labels and no update method on this resource, so Alchemy stamps ownership into the description and treats name, scope, description, and waves as replacement triggers.
RolloutPlan: Creating a Rollout Plan
Section titled “RolloutPlan: Creating a Rollout Plan”Single-wave zonal plan
const plan = yield* GCP.Compute.RolloutPlan("Fleet", { waves: [ { displayName: "central", selectors: [ { locationSelector: { includedLocations: ["us-central1-a"], }, }, ], validation: { type: "time", timeBasedValidationMetadata: { waitDuration: "0s" }, }, }, ],});Named plan with a description
const plan = yield* GCP.Compute.RolloutPlan("Fleet", { rolloutPlanName: "ops-agent-rollout", description: "ops-agent canary", locationScope: "ZONAL", waves: [ { selectors: [ { locationSelector: { includedLocations: ["us-central1-a", "us-central1-b"], }, }, ], validation: { type: "manual" }, }, ],});Source:
src/GCP/Compute/Route.ts
A VPC static route.
Routes tell instances where to send packets whose destination matches
destRange. Compute Engine has no update API for routes — every
user-facing field is immutable and changing it replaces the resource.
Ownership is stamped into the description because routes have no labels.
Route: Creating a Route
Section titled “Route: Creating a Route”Default internet route on the default network
const route = yield* GCP.Compute.Route("internet", { destRange: "0.0.0.0/0", network: "default", nextHopGateway: "default-internet-gateway",});Named route with priority and tags
const route = yield* GCP.Compute.Route("tagged", { routeName: "app-egress", destRange: "192.0.2.0/24", network: "default", nextHopGateway: "default-internet-gateway", priority: 100, tags: ["egress"], description: "test-net egress",});Next hop IP
const route = yield* GCP.Compute.Route("appliance", { destRange: "10.200.0.0/16", network: "default", nextHopIp: "10.128.0.5",});Router
Section titled “Router”Source:
src/GCP/Compute/Router.ts
A regional Cloud Router.
Cloud Routers advertise VPC routes over BGP to VPN tunnels and
interconnects, and they host Cloud NAT. Compute Router has no labels
field — Alchemy stamps alchemy-stack / alchemy-stage / alchemy-id
into the description so list and pnpm nuke:gcp can find owned
routers.
Name, region, network, encryptedInterconnectRouter, and nccGateway
are immutable. Description and BGP (ASN, advertise mode, advertised
ranges, keepalive) and Cloud NAT gateways (nats) update in place via
routers.patch.
Router: Creating a Router
Section titled “Router: Creating a Router”Generated name on a custom-mode VPC
const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const router = yield* GCP.Compute.Router("Edge", { network: network.networkName,});Named router with BGP
const router = yield* GCP.Compute.Router("Edge", { routerName: "app-router", region: "us-central1", network: "app-vpc", description: "edge bgp", bgp: { asn: 65001, advertiseMode: "DEFAULT" },});Router: Cloud NAT
Section titled “Router: Cloud NAT”const egressIp = yield* GCP.Compute.Address("EgressIp", { addressType: "EXTERNAL",});const router = yield* GCP.Compute.Router("Nat", { network: network.networkName, nats: [ { name: "egress", sourceSubnetworkIpRangesToNat: "LIST_OF_SUBNETWORKS", subnetworks: [{ name: subnet.subnetworkName }], natIpAllocateOption: "MANUAL_ONLY", natIps: [egressIp.selfLink.as<string>()], logConfig: { enable: true, filter: "ERRORS_ONLY" }, }, ],});Router: Custom advertisements
Section titled “Router: Custom advertisements”const router = yield* GCP.Compute.Router("Edge", { network: network.networkName, bgp: { asn: 65001, advertiseMode: "CUSTOM", advertisedGroups: ["ALL_SUBNETS"], advertisedIpRanges: [ { range: "10.0.0.0/8", description: "rfc1918" }, ], },});SecurityPolicy
Section titled “SecurityPolicy”Source:
src/GCP/Compute/SecurityPolicy.ts
A global Cloud Armor security policy that filters HTTP(S) requests
targeting backend services (and, for CLOUD_ARMOR_EDGE, backend
buckets).
