Skip to content

GCP.Compute reference

Source: src/GCP/Compute/Address.ts

A regional Compute Engine static IP address.

Reserves a regional internal or external IP. Labels are the only in-place update (addresses.setLabels); name, region, IP, type, version, purpose, network, subnetwork, prefix length, and description replace the address.

Generated name

const ip = yield* GCP.Compute.Address("Ingress", {});

Named address with labels

const ip = yield* GCP.Compute.Address("Ingress", {
addressName: "app-ingress",
region: "us-central1",
addressType: "EXTERNAL",
networkTier: "PREMIUM",
labels: { env: "prod" },
});
const ip = yield* GCP.Compute.Address("ServiceIp", {
region: "us-central1",
addressType: "INTERNAL",
subnetwork:
"projects/my-project/regions/us-central1/subnetworks/default",
purpose: "GCE_ENDPOINT",
});

Source: src/GCP/Compute/Autoscaler.ts

A zonal Compute Engine autoscaler for a managed instance group.

Changing autoscalerName or zone replaces the autoscaler. Policy, target, description, and labels update in place via autoscalers.patch. Compute Engine has no labels on this resource, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

CPU policy with generated name

const scaler = yield* GCP.Compute.Autoscaler("Web", {
target: mig.selfLink,
autoscalingPolicy: {
minNumReplicas: 1,
maxNumReplicas: 5,
coolDownPeriodSec: 60,
cpuUtilization: { utilizationTarget: 0.6 },
},
});

Named autoscaler, labels, and OFF mode

const scaler = yield* GCP.Compute.Autoscaler("Web", {
autoscalerName: "web-scaler",
zone: "us-central1-a",
target: "web-mig",
description: "scale the web MIG",
labels: { env: "prod" },
autoscalingPolicy: {
minNumReplicas: 0,
maxNumReplicas: 3,
mode: "OFF",
cpuUtilization: { utilizationTarget: 0.5 },
},
});

Source: src/GCP/Compute/BackendBucket.ts

A global Compute Engine backend bucket that fronts a Cloud Storage bucket for HTTP(S) load balancing.

Compute Engine backend buckets have no labels field, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

Generated name in front of a Storage bucket

const assets = yield* GCP.Storage.Bucket("assets", {
forceDestroy: true,
});
const backend = yield* GCP.Compute.BackendBucket("cdn", {
bucketName: assets.bucketName,
description: "static assets",
});

Explicit name with Cloud CDN

const backend = yield* GCP.Compute.BackendBucket("cdn", {
name: "app-static",
bucketName: assets.bucketName,
enableCdn: true,
compressionMode: "AUTOMATIC",
customResponseHeaders: ["X-Frame-Options: DENY"],
});

Source: src/GCP/Compute/BackendService.ts

A global Compute Engine backend service. Backend services define how Google Cloud load balancers distribute traffic — protocol, timeout, session affinity, health checks, and the backends themselves.

Compute Engine backend services have no labels field, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

BackendService: Creating a Backend Service

Section titled “BackendService: Creating a Backend Service”

Generated name

const backend = yield* GCP.Compute.BackendService("web", {
protocol: "HTTP",
});

Explicit name, timeout, and labels

const backend = yield* GCP.Compute.BackendService("web", {
name: "web-backend",
protocol: "HTTP",
loadBalancingScheme: "EXTERNAL",
timeoutSec: 30,
enableCDN: true,
labels: { env: "prod" },
});

BackendService: Updating a Backend Service

Section titled “BackendService: Updating a Backend Service”
const backend = yield* GCP.Compute.BackendService("web", {
name: "web-backend",
timeoutSec: 60,
enableCDN: true,
});

Source: src/GCP/Compute/CrossSiteNetwork.ts

A global Compute Engine cross-site network.

Cross-site networks group Wire Groups that connect on-premises and cloud sites through Cross-Cloud Interconnect. The resource itself is a named container — Wire Groups attach later. Compute has no labels field, so Alchemy stamps ownership into the description.

CrossSiteNetwork: Creating a Cross-Site Network

Section titled “CrossSiteNetwork: Creating a Cross-Site Network”

Generated name

const network = yield* GCP.Compute.CrossSiteNetwork("backbone", {});

Named network with a description

const network = yield* GCP.Compute.CrossSiteNetwork("backbone", {
crossSiteNetworkName: "prod-backbone",
description: "cross-cloud interconnect fabric",
});

Source: src/GCP/Compute/Disk.ts

A zonal Compute Engine persistent disk.

Changing zone, type, diskName, sourceImage, sourceSnapshot, sourceDisk, architecture, physicalBlockSizeBytes, or enableConfidentialCompute replaces the disk. Growing sizeGb is applied in place via disks.resize; shrinking it replaces the disk.

Generated name

const disk = yield* GCP.Compute.Disk("data", {});

Explicit name, type, size, and labels

const disk = yield* GCP.Compute.Disk("data", {
diskName: "app-data",
zone: "us-central1-a",
type: "pd-balanced",
sizeGb: 20,
labels: { env: "prod" },
});
const disk = yield* GCP.Compute.Disk("data", {
diskName: "app-data",
sizeGb: 50,
});

Source: src/GCP/Compute/ExternalVpnGateway.ts

A global Compute Engine external VPN gateway — the on-premises or other-cloud peer that an HA VPN gateway connects to.

Labels are the only in-place update (externalVpnGateways.setLabels). Name, description, redundancy type, and interfaces replace the gateway.

ExternalVpnGateway: Creating an ExternalVpnGateway

Section titled “ExternalVpnGateway: Creating an ExternalVpnGateway”

Generated name with two peer IPs

const peer = yield* GCP.Compute.ExternalVpnGateway("Peer", {
redundancyType: "TWO_IPS_REDUNDANCY",
interfaces: [
{ id: 0, ipAddress: "203.0.113.1" },
{ id: 1, ipAddress: "203.0.113.2" },
],
});

Named gateway with labels

const peer = yield* GCP.Compute.ExternalVpnGateway("Peer", {
externalVpnGatewayName: "onprem-vpn",
description: "on-prem peer",
redundancyType: "SINGLE_IP_INTERNALLY_REDUNDANT",
interfaces: [{ id: 0, ipAddress: "203.0.113.10" }],
labels: { env: "prod" },
});

Source: src/GCP/Compute/Firewall.ts

A VPC firewall rule that allows or denies ingress/egress traffic for instances on a network.

Compute Engine firewalls have no resource labels. Alchemy stamps ownership (alchemy-stack / alchemy-stage / alchemy-id) into the description so read and list (and pnpm nuke:gcp) can find them.

Name, network, direction, and allow-vs-deny are immutable — changing any of them replaces the rule.

Generated name, HTTP from a private range

const http = yield* GCP.Compute.Firewall("AllowHttp", {
allowed: [{ protocol: "tcp", ports: ["80"] }],
sourceRanges: ["10.0.0.0/8"],
targetTags: ["web"],
});

Explicit name, HTTPS deny, logging

const deny = yield* GCP.Compute.Firewall("DenyHttps", {
firewallName: "deny-https-egress",
direction: "EGRESS",
denied: [{ protocol: "tcp", ports: ["443"] }],
destinationRanges: ["0.0.0.0/0"],
priority: 800,
logConfig: { enable: true, metadata: "INCLUDE_ALL_METADATA" },
});

Source: src/GCP/Compute/FirewallPolicy.ts

A hierarchical firewall policy attached to an organization or folder.

Policies live under locations/global/firewallPolicies and are identified by a server-assigned numeric id. The user-facing name is shortName. Parent and shortName are immutable — changing either replaces the policy. Description updates in place via firewallPolicies.patch. Rules are synced with addRule / patchRule / removeRule.

Compute Engine firewall policies have no resource labels. Alchemy stamps ownership into the description so read / list (and pnpm nuke:gcp) can find them.

FirewallPolicy: Creating a Firewall Policy

Section titled “FirewallPolicy: Creating a Firewall Policy”

Generated name with an allow rule

const policy = yield* GCP.Compute.FirewallPolicy("OrgFw", {
description: "allow internal http",
rules: [
{
action: "allow",
priority: 1000,
direction: "INGRESS",
match: {
srcIpRanges: ["10.0.0.0/8"],
layer4Configs: [{ ipProtocol: "tcp", ports: ["80"] }],
},
},
],
});

Named policy under a folder

const policy = yield* GCP.Compute.FirewallPolicy("OrgFw", {
shortName: "app-org-fw",
parent: "folders/123456789",
description: "folder guardrail",
});

Source: src/GCP/Compute/ForwardingRule.ts

A regional Compute Engine forwarding rule.

Forwarding rules are the frontend of a Google Cloud load balancer: an IP address, protocol, and port that send traffic to a target (pool, instance, HTTP(S)/TCP proxy, VPN gateway) or a backend service. This resource maps to the regional forwardingRules collection (globalForwardingRules is a separate resource).

Labels cannot be set on insert — Alchemy applies them with setLabels after the rule exists. target, allowGlobalAccess, and allowPscGlobalAccess update in place; name, region, IP, protocol, ports, scheme, network, subnetwork, backend service, and description replace the rule.

ForwardingRule: Creating a Forwarding Rule

Section titled “ForwardingRule: Creating a Forwarding Rule”

Classic Network Load Balancer frontend

const rule = yield* GCP.Compute.ForwardingRule("Frontend", {
region: "us-central1",
target: targetPool.selfLink,
portRange: "80",
});

Named rule with labels

const rule = yield* GCP.Compute.ForwardingRule("Frontend", {
forwardingRuleName: "app-frontend",
region: "us-central1",
ipProtocol: "TCP",
portRange: "80-80",
target: targetPool.selfLink,
labels: { env: "prod" },
});
const rule = yield* GCP.Compute.ForwardingRule("Ilb", {
region: "us-central1",
loadBalancingScheme: "INTERNAL",
backendService: backend.selfLink,
network: vpc.selfLink,
subnetwork: subnet.selfLink,
ipProtocol: "TCP",
ports: ["80"],
allowGlobalAccess: true,
});

Source: src/GCP/Compute/FutureReservation.ts

A zonal Compute Engine future reservation.

Future reservations lock capacity for a later delivery window. Name and zone replace the resource; description, planning status, and the time window update in place via futureReservations.patch. Compute has no labels field, so Alchemy stamps ownership into the description.

Creating a reservation typically requires quota and, for CALENDAR mode, GPU/TPU SKUs. Draft reservations (planningStatus: "DRAFT") stay off the procurement queue.

FutureReservation: Creating a Future Reservation

Section titled “FutureReservation: Creating a Future Reservation”
const reservation = yield* GCP.Compute.FutureReservation("burst", {
planningStatus: "DRAFT",
timeWindow: {
startTime: "2030-06-01T00:00:00Z",
endTime: "2030-06-08T00:00:00Z",
},
specificSkuProperties: {
totalCount: "1",
instanceProperties: { machineType: "n2-standard-2" },
},
});

Source: src/GCP/Compute/GetInstance.ts

Runtime binding for Compute Engine instances.get.

Bind this operation to an Instance in a Function/Action init phase. Provide GetInstanceHttp.

const getInstance = yield* GCP.Compute.GetInstance(vm);
const live = yield* getInstance();

Source: src/GCP/Compute/GetInstanceHttp.ts Kind: Layer · Provides: GCP.Compute.GetInstance

HTTP implementation of GetInstance.

Source: src/GCP/Compute/GlobalAddress.ts

A global Compute Engine address — a reserved anycast IP for global forwarding rules, or an internal range for VPC peering / Private Service Connect.

Labels are the only in-place update. Name, IP, type, version, purpose, network, prefix length, and description replace the address.

Generated name

const ip = yield* GCP.Compute.GlobalAddress("FrontendIp", {});

Named address with labels

const ip = yield* GCP.Compute.GlobalAddress("FrontendIp", {
addressName: "app-lb-ip",
description: "Global anycast IP for the HTTPS load balancer",
ipVersion: "IPV4",
labels: { env: "prod" },
});
const range = yield* GCP.Compute.GlobalAddress("PsaRange", {
addressType: "INTERNAL",
purpose: "VPC_PEERING",
network: "projects/my-project/global/networks/main",
prefixLength: 16,
});

Source: src/GCP/Compute/GlobalForwardingRule.ts

A global Compute Engine forwarding rule — the frontend of a global load balancer. It binds an IP and port range to a target HTTP/HTTPS proxy (or SSL/TCP/gRPC proxy, or a Private Service Connect bundle).

Labels cannot be set on insert — Alchemy applies them with setLabels after the rule exists and also stamps ownership into the description so list / pnpm nuke:gcp can find a rule if labeling is interrupted. list also includes unlabeled rules whose target is an Alchemy-owned HTTP(S) proxy. target and networkTier update in place (setTarget / patch). Name, IP, protocol, port range, description, network, and load-balancing scheme replace the rule.

GlobalForwardingRule: Creating a Global Forwarding Rule

Section titled “GlobalForwardingRule: Creating a Global Forwarding Rule”

HTTP frontend in front of a target HTTP proxy

const map = yield* GCP.Compute.UrlMap("web", {
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "example.com",
stripQuery: false,
},
});
const proxy = yield* GCP.Compute.TargetHttpProxy("http", {
urlMap: map.urlMapName,
});
const rule = yield* GCP.Compute.GlobalForwardingRule("frontend", {
target: proxy.selfLink,
portRange: "80",
});

Named rule with labels and a reserved IP

const ip = yield* GCP.Compute.GlobalAddress("FrontendIp", {});
const rule = yield* GCP.Compute.GlobalForwardingRule("frontend", {
forwardingRuleName: "app-http",
description: "public HTTP frontend",
target: proxy.selfLink,
ipAddress: ip.address,
portRange: "80",
loadBalancingScheme: "EXTERNAL",
labels: { env: "prod" },
});

GlobalForwardingRule: Updating a Global Forwarding Rule

Section titled “GlobalForwardingRule: Updating a Global Forwarding Rule”
const rule = yield* GCP.Compute.GlobalForwardingRule("frontend", {
forwardingRuleName: "app-http",
target: otherProxy.selfLink,
portRange: "80",
labels: { env: "prod", role: "edge" },
});

Source: src/GCP/Compute/GlobalNetworkEndpointGroup.ts

A global Compute Engine internet network endpoint group.

Global NEGs back internet (INTERNET_FQDN_PORT / INTERNET_IP_PORT) backends for global external Application Load Balancers. They live in the global/networkEndpointGroups collection (zonal VM NEGs and regional serverless/PSC NEGs are separate resources). The collection has no labels field and no update API — Alchemy stamps ownership into the description so list / nuke can find leaked groups. Name, type, default port, annotations, and description are immutable (changing any of them replaces the group). Endpoints attach and detach in place.