Type is immutable — changing it replaces the policy. Name is
immutable. Description, advanced options, Adaptive Protection,
reCAPTCHA, DDoS config, and user-defined fields update in place via
securityPolicies.patch. Rules are synced with addRule /
patchRule / removeRule (not patch). Labels are applied with
setLabels after the policy exists.
SecurityPolicy: Creating a Security Policy
Section titled “SecurityPolicy: Creating a Security Policy”Generated name with a deny rule
const policy = yield* GCP.Compute.SecurityPolicy("Armor", { description: "deny a scanner", rules: [ { action: "deny(403)", priority: 1000, description: "block scanner", match: { versionedExpr: "SRC_IPS_V1", config: { srcIpRanges: ["9.9.9.0/24"] }, }, }, ],});Named policy with labels
const policy = yield* GCP.Compute.SecurityPolicy("Armor", { securityPolicyName: "app-armor", type: "CLOUD_ARMOR", description: "prod WAF", labels: { env: "prod" },});SecurityPolicy: Advanced Options
Section titled “SecurityPolicy: Advanced Options”const policy = yield* GCP.Compute.SecurityPolicy("Armor", { advancedOptionsConfig: { jsonParsing: "STANDARD", logLevel: "VERBOSE", },});ServiceAttachment
Section titled “ServiceAttachment”Source:
src/GCP/Compute/ServiceAttachment.ts
A regional Compute Engine Private Service Connect service attachment.
A service attachment is how a producer exposes an internal load
balancer (or other target service) to consumers over Private Service
Connect. It points at a producer forwarding rule, lists NAT subnets
with purpose PRIVATE_SERVICE_CONNECT, and admits consumers either
automatically or via accept/reject lists.
Compute ServiceAttachment has no labels field — Alchemy ownership is stored in the description so nuke can find leaked attachments.
ServiceAttachment: Creating a Service Attachment
Section titled “ServiceAttachment: Creating a Service Attachment”Generated name, automatic accept
const attachment = yield* GCP.Compute.ServiceAttachment("Producer", { region: "us-central1", targetService: forwardingRule.selfLink, natSubnets: [natSubnet.selfLink], connectionPreference: "ACCEPT_AUTOMATIC", enableProxyProtocol: false,});Named attachment with labels
const attachment = yield* GCP.Compute.ServiceAttachment("Producer", { serviceAttachmentName: "app-psc", region: "us-central1", targetService: forwardingRule.selfLink, natSubnets: [natSubnet.selfLink], description: "private service connect", labels: { env: "prod" },});ServiceAttachment: Manual admission
Section titled “ServiceAttachment: Manual admission”const attachment = yield* GCP.Compute.ServiceAttachment("Producer", { targetService: forwardingRule.selfLink, natSubnets: [natSubnet.selfLink], connectionPreference: "ACCEPT_MANUAL", consumerAcceptLists: [ { projectIdOrNum: "my-consumer-project", connectionLimit: 10 }, ], reconcileConnections: true,});Snapshot
Section titled “Snapshot”Source:
src/GCP/Compute/Snapshot.ts
A global Compute Engine persistent-disk snapshot.
Snapshots are created from a source disk (or instant snapshot). Name,
source, type, storage locations, chain name, and description are
immutable — changing them replaces the snapshot. Labels are updated
in place via snapshots.setLabels.
Snapshot: Creating a Snapshot
Section titled “Snapshot: Creating a Snapshot”Snapshot of a disk
const disk = yield* GCP.Compute.Disk("data", { zone: "us-central1-a", sizeGb: 10,});const snapshot = yield* GCP.Compute.Snapshot("nightly", { sourceDisk: disk.selfLink,});Explicit name, archive type, and labels
const snapshot = yield* GCP.Compute.Snapshot("nightly", { snapshotName: "app-data-nightly", sourceDisk: "zones/us-central1-a/disks/app-data", snapshotType: "ARCHIVE", storageLocations: ["us-central1"], labels: { env: "prod" },});SslCertificate
Section titled “SslCertificate”Source:
src/GCP/Compute/SslCertificate.ts
A global Compute Engine SSL certificate for HTTPS / SSL load balancing.