GlobalNetworkEndpointGroup: Creating a GlobalNetworkEndpointGroup

Section titled “GlobalNetworkEndpointGroup: Creating a GlobalNetworkEndpointGroup”

FQDN internet NEG

const neg = yield* GCP.Compute.GlobalNetworkEndpointGroup("Internet", {
networkEndpointType: "INTERNET_FQDN_PORT",
defaultPort: 443,
});

Explicit name and a single FQDN endpoint

const neg = yield* GCP.Compute.GlobalNetworkEndpointGroup("Internet", {
networkEndpointGroupName: "www-neg",
networkEndpointType: "INTERNET_FQDN_PORT",
defaultPort: 443,
networkEndpoints: [{ fqdn: "www.example.com", port: 443 }],
});

GlobalNetworkEndpointGroup: IP internet NEGs

Section titled “GlobalNetworkEndpointGroup: IP internet NEGs”
const neg = yield* GCP.Compute.GlobalNetworkEndpointGroup("IpNeg", {
networkEndpointType: "INTERNET_IP_PORT",
defaultPort: 443,
networkEndpoints: [{ ipAddress: "203.0.113.10", port: 443 }],
});

Source: src/GCP/Compute/GlobalPublicDelegatedPrefix.ts

A global Compute Engine public delegated prefix (BYOIP).

Delegates a CIDR from a Public Advertised Prefix so addresses and sub-prefixes can be created. Creating one requires a parent advertised prefix (Bring Your Own IP). Name, parent, CIDR, and mode replace the resource; description updates in place via patch. Compute has no labels field, so Alchemy stamps ownership into the description.

GlobalPublicDelegatedPrefix: Creating a Global Public Delegated Prefix

Section titled “GlobalPublicDelegatedPrefix: Creating a Global Public Delegated Prefix”
const prefix = yield* GCP.Compute.GlobalPublicDelegatedPrefix("byoip", {
parentPrefix:
"projects/my-project/global/publicAdvertisedPrefixes/edge",
ipCidrRange: "203.0.113.0/24",
});

Source: src/GCP/Compute/GlobalVmExtensionPolicy.ts

A project-level Compute Engine VM extension policy.

Global policies roll out guest extensions (Ops Agent, and similar) to matching VMs. Name replaces the resource; description, priority, selectors, extensions, and the rollout plan update in place. Compute has no labels field, so Alchemy stamps ownership into the description.

GlobalVmExtensionPolicy: Creating a Global VM Extension Policy

Section titled “GlobalVmExtensionPolicy: Creating a Global VM Extension Policy”

Ops Agent, fast rollout

const policy = yield* GCP.Compute.GlobalVmExtensionPolicy("ops", {
extensionPolicies: { "ops-agent": {} },
rolloutOperation: {
rolloutInput: { predefinedRolloutPlan: "FAST_ROLLOUT" },
},
});

Label-selected VMs

const policy = yield* GCP.Compute.GlobalVmExtensionPolicy("ops", {
extensionPolicies: { "ops-agent": { pinnedVersion: "2.53.0" } },
instanceSelectors: [
{ labelSelector: { inclusionLabels: { role: "web" } } },
],
priority: 100,
});

Source: src/GCP/Compute/HealthCheck.ts

A global Compute Engine health check.

Health checks probe backends for load balancing and managed-instance-group autohealing. This resource maps to the global healthChecks collection (regionHealthChecks is a separate resource). Compute HealthCheck has no labels field — Alchemy ownership is stored in the description so nuke can find leaked checks.

Generated name (HTTP on port 80)

const check = yield* GCP.Compute.HealthCheck("api", {});

HTTP path and thresholds

const check = yield* GCP.Compute.HealthCheck("api", {
description: "frontend /health",
checkIntervalSec: 10,
timeoutSec: 5,
httpHealthCheck: { port: 80, requestPath: "/health" },
});

TCP health check

const check = yield* GCP.Compute.HealthCheck("tcp", {
type: "TCP",
tcpHealthCheck: { port: 8080 },
});

Source: src/GCP/Compute/HttpHealthCheck.ts

A legacy global Compute Engine HTTP health check.

Legacy HTTP health checks are required by target-pool network load balancers. Other load balancers and MIG autohealing should use HealthCheck. Compute HttpHealthCheck has no labels field — Alchemy ownership is stored in the description so nuke can find leaked checks.

HttpHealthCheck: Creating an HTTP Health Check

Section titled “HttpHealthCheck: Creating an HTTP Health Check”

Generated name

const check = yield* GCP.Compute.HttpHealthCheck("api", {});

Path, port, and interval

const check = yield* GCP.Compute.HttpHealthCheck("api", {
description: "frontend /health",
port: 80,
requestPath: "/health",
checkIntervalSec: 10,
timeoutSec: 5,
});
const check = yield* GCP.Compute.HttpHealthCheck("api", {
requestPath: "/health",
});
const pool = yield* GCP.Compute.TargetPool("backends", {
healthChecks: [check.httpHealthCheckName],
});

Source: src/GCP/Compute/HttpsHealthCheck.ts

A legacy global Compute Engine HTTPS health check.

Legacy HTTPS health checks are deprecated for most load balancers — prefer HealthCheck with httpsHealthCheck. Compute HttpsHealthCheck has no labels field — Alchemy ownership is stored in the description so nuke can find leaked checks.

HttpsHealthCheck: Creating an HTTPS Health Check

Section titled “HttpsHealthCheck: Creating an HTTPS Health Check”

Generated name

const check = yield* GCP.Compute.HttpsHealthCheck("api", {});

Path, port, and interval

const check = yield* GCP.Compute.HttpsHealthCheck("api", {
description: "frontend /health",
port: 443,
requestPath: "/health",
checkIntervalSec: 10,
timeoutSec: 5,
});

Source: src/GCP/Compute/Image.ts

A Compute Engine custom image used to create boot disks for VMs.

Create from a disk, another image, a snapshot, or a GCS tarball. family and description update in place; labels are synced via setLabels. Source, size, architecture, licenses, and storage locations replace the image.

Image from a disk

const image = yield* GCP.Compute.Image("boot", {
sourceDisk: "projects/my-project/zones/us-central1-a/disks/my-disk",
family: "app-boot",
labels: { env: "prod" },
});

Clone a public image family

const image = yield* GCP.Compute.Image("debian", {
sourceImage: "projects/debian-cloud/global/images/family/debian-12",
storageLocations: ["us-central1"],
});
const image = yield* GCP.Compute.Image("boot", {
imageName: "app-boot-v2",
sourceDisk: "projects/my-project/zones/us-central1-a/disks/my-disk",
family: "app-boot",
description: "golden image",
labels: { env: "prod", role: "boot" },
});

Source: src/GCP/Compute/Instance.ts

A Google Compute Engine VM instance.

Generated name

const vm = yield* GCP.Compute.Instance("web", {
zone: "us-central1-a",
machineType: "e2-micro",
});

Explicit name, labels, and metadata

const vm = yield* GCP.Compute.Instance("web", {
instanceName: "web-1",
zone: "us-central1-a",
machineType: "e2-micro",
sourceImage: "projects/debian-cloud/global/images/family/debian-12",
labels: { env: "prod" },
tags: ["http-server"],
metadata: { "enable-oslogin": "TRUE" },
});
const ip = yield* GCP.Compute.Address("web-ip", { region: "us-central1" });
const data = yield* GCP.Compute.Disk("web-data", {
zone: "us-central1-a",
sizeGb: 10,
});
const vm = yield* GCP.Compute.Instance("web", {
zone: "us-central1-a",
natIP: ip.address,
attachedDisks: [{ source: data.selfLink, deviceName: "data" }],
tags: ["http-server"],
metadata: {
"startup-script": "#!/bin/bash\ncd /tmp && python3 -m http.server 80",
},
});
const start = yield* GCP.Compute.StartInstance(vm);
yield* start();

Source: src/GCP/Compute/InstanceGroup.ts

A zonal unmanaged Compute Engine instance group.

Unmanaged groups hold an explicit list of VMs and optional named ports for load balancing. They have no labels API — Alchemy records ownership in the description so list / pnpm nuke:gcp can find them.

Generated name

const group = yield* GCP.Compute.InstanceGroup("web", {
namedPorts: [{ name: "http", port: 80 }],
});

Explicit name, zone, and named ports

const group = yield* GCP.Compute.InstanceGroup("web", {
instanceGroupName: "web-backends",
zone: "us-central1-a",
description: "HTTP backends",
namedPorts: [
{ name: "http", port: 80 },
{ name: "https", port: 443 },
],
});

Source: src/GCP/Compute/InstanceGroupManager.ts

A zonal Compute Engine managed instance group (MIG).

The group creates VMs from an instance template and maintains targetSize. Alchemy records ownership in the description so list / pnpm nuke:gcp can find groups (MIGs have no labels API). Changing managerName, zone, or baseInstanceName replaces the group.

InstanceGroupManager: Creating a Managed Instance Group

Section titled “InstanceGroupManager: Creating a Managed Instance Group”

Generated name, empty group

const template = yield* GCP.Compute.InstanceTemplate("web", {});
const group = yield* GCP.Compute.InstanceGroupManager("web", {
instanceTemplate: template.templateName,
});

Named ports and target size

const template = yield* GCP.Compute.InstanceTemplate("web", {});
const group = yield* GCP.Compute.InstanceGroupManager("web", {
managerName: "web-mig",
zone: "us-central1-a",
instanceTemplate: template.templateName,
targetSize: 2,
namedPorts: [{ name: "http", port: 80 }],
});

Source: src/GCP/Compute/InstanceGroupManagerResizeRequest.ts

A zonal queued resize request on a managed instance group.

Resize requests provision additional MIG VMs immediately or by queueing until capacity is available (typically GPU / queued-provisioning machine types). Name, zone, MIG, resizeBy, and run duration replace the request — there is no in-place update. Compute has no labels field, so Alchemy stamps ownership into the description.

Delete cancels an ACCEPTED / CREATING request first, then removes the record.

InstanceGroupManagerResizeRequest: Creating a Resize Request

Section titled “InstanceGroupManagerResizeRequest: Creating a Resize Request”
const template = yield* GCP.Compute.InstanceTemplate("web", {});
const group = yield* GCP.Compute.InstanceGroupManager("web", {
instanceTemplate: template.templateName,
targetSize: 0,
});
const request = yield* GCP.Compute.InstanceGroupManagerResizeRequest(
"burst",
{
instanceGroupManager: group.managerName,
zone: group.zone,
resizeBy: 1,
requestedRunDuration: { seconds: "3600" },
},
);

Source: src/GCP/Compute/InstanceTemplate.ts

A global Compute Engine instance template.

Instance templates are immutable. Changing machine type, disks, labels, network interfaces, or other properties replaces the template. Use the template to create VMs, managed instance groups, and reservations.

Generated name with defaults

const template = yield* GCP.Compute.InstanceTemplate("web", {});

Explicit machine type, disk, and labels

const template = yield* GCP.Compute.InstanceTemplate("web", {
machineType: "e2-micro",
labels: { env: "prod" },
disks: [
{
boot: true,
autoDelete: true,
sourceImage:
"projects/debian-cloud/global/images/family/debian-12",
diskSizeGb: 10,
},
],
networkInterfaces: [{ network: "global/networks/default" }],
});

Source: src/GCP/Compute/InstantSnapshot.ts

A zonal Compute Engine instant snapshot.

Instant snapshots capture a disk’s point-in-time state in the same zone (Hyperdisk and some persistent-disk types). Name, zone, source disk, and description are immutable — changing them replaces the snapshot. Labels update in place via instantSnapshots.setLabels.

InstantSnapshot: Creating an Instant Snapshot

Section titled “InstantSnapshot: Creating an Instant Snapshot”

Snapshot of a disk

const disk = yield* GCP.Compute.Disk("data", {
zone: "us-central1-a",
type: "pd-balanced",
sizeGb: 10,
});
const snap = yield* GCP.Compute.InstantSnapshot("checkpoint", {
sourceDisk: disk.selfLink,
zone: disk.zone,
});

Named snapshot with labels

const snap = yield* GCP.Compute.InstantSnapshot("checkpoint", {
instantSnapshotName: "app-data-now",
zone: "us-central1-a",
sourceDisk: "zones/us-central1-a/disks/app-data",
labels: { env: "prod" },
});

Source: src/GCP/Compute/InstantSnapshotGroup.ts

A zonal Compute Engine instant snapshot group.

Captures a point-in-time state of every disk in a consistency group. Name, zone, and source policy replace the group. Compute has no labels field, so Alchemy stamps ownership into the description.

InstantSnapshotGroup: Creating an Instant Snapshot Group

Section titled “InstantSnapshotGroup: Creating an Instant Snapshot Group”
const policy = yield* GCP.Compute.ResourcePolicy("consistent", {
diskConsistencyGroupPolicy: {},
});
const group = yield* GCP.Compute.InstantSnapshotGroup("checkpoint", {
zone: "us-central1-a",
sourceConsistencyGroup: policy.selfLink,
});

Source: src/GCP/Compute/Interconnect.ts

A global Compute Engine Dedicated Interconnect.

Dedicated Interconnect is a physical connection between your on-premises network and Google’s network at a colocation facility. Name, location, interconnect type, link type, customer name, remote location, and requested features are immutable. Description, admin status, link count, NOC email, and MACsec update in place via interconnects.patch. Labels are applied with setLabels after the interconnect exists.

Dedicated 10G interconnect

const interconnect = yield* GCP.Compute.Interconnect("OnPrem", {
location: "iad-zone1-1",
interconnectType: "DEDICATED",
linkType: "LINK_TYPE_ETHERNET_10G_LR",
requestedLinkCount: 1,
customerName: "Example Corp",
description: "prod interconnect",
});

Named interconnect with labels

const interconnect = yield* GCP.Compute.Interconnect("OnPrem", {
interconnectName: "app-ix",
location: "iad-zone1-1",
customerName: "Example Corp",
labels: { env: "prod" },
});

Source: src/GCP/Compute/InterconnectAttachment.ts

A regional Compute Engine Interconnect VLAN attachment.

VLAN attachments connect a Cloud Router to a Dedicated or Partner Interconnect. Name, region, router, type, interconnect, encryption, VLAN tag, and availability domain are immutable. Description, admin status, bandwidth, MTU, and stack type update in place via interconnectAttachments.patch. Labels are applied with setLabels after the attachment exists.

InterconnectAttachment: Creating an Interconnect Attachment

Section titled “InterconnectAttachment: Creating an Interconnect Attachment”

Partner attachment

const attachment = yield* GCP.Compute.InterconnectAttachment("Vlan", {
region: "us-central1",
router: router.routerName,
type: "PARTNER",
edgeAvailabilityDomain: "AVAILABILITY_DOMAIN_1",
mtu: 1500,
});

Dedicated attachment

const attachment = yield* GCP.Compute.InterconnectAttachment("Vlan", {
interconnectAttachmentName: "app-vlan",
router: router.selfLink,
type: "DEDICATED",
interconnect: interconnect.selfLink,
vlanTag8021q: 100,
bandwidth: "BPS_1G",
});

Source: src/GCP/Compute/InterconnectAttachmentGroup.ts

A global Compute Engine Interconnect attachment group.

Groups collect VLAN attachments so GCP can report the availability SLA they actually provide. Name is immutable. Description, intent, member attachments, and the optional InterconnectGroup URL update in place via interconnectAttachmentGroups.patch. Compute InterconnectAttachmentGroup has no labels field — Alchemy stamps ownership into the description so nuke can find leaked groups.