Maps to the global sslCertificates collection (regionSslCertificates
is a separate resource). Certificates cannot be updated in place — every
user-facing field is immutable and changing it replaces the resource.
Compute SSL certificates have no labels field, so Alchemy stamps
ownership into the description for list / nuke.
SslCertificate: Creating a Self-Managed Certificate
Section titled “SslCertificate: Creating a Self-Managed Certificate”Generated name
const cert = yield* GCP.Compute.SslCertificate("Frontend", { certificate: pemCertificate, privateKey: pemPrivateKey,});Named certificate with a description
const cert = yield* GCP.Compute.SslCertificate("Frontend", { sslCertificateName: "app-frontend-tls", description: "prod frontend", certificate: pemCertificate, privateKey: pemPrivateKey,});SslCertificate: Google-Managed Certificates
Section titled “SslCertificate: Google-Managed Certificates”const cert = yield* GCP.Compute.SslCertificate("Frontend", { type: "MANAGED", managed: { domains: ["www.example.com"] },});SslPolicy
Section titled “SslPolicy”Source:
src/GCP/Compute/SslPolicy.ts
A global Compute Engine SSL policy for HTTPS and SSL load balancing.
SSL policies control the TLS versions and cipher suites offered by
Application Load Balancers and proxy Network Load Balancers. This
resource maps to the global sslPolicies collection
(regionSslPolicies is a separate resource). Compute SslPolicy has no
labels field — Alchemy ownership is stored in the description so nuke
can find leaked policies.
SslPolicy: Creating an SSL Policy
Section titled “SslPolicy: Creating an SSL Policy”Generated name (COMPATIBLE, TLS 1.0)
const policy = yield* GCP.Compute.SslPolicy("Frontend", {});Modern profile and TLS 1.2
const policy = yield* GCP.Compute.SslPolicy("Frontend", { description: "prod frontend", profile: "MODERN", minTlsVersion: "TLS_1_2",});SslPolicy: Custom Cipher Suites
Section titled “SslPolicy: Custom Cipher Suites”const policy = yield* GCP.Compute.SslPolicy("Frontend", { profile: "CUSTOM", minTlsVersion: "TLS_1_2", customFeatures: [ "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256", "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256", ],});StartInstance
Section titled “StartInstance”Source:
src/GCP/Compute/StartInstance.ts
Runtime binding for Compute Engine instances.start.
Bind this operation to an Instance in a Function/Action init phase.
Provide StartInstanceHttp.
StartInstance: Instance Lifecycle Control
Section titled “StartInstance: Instance Lifecycle Control”const startInstance = yield* GCP.Compute.StartInstance(vm);yield* startInstance();StartInstanceHttp
Section titled “StartInstanceHttp”Source:
src/GCP/Compute/StartInstanceHttp.tsKind: Layer · Provides:GCP.Compute.StartInstance
HTTP implementation of StartInstance.
Grants roles/compute.instanceAdmin.v1 on the bound instance only,
because no narrower predefined role contains compute.instances.start.
StopInstance
Section titled “StopInstance”Source:
src/GCP/Compute/StopInstance.ts
Runtime binding for Compute Engine instances.stop.
Bind this operation to an Instance in a Function/Action init phase.
Provide StopInstanceHttp.
StopInstance: Instance Lifecycle Control
Section titled “StopInstance: Instance Lifecycle Control”const stopInstance = yield* GCP.Compute.StopInstance(vm);yield* stopInstance();StopInstanceHttp
Section titled “StopInstanceHttp”Source:
src/GCP/Compute/StopInstanceHttp.tsKind: Layer · Provides:GCP.Compute.StopInstance
HTTP implementation of StopInstance.
Grants roles/compute.instanceAdmin.v1 on the bound instance only,
because no narrower predefined role contains compute.instances.stop.
StoragePool
Section titled “StoragePool”Source:
src/GCP/Compute/StoragePool.ts
A zonal Compute Engine Hyperdisk storage pool.
Storage pools pre-purchase Hyperdisk capacity, IOPS, and throughput.
Changing zone, storagePoolType, capacityProvisioningType, or
performanceProvisioningType replaces the pool. Capacity, IOPS,
throughput, labels, and description update in place.