InterconnectAttachmentGroup: Creating an Attachment Group

Section titled “InterconnectAttachmentGroup: Creating an Attachment Group”

Generated name, no SLA

const group = yield* GCP.Compute.InterconnectAttachmentGroup("Vlans", {
description: "dev vlan attachments",
intent: { availabilitySla: "NO_SLA" },
});

Named group with a member attachment

const group = yield* GCP.Compute.InterconnectAttachmentGroup("Vlans", {
interconnectAttachmentGroupName: "app-vlan-group",
intent: { availabilitySla: "PRODUCTION_NON_CRITICAL" },
attachments: {
primary: { attachment: attachment.selfLink },
},
});

Source: src/GCP/Compute/InterconnectGroup.ts

A global Compute Engine Interconnect group.

Groups collect Dedicated Interconnects so GCP can report the topology capability (SLA) they actually provide. Name is immutable. Description, intent, and member interconnects update in place via interconnectGroups.patch. Compute InterconnectGroup has no labels field — Alchemy stamps ownership into the description so nuke can find leaked groups.

InterconnectGroup: Creating an Interconnect Group

Section titled “InterconnectGroup: Creating an Interconnect Group”

Generated name, no SLA

const group = yield* GCP.Compute.InterconnectGroup("Bundle", {
description: "dev interconnects",
intent: { topologyCapability: "NO_SLA" },
});

Named group with a member interconnect

const group = yield* GCP.Compute.InterconnectGroup("Bundle", {
interconnectGroupName: "app-ix-group",
intent: { topologyCapability: "PRODUCTION_NON_CRITICAL" },
interconnects: {
primary: { interconnect: interconnect.selfLink },
},
});

Source: src/GCP/Compute/License.ts

A global Compute Engine License.

Licenses are intended for third-party partners who publish Cloud Marketplace images. Name and osLicense are immutable. Description and the attachability flags update in place via licenses.update. Compute License has no labels field — Alchemy stamps ownership into the description so nuke can find leaked licenses.

Generated name

const license = yield* GCP.Compute.License("ImageLicense", {
description: "marketplace os",
transferable: true,
});

Named OS license

const license = yield* GCP.Compute.License("ImageLicense", {
licenseName: "app-os",
osLicense: true,
transferable: false,
removableFromDisk: false,
});

Source: src/GCP/Compute/MachineImage.ts

A Compute Engine machine image capturing a VM’s disks, metadata, and configuration so it can be used to create new instances.

Create from a source instance. Name, source instance, description, and storage locations replace the machine image. Labels are synced in place via setLabels.

Machine image from an instance

const vm = yield* GCP.Compute.Instance("web", {
zone: "us-central1-a",
machineType: "e2-micro",
});
const image = yield* GCP.Compute.MachineImage("backup", {
sourceInstance: vm.selfLink,
labels: { env: "prod" },
});

Explicit name and regional storage

const image = yield* GCP.Compute.MachineImage("backup", {
machineImageName: "web-golden",
sourceInstance:
"projects/{project}/zones/us-central1-a/instances/web",
description: "golden image of web",
storageLocations: ["us-central1"],
});
const image = yield* GCP.Compute.MachineImage("backup", {
machineImageName: "web-golden",
sourceInstance:
"projects/{project}/zones/us-central1-a/instances/web",
labels: { env: "prod", role: "golden" },
});

Source: src/GCP/Compute/Network.ts

A Google Compute Engine VPC network.

VPC networks have no labels field. Alchemy stamps alchemy-stack / alchemy-stage / alchemy-id into the description so list and pnpm nuke:gcp can still identify owned networks.

Custom-mode VPC (generated name)

const network = yield* GCP.Compute.Network("Vpc", {});

Explicit name, MTU, and routing mode

const network = yield* GCP.Compute.Network("Vpc", {
networkName: "app-vpc",
description: "application vpc",
autoCreateSubnetworks: false,
mtu: 1500,
routingMode: "GLOBAL",
});
const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: true,
});

Auto mode is slower to create and delete (one subnet per region). Prefer custom mode (autoCreateSubnetworks: false, the default) unless you specifically want the pre-created ranges.

Source: src/GCP/Compute/NetworkAttachment.ts

A regional Compute Engine Private Service Connect network attachment.

A network attachment lets a producer VPC initiate connections into a consumer VPC through a PSC interface. It lists consumer subnets and admits producers either automatically or via accept/reject lists. Compute NetworkAttachment has no labels field — Alchemy ownership is stored in the description so nuke can find leaked attachments.

NetworkAttachment: Creating a Network Attachment

Section titled “NetworkAttachment: Creating a Network Attachment”

Generated name, automatic accept

const attachment = yield* GCP.Compute.NetworkAttachment("Consumer", {
region: "us-central1",
subnetworks: [subnet.selfLink],
connectionPreference: "ACCEPT_AUTOMATIC",
});

Manual admission

const attachment = yield* GCP.Compute.NetworkAttachment("Consumer", {
networkAttachmentName: "app-na",
subnetworks: [subnet.selfLink],
connectionPreference: "ACCEPT_MANUAL",
producerAcceptLists: ["my-producer-project"],
});

Source: src/GCP/Compute/NetworkEdgeSecurityService.ts

A regional Compute Engine network edge security service.

Network edge security services attach a Cloud Armor network (L3/L4) security policy to a region. Name and region are immutable. Description and securityPolicy update in place via networkEdgeSecurityServices.patch. Compute NetworkEdgeSecurityService has no labels field — Alchemy stamps ownership into the description so nuke can find leaked services.

NetworkEdgeSecurityService: Creating a Network Edge Security Service

Section titled “NetworkEdgeSecurityService: Creating a Network Edge Security Service”

Generated name

const ness = yield* GCP.Compute.NetworkEdgeSecurityService("EdgeArmor", {
region: "us-central1",
description: "regional network armor",
});

Attach a network security policy

const ness = yield* GCP.Compute.NetworkEdgeSecurityService("EdgeArmor", {
networkEdgeSecurityServiceName: "app-ness",
securityPolicy: policy.selfLink,
});

Source: src/GCP/Compute/NetworkEndpointGroup.ts

A zonal Compute Engine network endpoint group (NEG).

Zonal NEGs hold VM IP/port endpoints (or hybrid NON_GCP_PRIVATE_IP_PORT endpoints) for load balancing. They have no labels API — Alchemy records ownership in the description so list / pnpm nuke:gcp can find them. Serverless, PSC, and internet NEGs use the regional/global collections and are not this resource.

NetworkEndpointGroup: Creating a Network Endpoint Group

Section titled “NetworkEndpointGroup: Creating a Network Endpoint Group”

Generated name

const neg = yield* GCP.Compute.NetworkEndpointGroup("web", {
defaultPort: 80,
});

Explicit name, zone, and default port

const neg = yield* GCP.Compute.NetworkEndpointGroup("web", {
networkEndpointGroupName: "web-neg",
zone: "us-central1-a",
network: "default",
defaultPort: 80,
description: "HTTP backends",
});
const neg = yield* GCP.Compute.NetworkEndpointGroup("web", {
zone: "us-central1-a",
defaultPort: 80,
networkEndpoints: [
{ instance: vm.instanceName, port: 80 },
],
});

Source: src/GCP/Compute/NetworkFirewallPolicy.ts

A global Compute Engine network firewall policy.

Network firewall policies live at the project level under global/firewallPolicies and are identified by the user-provided name. Name and policy type are immutable. Description updates in place via networkFirewallPolicies.patch. Rules are synced with addRule / patchRule / removeRule. Associations are synced with addAssociation / removeAssociation. Compute network firewall policies have no labels field — Alchemy stamps ownership into the description so nuke can find leaked policies.

NetworkFirewallPolicy: Creating a Network Firewall Policy

Section titled “NetworkFirewallPolicy: Creating a Network Firewall Policy”

Generated name with an allow rule

const policy = yield* GCP.Compute.NetworkFirewallPolicy("VpcFw", {
description: "allow internal http",
rules: [
{
action: "allow",
priority: 1000,
direction: "INGRESS",
match: {
srcIpRanges: ["10.0.0.0/8"],
layer4Configs: [{ ipProtocol: "tcp", ports: ["80"] }],
},
},
],
});

Associate with a VPC

const policy = yield* GCP.Compute.NetworkFirewallPolicy("VpcFw", {
networkFirewallPolicyName: "app-nfw",
associations: [{ name: "vpc", attachmentTarget: network.selfLink }],
});

Source: src/GCP/Compute/NodeGroup.ts

A zonal Compute Engine sole-tenant node group.

Node groups allocate dedicated physical servers from a node template. Name and zone are immutable. Description, maintenance policy, window, interval, autoscaling, and share settings update in place via nodeGroups.patch. The node template is swapped with setNodeTemplate. Compute NodeGroup has no labels field — Alchemy stamps ownership into the description so nuke can find leaked groups.

Generated name from a template

const group = yield* GCP.Compute.NodeGroup("SoleTenant", {
zone: "us-central1-a",
nodeTemplate: template.selfLink,
initialNodeCount: 1,
description: "prod sole tenant",
});

Autoscaled group

const group = yield* GCP.Compute.NodeGroup("SoleTenant", {
nodeTemplate: template.nodeTemplateName,
initialNodeCount: 0,
autoscalingPolicy: { mode: "ON", minNodes: 0, maxNodes: 3 },
});

Source: src/GCP/Compute/NodeTemplate.ts

A regional Compute Engine sole-tenant node template.

Node templates define the properties of sole-tenant nodes created in a node group (node type, CPU overcommit, affinity labels, local disks). There is no in-place update API — changing any property replaces the template. Compute NodeTemplate has no labels field — Alchemy stamps ownership into the description so nuke can find leaked templates.

Generated name with a node type

const template = yield* GCP.Compute.NodeTemplate("SoleTenant", {
region: "us-central1",
nodeType: "n2-node-80-640",
description: "prod sole tenant",
});

Flexible node type

const template = yield* GCP.Compute.NodeTemplate("SoleTenant", {
nodeTypeFlexibility: { cpus: "80", memory: "640GB" },
cpuOvercommitType: "ENABLED",
});

Source: src/GCP/Compute/OrganizationSecurityPolicy.ts

An organization-scoped Cloud Armor security policy.

Organization security policies live under locations/global/securityPolicies and are identified by a server-assigned numeric id. The user-facing name is shortName. Parent and type are immutable. Description and WAF options update in place via organizationSecurityPolicies.patch. Rules are synced with addRule / patchRule / removeRule.

OrganizationSecurityPolicy: Creating an Organization Security Policy

Section titled “OrganizationSecurityPolicy: Creating an Organization Security Policy”

Generated name with a deny rule

const policy = yield* GCP.Compute.OrganizationSecurityPolicy("OrgArmor", {
description: "deny a scanner",
rules: [
{
action: "deny(403)",
priority: 1000,
match: {
versionedExpr: "SRC_IPS_V1",
config: { srcIpRanges: ["9.9.9.0/24"] },
},
},
],
});

Named policy under an organization

const policy = yield* GCP.Compute.OrganizationSecurityPolicy("OrgArmor", {
shortName: "app-org-armor",
parent: "organizations/123456789",
description: "org WAF",
});

Source: src/GCP/Compute/PacketMirroring.ts

A regional Compute Engine packet mirroring policy.

Packet Mirroring copies traffic from selected VMs, subnets, or network tags in a VPC and sends it to a collector internal passthrough Network Load Balancer (ForwardingRule with isMirroringCollector: true). Compute PacketMirroring has no labels field — Alchemy ownership is stored in the description so nuke can find leaked resources.

Name, region, network, and description are immutable; collector ILB, mirrored sources, filter, enable, and priority update in place.

PacketMirroring: Creating a Packet Mirroring Policy

Section titled “PacketMirroring: Creating a Packet Mirroring Policy”

Mirror VMs by network tag

const policy = yield* GCP.Compute.PacketMirroring("Capture", {
network: vpc.selfLink,
collectorIlb: collector.selfLink,
mirroredResources: { tags: ["mirror-me"] },
});

Named policy with a traffic filter

const policy = yield* GCP.Compute.PacketMirroring("Capture", {
packetMirroringName: "app-capture",
region: "us-central1",
description: "tcp to the collector",
network: "default",
collectorIlb: collector.selfLink,
mirroredResources: {
subnetworks: [subnet.selfLink],
tags: ["web"],
},
filter: {
direction: "BOTH",
ipProtocols: ["tcp"],
cidrRanges: ["0.0.0.0/0"],
},
priority: 800,
});
const policy = yield* GCP.Compute.PacketMirroring("Capture", {
packetMirroringName: "app-capture",
network: vpc.selfLink,
collectorIlb: collector.selfLink,
mirroredResources: { tags: ["mirror-me"] },
enable: false,
});

Source: src/GCP/Compute/PublicAdvertisedPrefix.ts

A global public advertised prefix (BYOIP).

A public advertised prefix is an aggregated IP prefix you bring to Google Cloud. Creating one requires a prefix you own and reverse-DNS verification. Name, CIDR, verification IP, and PDP scope are immutable. Description updates in place via publicAdvertisedPrefixes.patch.

PublicAdvertisedPrefix: Creating a Public Advertised Prefix

Section titled “PublicAdvertisedPrefix: Creating a Public Advertised Prefix”

Regional-scope IPv4 prefix

const prefix = yield* GCP.Compute.PublicAdvertisedPrefix("Byoip", {
ipCidrRange: "203.0.113.0/24",
dnsVerificationIp: "203.0.113.1",
pdpScope: "REGIONAL",
description: "lab prefix",
});

Explicit name

const prefix = yield* GCP.Compute.PublicAdvertisedPrefix("Byoip", {
prefixName: "lab-pap",
ipCidrRange: "203.0.113.0/24",
pdpScope: "REGIONAL",
});

Source: src/GCP/Compute/PublicDelegatedPrefix.ts

A regional public delegated prefix (BYOIP).

A public delegated prefix is an IP block carved from a public advertised prefix and scoped to one region (or global). Creating one requires a parent advertised prefix. Name, region, parent, CIDR, and mode are immutable. Description and sub-prefixes update in place via publicDelegatedPrefixes.patch.

PublicDelegatedPrefix: Creating a Public Delegated Prefix

Section titled “PublicDelegatedPrefix: Creating a Public Delegated Prefix”

Regional IPv4 sub-prefix

const pap = yield* GCP.Compute.PublicAdvertisedPrefix("Byoip", {
ipCidrRange: "203.0.113.0/24",
pdpScope: "REGIONAL",
});
const pdp = yield* GCP.Compute.PublicDelegatedPrefix("Delegate", {
parentPrefix: pap.selfLink,
ipCidrRange: "203.0.113.0/26",
description: "us-central1 block",
});

Explicit name

const pdp = yield* GCP.Compute.PublicDelegatedPrefix("Delegate", {
prefixName: "lab-pdp",
region: "us-central1",
parentPrefix: pap.selfLink,
ipCidrRange: "203.0.113.0/26",
});

Source: src/GCP/Compute/RegionAutoscaler.ts

A regional Compute Engine autoscaler for a managed instance group.