StoragePool: Creating a Storage Pool
Section titled “StoragePool: Creating a Storage Pool”Hyperdisk Balanced pool
const pool = yield* GCP.Compute.StoragePool("disks", { storagePoolType: "hyperdisk-balanced", poolProvisionedCapacityGb: 10240, poolProvisionedIops: 10000, poolProvisionedThroughput: 1024, labels: { env: "prod" },});Named pool in a specific zone
const pool = yield* GCP.Compute.StoragePool("disks", { storagePoolName: "app-hyperdisk", zone: "us-central1-a", description: "shared hyperdisk capacity", poolProvisionedCapacityGb: 10240,});Subnetwork
Section titled “Subnetwork”Source:
src/GCP/Compute/Subnetwork.ts
A Google Compute Engine VPC subnetwork (subnet).
Subnets are regional partitions of a VPC with one primary IPv4 range and
optional secondary ranges. Compute Subnetwork has no labels field —
Alchemy stamps alchemy-stack / alchemy-stage / alchemy-id into the
description so list and pnpm nuke:gcp can identify owned subnets.
The parent VPC must be custom mode (autoCreateSubnetworks: false)
unless you are attaching to an auto-mode network’s existing range.
Subnetwork: Creating a Subnetwork
Section titled “Subnetwork: Creating a Subnetwork”Subnet in a custom-mode VPC
const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const subnet = yield* GCP.Compute.Subnetwork("Private", { network: network.networkName, ipCidrRange: "10.0.0.0/24",});Explicit name, region, and Private Google Access
const subnet = yield* GCP.Compute.Subnetwork("Private", { subnetworkName: "app-private", region: "us-central1", network: "app-vpc", ipCidrRange: "10.10.0.0/24", privateIpGoogleAccess: true, description: "application private subnet",});Subnetwork: Secondary ranges
Section titled “Subnetwork: Secondary ranges”const subnet = yield* GCP.Compute.Subnetwork("Private", { network: network.networkName, ipCidrRange: "10.10.0.0/24", secondaryIpRanges: [ { rangeName: "pods", ipCidrRange: "10.10.1.0/24" }, ],});TargetGrpcProxy
Section titled “TargetGrpcProxy”Source:
src/GCP/Compute/TargetGrpcProxy.ts
A global Compute Engine target gRPC proxy.
Target gRPC proxies are referenced by global forwarding rules with
load-balancing scheme INTERNAL_SELF_MANAGED (Traffic Director) and
point at a URL map whose backend services use protocol GRPC. This
resource maps to the global targetGrpcProxies collection. Compute
TargetGrpcProxy has no labels field — Alchemy ownership is stored in
the description so nuke can find leaked proxies.
TargetGrpcProxy: Creating a Target gRPC Proxy
Section titled “TargetGrpcProxy: Creating a Target gRPC Proxy”Generated name in front of a gRPC URL map
const backend = yield* GCP.Compute.BackendService("grpc", { protocol: "GRPC", loadBalancingScheme: "INTERNAL_SELF_MANAGED",});const map = yield* GCP.Compute.UrlMap("grpc", { defaultService: backend.selfLink,});const proxy = yield* GCP.Compute.TargetGrpcProxy("grpc", { urlMap: map.urlMapName,});Explicit name, description, and proxyless validation
const proxy = yield* GCP.Compute.TargetGrpcProxy("grpc", { targetGrpcProxyName: "app-grpc", description: "traffic director frontend", urlMap: map.selfLink, validateForProxyless: true,});TargetHttpProxy
Section titled “TargetHttpProxy”Source:
src/GCP/Compute/TargetHttpProxy.ts
A global Compute Engine target HTTP proxy.
Target HTTP proxies are referenced by global forwarding rules and point
at a URL map that routes host/path to a backend service, backend bucket,
or redirect. This resource maps to the global targetHttpProxies
collection (regionTargetHttpProxies is a separate resource). Compute
TargetHttpProxy has no labels field — Alchemy ownership is stored in the
description so nuke can find leaked proxies.