Changing autoscalerName or region replaces the autoscaler. Policy, target, description, and labels update in place via regionAutoscalers.patch. Compute Engine has no labels on this resource, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

RegionAutoscaler: Creating a Region Autoscaler

Section titled “RegionAutoscaler: Creating a Region Autoscaler”

CPU policy with generated name

const scaler = yield* GCP.Compute.RegionAutoscaler("Web", {
target: mig.selfLink,
autoscalingPolicy: {
minNumReplicas: 1,
maxNumReplicas: 5,
coolDownPeriodSec: 60,
cpuUtilization: { utilizationTarget: 0.6 },
},
});

Named autoscaler, labels, and OFF mode

const scaler = yield* GCP.Compute.RegionAutoscaler("Web", {
autoscalerName: "web-scaler",
region: "us-central1",
target:
"projects/{project}/regions/us-central1/instanceGroupManagers/web",
description: "scale the web MIG",
labels: { env: "prod" },
autoscalingPolicy: {
minNumReplicas: 0,
maxNumReplicas: 3,
mode: "OFF",
cpuUtilization: { utilizationTarget: 0.5 },
},
});
const scaler = yield* GCP.Compute.RegionAutoscaler("Web", {
autoscalerName: "web-scaler",
target: mig.selfLink,
autoscalingPolicy: {
minNumReplicas: 1,
maxNumReplicas: 10,
cpuUtilization: { utilizationTarget: 0.5 },
},
});

Source: src/GCP/Compute/RegionBackendBucket.ts

A regional Compute Engine backend bucket that fronts a Cloud Storage bucket for HTTP(S) load balancing.

Compute Engine backend buckets have no labels field, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

RegionBackendBucket: Creating a Region Backend Bucket

Section titled “RegionBackendBucket: Creating a Region Backend Bucket”

Generated name in front of a Storage bucket

const assets = yield* GCP.Storage.Bucket("assets", {
forceDestroy: true,
});
const backend = yield* GCP.Compute.RegionBackendBucket("cdn", {
bucketName: assets.bucketName,
description: "static assets",
});

Explicit name with Cloud CDN

const backend = yield* GCP.Compute.RegionBackendBucket("cdn", {
name: "app-static",
region: "us-central1",
bucketName: assets.bucketName,
enableCdn: true,
compressionMode: "AUTOMATIC",
});

Source: src/GCP/Compute/RegionBackendService.ts

A regional Compute Engine backend service. Backend services define how Google Cloud load balancers distribute traffic — protocol, timeout, session affinity, health checks, and the backends themselves.

Compute Engine backend services have no labels field, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them. Changing name, region, loadBalancingScheme, or network replaces the resource.

RegionBackendService: Creating a Region Backend Service

Section titled “RegionBackendService: Creating a Region Backend Service”

Generated name

const backend = yield* GCP.Compute.RegionBackendService("web", {
protocol: "HTTP",
loadBalancingScheme: "INTERNAL_MANAGED",
});

Explicit name, timeout, and labels

const backend = yield* GCP.Compute.RegionBackendService("web", {
name: "web-backend",
region: "us-central1",
protocol: "HTTP",
loadBalancingScheme: "INTERNAL_MANAGED",
timeoutSec: 30,
localityLbPolicy: "ROUND_ROBIN",
labels: { env: "prod" },
});

RegionBackendService: Updating a Region Backend Service

Section titled “RegionBackendService: Updating a Region Backend Service”
const backend = yield* GCP.Compute.RegionBackendService("web", {
name: "web-backend",
timeoutSec: 60,
});

Source: src/GCP/Compute/RegionCompositeHealthCheck.ts

A regional Compute Engine composite health check.

Composite health checks AND the results of one or more HealthSource resources and publish the aggregate to a destination ForwardingRule. Name and region are immutable. Destination, sources, and description update in place via regionCompositeHealthChecks.patch.

RegionCompositeHealthCheck: Creating a Composite Health Check

Section titled “RegionCompositeHealthCheck: Creating a Composite Health Check”

Generated name

const check = yield* GCP.Compute.RegionCompositeHealthCheck("Comp", {
healthDestination: rule.selfLink,
healthSources: [source.selfLink],
description: "and backends",
});

Named check

const check = yield* GCP.Compute.RegionCompositeHealthCheck("Comp", {
healthCheckName: "app-composite",
region: "us-central1",
healthDestination: rule.selfLink,
healthSources: [source.selfLink],
});

Source: src/GCP/Compute/RegionDisk.ts

A regional Compute Engine persistent disk.

Regional disks replicate across two zones in a region and require a minimum size of 200 GB. Changing region, replicaZones, type, diskName, sourceImage, sourceSnapshot, sourceDisk, architecture, physicalBlockSizeBytes, or enableConfidentialCompute replaces the disk. Growing sizeGb is applied in place via regionDisks.resize; shrinking it replaces the disk.

Generated name

const disk = yield* GCP.Compute.RegionDisk("data", {});

Explicit name, replica zones, type, size, and labels

const disk = yield* GCP.Compute.RegionDisk("data", {
diskName: "app-data",
region: "us-central1",
replicaZones: ["us-central1-a", "us-central1-b"],
type: "pd-balanced",
sizeGb: 200,
labels: { env: "prod" },
});
const disk = yield* GCP.Compute.RegionDisk("data", {
diskName: "app-data",
region: "us-central1",
sizeGb: 250,
});

Source: src/GCP/Compute/RegionHealthAggregationPolicy.ts

A regional Compute Engine health aggregation policy.

Health aggregation policies define how endpoint health is rolled up for backend services used by composite health checks. Type is immutable — changing it replaces the policy. Thresholds and description update in place via regionHealthAggregationPolicies.patch.

RegionHealthAggregationPolicy: Creating a Health Aggregation Policy

Section titled “RegionHealthAggregationPolicy: Creating a Health Aggregation Policy”

Generated name with defaults

const policy = yield* GCP.Compute.RegionHealthAggregationPolicy(
"Agg",
{},
);

Custom thresholds

const policy = yield* GCP.Compute.RegionHealthAggregationPolicy(
"Agg",
{
description: "backend rollup",
minHealthyThreshold: 2,
healthyPercentThreshold: 80,
},
);

Source: src/GCP/Compute/RegionHealthCheck.ts

A regional Compute Engine health check.

Health checks probe backends for load balancing and managed-instance-group autohealing. This resource maps to the regional regionHealthChecks collection (the global healthChecks resource is GCP.Compute.HealthCheck). Compute HealthCheck has no labels field — Alchemy ownership is stored in the description so nuke can find leaked checks.

Changing healthCheckName, region, or type replaces the resource.

RegionHealthCheck: Creating a Region Health Check

Section titled “RegionHealthCheck: Creating a Region Health Check”

Generated name (HTTP on port 80)

const check = yield* GCP.Compute.RegionHealthCheck("api", {});

HTTP path and thresholds

const check = yield* GCP.Compute.RegionHealthCheck("api", {
region: "us-central1",
description: "frontend /health",
checkIntervalSec: 10,
timeoutSec: 5,
httpHealthCheck: { port: 80, requestPath: "/health" },
});

TCP health check

const check = yield* GCP.Compute.RegionHealthCheck("tcp", {
type: "TCP",
tcpHealthCheck: { port: 8080 },
});

Source: src/GCP/Compute/RegionHealthCheckService.ts

A regional Compute Engine Health Check as a Service (HCSS) resource.

Health check services publish endpoint health from NEGs to notification endpoints. Name and region are immutable. Health checks, NEGs, notification endpoints, aggregation policy, and description update in place via regionHealthCheckServices.patch.