TargetHttpProxy: Creating a Target HTTP Proxy
Section titled “TargetHttpProxy: Creating a Target HTTP Proxy”Generated name in front of a URL map
const map = yield* GCP.Compute.UrlMap("web", { defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "example.com", stripQuery: false, },});const proxy = yield* GCP.Compute.TargetHttpProxy("http", { urlMap: map.urlMapName,});Explicit name and description
const proxy = yield* GCP.Compute.TargetHttpProxy("http", { targetHttpProxyName: "app-http", description: "public http frontend", urlMap: map.selfLink,});TargetHttpsProxy
Section titled “TargetHttpsProxy”Source:
src/GCP/Compute/TargetHttpsProxy.ts
A global Compute Engine target HTTPS proxy.
Target HTTPS proxies terminate HTTPS for global external Application Load Balancers, classic Application Load Balancers, cross-region internal Application Load Balancers, and Traffic Director. A forwarding rule points at the proxy; the proxy points at a URL map and one or more SSL certificates (or a Certificate Manager map).
This resource maps to the global targetHttpsProxies collection
(regionTargetHttpsProxies is a separate resource). Compute
TargetHttpsProxy has no labels field — Alchemy ownership is stored in
the description so nuke can find leaked proxies.
TargetHttpsProxy: Creating a Target HTTPS Proxy
Section titled “TargetHttpsProxy: Creating a Target HTTPS Proxy”Generated name in front of a URL map
const map = yield* GCP.Compute.UrlMap("web", { defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "example.com", stripQuery: false, },});const cert = yield* GCP.Compute.SslCertificate("tls", { certificate: pemCertificate, privateKey: pemPrivateKey,});const proxy = yield* GCP.Compute.TargetHttpsProxy("https", { urlMap: map.urlMapName, sslCertificates: [cert.sslCertificateName],});Explicit name, QUIC, and description
const proxy = yield* GCP.Compute.TargetHttpsProxy("https", { targetHttpsProxyName: "web-https", urlMap: map.selfLink, sslCertificates: [cert.selfLink], quicOverride: "ENABLE", description: "public https",});TargetHttpsProxy: Updating a Target HTTPS Proxy
Section titled “TargetHttpsProxy: Updating a Target HTTPS Proxy”const proxy = yield* GCP.Compute.TargetHttpsProxy("https", { targetHttpsProxyName: "web-https", urlMap: map.urlMapName, sslCertificates: [nextCert.sslCertificateName], quicOverride: "ENABLE",});TargetInstance
Section titled “TargetInstance”Source:
src/GCP/Compute/TargetInstance.ts
A zonal Compute Engine target instance.
Target instances terminate protocol-forwarding traffic (ESP, AH, TCP,
UDP) for one or more forwarding rules. The backend VM should enable IP
forwarding (canIpForward). Compute TargetInstance has no labels field —
Alchemy ownership is stored in the description so nuke can find leaked
resources. Name, zone, instance, network, NAT policy, and description are
immutable; only securityPolicy updates in place.
TargetInstance: Creating a Target Instance
Section titled “TargetInstance: Creating a Target Instance”Generated name in front of a VM
const vm = yield* GCP.Compute.Instance("web", { zone: "us-central1-a", canIpForward: true,});const target = yield* GCP.Compute.TargetInstance("protocol", { instance: vm.instanceName, zone: vm.zone,});Explicit name, description, and network
const target = yield* GCP.Compute.TargetInstance("protocol", { targetInstanceName: "app-protocol", description: "esp frontend", instance: vm.selfLink, zone: "us-central1-a", network: "default", natPolicy: "NO_NAT",});TargetPool
Section titled “TargetPool”Source:
src/GCP/Compute/TargetPool.ts
A regional Compute Engine target pool.
Target pools are the backend for external network load balancers (target-pool forwarding rules). Members are zonal instances in the same region. Health checking uses legacy HttpHealthCheck resources only. Compute TargetPool has no labels field — Alchemy ownership is stored in the description so nuke can find leaked pools.
TargetPool: Creating a Target Pool
Section titled “TargetPool: Creating a Target Pool”Generated name
const pool = yield* GCP.Compute.TargetPool("backends", {});Named pool with session affinity
const pool = yield* GCP.Compute.TargetPool("backends", { targetPoolName: "app-nlb", region: "us-central1", sessionAffinity: "CLIENT_IP", description: "network load balancer",});TargetPool: Failover
Section titled “TargetPool: Failover”const backup = yield* GCP.Compute.TargetPool("failover", {});const primary = yield* GCP.Compute.TargetPool("backends", { backupPool: backup.selfLink, failoverRatio: 0.5,});TargetPool: Instances
Section titled “TargetPool: Instances”const pool = yield* GCP.Compute.TargetPool("backends", { instances: [ "projects/{project}/zones/us-central1-a/instances/web-1", "us-central1-b/web-2", ],});TargetSslProxy
Section titled “TargetSslProxy”Source:
src/GCP/Compute/TargetSslProxy.ts
A global Compute Engine target SSL proxy.
Target SSL proxies terminate SSL/TLS for Proxy Network Load Balancers
(SSL proxy). A forwarding rule points at the proxy; the proxy points at
a backend service (protocol SSL) and one or more SSL certificates (or
a Certificate Manager map).
This resource maps to the global targetSslProxies collection. Compute
TargetSslProxy has no labels field — Alchemy ownership is stored in the
description so nuke can find leaked proxies. Description is immutable
after create.
TargetSslProxy: Creating a Target SSL Proxy
Section titled “TargetSslProxy: Creating a Target SSL Proxy”Generated name in front of an SSL backend
const check = yield* GCP.Compute.HealthCheck("ssl", { type: "TCP", tcpHealthCheck: { port: 443 },});const backend = yield* GCP.Compute.BackendService("ssl", { protocol: "SSL", healthChecks: [check.selfLink],});const cert = yield* GCP.Compute.SslCertificate("tls", { certificate: pemCertificate, privateKey: pemPrivateKey,});const proxy = yield* GCP.Compute.TargetSslProxy("ssl", { service: backend.name, sslCertificates: [cert.sslCertificateName],});Explicit name, PROXY protocol, and description
const proxy = yield* GCP.Compute.TargetSslProxy("ssl", { targetSslProxyName: "web-ssl", service: backend.selfLink, sslCertificates: [cert.selfLink], proxyHeader: "PROXY_V1", description: "public ssl",});TargetSslProxy: Updating a Target SSL Proxy
Section titled “TargetSslProxy: Updating a Target SSL Proxy”const proxy = yield* GCP.Compute.TargetSslProxy("ssl", { targetSslProxyName: "web-ssl", service: nextBackend.name, sslCertificates: [nextCert.sslCertificateName], proxyHeader: "PROXY_V1",});TargetTcpProxy
Section titled “TargetTcpProxy”Source:
src/GCP/Compute/TargetTcpProxy.ts
A global Compute Engine target TCP proxy.
Target TCP proxies are referenced by global forwarding rules and point
at a backend service. They are a component of Proxy Network Load
Balancers (classic and global external). This resource maps to the
global targetTcpProxies collection (regionTargetTcpProxies is a
separate resource). Compute TargetTcpProxy has no labels field —
Alchemy ownership is stored in the description so nuke can find leaked
proxies.
The API can update the backend service and proxy header in place.
targetTcpProxyName, description, proxyBind, and
loadBalancingScheme replace the resource.
TargetTcpProxy: Creating a Target TCP Proxy
Section titled “TargetTcpProxy: Creating a Target TCP Proxy”Generated name in front of a TCP backend service
const backend = yield* GCP.Compute.BackendService("tcp", { protocol: "TCP", loadBalancingScheme: "EXTERNAL",});const proxy = yield* GCP.Compute.TargetTcpProxy("tcp", { service: backend.name,});Explicit name, PROXY protocol, and description
const proxy = yield* GCP.Compute.TargetTcpProxy("tcp", { targetTcpProxyName: "app-tcp", description: "public tcp frontend", service: backend.selfLink, proxyHeader: "PROXY_V1",});TargetTcpProxy: Updating a Target TCP Proxy
Section titled “TargetTcpProxy: Updating a Target TCP Proxy”const proxy = yield* GCP.Compute.TargetTcpProxy("tcp", { targetTcpProxyName: "app-tcp", service: otherBackend.name, proxyHeader: "PROXY_V1",});TargetVpnGateway
Section titled “TargetVpnGateway”Source:
src/GCP/Compute/TargetVpnGateway.ts
A regional Compute Engine Classic VPN gateway (targetVpnGateway).
Classic VPN attaches a single gateway to a VPC in one region. Prefer
HA VPN (VpnGateway) for new deployments. Labels are the only
in-place update (targetVpnGateways.setLabels); name, region,
network, and description replace the gateway.
TargetVpnGateway: Creating a TargetVpnGateway
Section titled “TargetVpnGateway: Creating a TargetVpnGateway”Generated name on a custom VPC
const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const gateway = yield* GCP.Compute.TargetVpnGateway("Gateway", { network: network.networkName,});Named gateway with labels
const gateway = yield* GCP.Compute.TargetVpnGateway("Gateway", { targetVpnGatewayName: "app-classic-vpn", region: "us-central1", network: "default", description: "classic vpn", labels: { env: "prod" },});UrlMap
Section titled “UrlMap”Source:
src/GCP/Compute/UrlMap.ts
A global Compute Engine URL map.
URL maps route hostnames and URL paths to a backend service, backend
bucket, or HTTP redirect. This resource maps to the global urlMaps
collection (regionUrlMaps is a separate resource). Compute UrlMap has
no labels field — Alchemy ownership is stored in the description so nuke
can find leaked maps.
One of defaultService, defaultUrlRedirect, or
defaultRouteAction.weightedBackendServices is required.
UrlMap: Creating a URL Map
Section titled “UrlMap: Creating a URL Map”Generated name with a default HTTPS redirect
const map = yield* GCP.Compute.UrlMap("web", { defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "example.com", stripQuery: false, },});Host rules and path matchers
const map = yield* GCP.Compute.UrlMap("web", { description: "public https", defaultUrlRedirect: { httpsRedirect: true, stripQuery: false, }, hostRules: [{ hosts: ["example.com"], pathMatcher: "all" }], pathMatchers: [ { name: "all", defaultUrlRedirect: { httpsRedirect: true, hostRedirect: "www.example.com", stripQuery: false, }, }, ],});Default backend service
const map = yield* GCP.Compute.UrlMap("web", { defaultService: backend.selfLink,});VpnGateway
Section titled “VpnGateway”Source:
src/GCP/Compute/VpnGateway.ts
A regional Compute Engine HA VPN gateway.
HA VPN is a high-availability Cloud VPN that attaches two interfaces
to a VPC in a single region. Labels are the only in-place update
(vpnGateways.setLabels); name, region, network, description, IP
version, stack type, and interconnect attachments replace the
gateway.
VpnGateway: Creating a VpnGateway
Section titled “VpnGateway: Creating a VpnGateway”Generated name on a custom VPC
const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const gateway = yield* GCP.Compute.VpnGateway("Gateway", { network: network.networkName,});Named gateway with labels
const gateway = yield* GCP.Compute.VpnGateway("Gateway", { vpnGatewayName: "app-vpn", region: "us-central1", network: "default", description: "ha vpn", labels: { env: "prod" },});VpnGateway: Dual-stack HA VPN
Section titled “VpnGateway: Dual-stack HA VPN”const gateway = yield* GCP.Compute.VpnGateway("Gateway", { network: "default", stackType: "IPV4_IPV6",});VpnTunnel
Section titled “VpnTunnel”Source:
src/GCP/Compute/VpnTunnel.ts
A regional Compute Engine Cloud VPN tunnel.
HA VPN tunnels attach to a VpnGateway plus a Cloud Router and a
peer (peerExternalGateway or peerGcpGateway). Classic VPN
tunnels attach to a TargetVpnGateway and a peerIp. Labels are
the only in-place update (vpnTunnels.setLabels); every other
field replaces the tunnel.
VpnTunnel: Creating an HA VPN tunnel
Section titled “VpnTunnel: Creating an HA VPN tunnel”HA VPN to an external peer
const network = yield* GCP.Compute.Network("Vpc", { autoCreateSubnetworks: false,});const gateway = yield* GCP.Compute.VpnGateway("Gateway", { network: network.networkName,});const router = yield* GCP.Compute.Router("Edge", { network: network.networkName, bgp: { asn: 64514 },});const peer = yield* GCP.Compute.ExternalVpnGateway("Peer", { redundancyType: "SINGLE_IP_INTERNALLY_REDUNDANT", interfaces: [{ id: 0, ipAddress: "15.0.0.120" }],});const tunnel = yield* GCP.Compute.VpnTunnel("Tunnel", { vpnGateway: gateway.vpnGatewayName, vpnGatewayInterface: 0, peerExternalGateway: peer.externalVpnGatewayName, peerExternalGatewayInterface: 0, router: router.routerName, sharedSecret: "replace-me-with-a-secret",});Named tunnel with labels
const tunnel = yield* GCP.Compute.VpnTunnel("Tunnel", { vpnTunnelName: "app-tunnel", region: "us-central1", vpnGateway: "app-vpn", vpnGatewayInterface: 0, peerGcpGateway: "peer-vpn", router: "app-router", sharedSecret: "replace-me-with-a-secret", labels: { env: "prod" },});VpnTunnel: Classic VPN
Section titled “VpnTunnel: Classic VPN”const tunnel = yield* GCP.Compute.VpnTunnel("Tunnel", { targetVpnGateway: gateway.targetVpnGatewayName, peerIp: "15.0.0.120", sharedSecret: "replace-me-with-a-secret", localTrafficSelector: ["10.0.0.0/16"], remoteTrafficSelector: ["172.16.0.0/16"],});WireGroup
Section titled “WireGroup”Source:
src/GCP/Compute/WireGroup.ts
A global Compute Engine wire group on a cross-site network.
Wire groups connect Interconnect endpoints across metros. Compute Engine
has no labels on this resource, so Alchemy stamps ownership into the
description so list / pnpm nuke:gcp can find them.
Name and parent crossSiteNetwork are immutable — changing them
replaces the group. adminEnabled, wireProperties, endpoints, and
description update in place via wireGroups.patch.
WireGroup: Creating a Wire Group
Section titled “WireGroup: Creating a Wire Group”const wires = yield* GCP.Compute.WireGroup("metro", { crossSiteNetwork: network.crossSiteNetworkName, description: "nyc-to-sfo", wireProperties: { bandwidthUnmetered: "10", bandwidthAllocation: "SHARED_WITH_WIRE_GROUP", }, endpoints: { nyc: { interconnects: { a: { interconnect: "global/interconnects/nyc-a", vlanTags: [100] }, }, }, sfo: { interconnects: { a: { interconnect: "global/interconnects/sfo-a", vlanTags: [100] }, }, }, },});ZoneVmExtensionPolicy
Section titled “ZoneVmExtensionPolicy”Source:
src/GCP/Compute/ZoneVmExtensionPolicy.ts
A zonal Compute Engine VM extension policy.
Zone VM extension policies install Google-provided extensions (Ops
Agent, SAP, workload) on VMs that match label selectors. Compute Engine
has no labels on this resource, so Alchemy stamps ownership into the
description so list / pnpm nuke:gcp can find them.
Name and zone are immutable — changing them replaces the policy.
Description, priority, selectors, and extension configurations update
in place via zoneVmExtensionPolicies.patch.
ZoneVmExtensionPolicy: Creating a Zone VM Extension Policy
Section titled “ZoneVmExtensionPolicy: Creating a Zone VM Extension Policy”Install Ops Agent on labeled VMs
const policy = yield* GCP.Compute.ZoneVmExtensionPolicy("Ops", { zone: "us-central1-a", extensionPolicies: { "ops-agent": { pinnedVersion: "2.58.0" }, }, instanceSelectors: [ { labelSelector: { inclusionLabels: { env: "prod" } } }, ],});Named policy with a description
const policy = yield* GCP.Compute.ZoneVmExtensionPolicy("Ops", { vmExtensionPolicyName: "ops-agent-prod", description: "ops-agent for prod VMs", priority: 500, extensionPolicies: { "ops-agent": {} }, instanceSelectors: [ { labelSelector: { inclusionLabels: { role: "app" } } }, ],});