RegionHealthCheckService: Creating a Health Check Service

Section titled “RegionHealthCheckService: Creating a Health Check Service”

Generated name with a regional HTTP health check

const check = yield* GCP.Compute.RegionHealthCheck("api", {
httpHealthCheck: { port: 80, portSpecification: "USE_FIXED_PORT" },
});
const service = yield* GCP.Compute.RegionHealthCheckService("Hcss", {
healthChecks: [check.selfLink],
description: "endpoint health",
});

AND aggregation

const service = yield* GCP.Compute.RegionHealthCheckService("Hcss", {
healthChecks: [check.selfLink],
healthStatusAggregationPolicy: "AND",
});

Source: src/GCP/Compute/RegionHealthSource.ts

A regional Compute Engine health source.

A health source names the backend resources whose health is aggregated by a HealthAggregationPolicy (used by composite health checks). Type is immutable. Sources, aggregation policy, and description update in place via regionHealthSources.patch.

RegionHealthSource: Creating a Health Source

Section titled “RegionHealthSource: Creating a Health Source”

Backend-service source

const policy = yield* GCP.Compute.RegionHealthAggregationPolicy(
"Agg",
{},
);
const backend = yield* GCP.Compute.RegionBackendService("Web", {
protocol: "TCP",
loadBalancingScheme: "INTERNAL",
});
const source = yield* GCP.Compute.RegionHealthSource("Src", {
sources: [backend.selfLink],
healthAggregationPolicy: policy.selfLink,
});

Named source

const source = yield* GCP.Compute.RegionHealthSource("Src", {
sourceName: "web-health",
sources: [backend.selfLink],
healthAggregationPolicy: policy.selfLink,
description: "internal backends",
});

Source: src/GCP/Compute/RegionInstanceGroupManager.ts

A regional Compute Engine managed instance group.

The manager creates and heals VMs from an instance template, spread across zones in a region. Compute Engine has no labels on this resource, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

Name, region, baseInstanceName, and distributionPolicy.zones are immutable — changing them replaces the manager. targetSize, instanceTemplate / versions, description, autohealing, and update policy patch in place. Named ports are synced onto the complementary regional instance group.

RegionInstanceGroupManager: Creating a Regional MIG

Section titled “RegionInstanceGroupManager: Creating a Regional MIG”

Generated name, no running VMs

const template = yield* GCP.Compute.InstanceTemplate("web", {});
const mig = yield* GCP.Compute.RegionInstanceGroupManager("web", {
instanceTemplate: template.selfLink,
targetSize: 0,
});

Named group with named ports

const mig = yield* GCP.Compute.RegionInstanceGroupManager("web", {
managerName: "web-mig",
region: "us-central1",
instanceTemplate:
"projects/{project}/global/instanceTemplates/web",
baseInstanceName: "web",
targetSize: 3,
namedPorts: [{ name: "http", port: 80 }],
});

Source: src/GCP/Compute/RegionInstanceGroupManagerResizeRequest.ts

A regional managed instance group resize request.

Resize requests provision (or queue) additional VMs on a regional MIG. They are immutable after create — changing resizeBy, duration, the parent group, or the name replaces the request. Delete cancels an in-flight request first when the API requires it.

RegionInstanceGroupManagerResizeRequest: Creating a Resize Request

Section titled “RegionInstanceGroupManagerResizeRequest: Creating a Resize Request”

Queue one extra VM

const request = yield* GCP.Compute.RegionInstanceGroupManagerResizeRequest(
"Burst",
{
instanceGroupManager: manager.managerName,
resizeBy: 1,
requestedRunDuration: { seconds: "3600" },
description: "burst capacity",
},
);

Timed run

const request = yield* GCP.Compute.RegionInstanceGroupManagerResizeRequest(
"Burst",
{
instanceGroupManager: manager.managerName,
resizeBy: 1,
requestedRunDuration: { seconds: "3600" },
},
);

Source: src/GCP/Compute/RegionInstanceTemplate.ts

A regional Compute Engine instance template.

Regional instance templates are immutable. Changing machine type, disks, labels, network interfaces, or other properties replaces the template. Use the template to create regional managed instance groups.

RegionInstanceTemplate: Creating a Regional Template

Section titled “RegionInstanceTemplate: Creating a Regional Template”

Generated name with defaults

const template = yield* GCP.Compute.RegionInstanceTemplate("web", {});

Explicit machine type, disk, and labels

const template = yield* GCP.Compute.RegionInstanceTemplate("web", {
region: "us-central1",
machineType: "e2-micro",
labels: { env: "prod" },
disks: [
{
boot: true,
autoDelete: true,
sourceImage:
"projects/debian-cloud/global/images/family/debian-12",
diskSizeGb: 10,
},
],
});

Source: src/GCP/Compute/RegionInstantSnapshot.ts

A regional Compute Engine instant snapshot.

Instant snapshots are crash-consistent rollback points of a regional disk. Name, source disk, description, and region are immutable — changing them replaces the snapshot. Labels are updated in place via regionInstantSnapshots.setLabels.

RegionInstantSnapshot: Creating a Regional Instant Snapshot

Section titled “RegionInstantSnapshot: Creating a Regional Instant Snapshot”
const disk = yield* GCP.Compute.RegionDisk("data", {
region: "us-central1",
sizeGb: 200,
});
const snapshot = yield* GCP.Compute.RegionInstantSnapshot("checkpoint", {
region: "us-central1",
sourceDisk: disk.selfLink,
});

Source: src/GCP/Compute/RegionInstantSnapshotGroup.ts

A regional Compute Engine instant snapshot group.

An instant snapshot group is a crash-consistent set of instant snapshots taken from every disk in a disk consistency group (a ResourcePolicy with diskConsistencyGroupPolicy). There is no update API and no labels field — Alchemy stamps ownership into the description so nuke can find leaked groups, and every user-facing field change replaces the resource.

RegionInstantSnapshotGroup: Creating a Regional Instant Snapshot Group

Section titled “RegionInstantSnapshotGroup: Creating a Regional Instant Snapshot Group”
const policy = yield* GCP.Compute.ResourcePolicy("cg", {
region: "us-central1",
diskConsistencyGroupPolicy: {},
});
const group = yield* GCP.Compute.RegionInstantSnapshotGroup("ckpt", {
region: "us-central1",
sourceConsistencyGroup: policy.resourcePolicyName,
});

Source: src/GCP/Compute/RegionNetworkEndpointGroup.ts

A regional Compute Engine network endpoint group.

Regional NEGs back serverless (Cloud Run, App Engine, Cloud Functions), internet (INTERNET_IP_PORT / INTERNET_FQDN_PORT), and Private Service Connect load-balancing backends. The regional collection has no labels field and no update API — Alchemy stamps ownership into the description so list / nuke can find leaked groups. Name, region, type, network, serverless config, PSC target, port, annotations, and description are all immutable (changing any of them replaces the group).

RegionNetworkEndpointGroup: Creating a RegionNetworkEndpointGroup

Section titled “RegionNetworkEndpointGroup: Creating a RegionNetworkEndpointGroup”

Cloud Run serverless NEG with a URL mask

const neg = yield* GCP.Compute.RegionNetworkEndpointGroup("RunNeg", {
region: "us-central1",
networkEndpointType: "SERVERLESS",
cloudRun: { urlMask: "<service>" },
});

Cloud Run service backend

const neg = yield* GCP.Compute.RegionNetworkEndpointGroup("RunNeg", {
cloudRun: { service: "api" },
});
const neg = yield* GCP.Compute.RegionNetworkEndpointGroup("Internet", {
network: "default",
networkEndpointType: "INTERNET_IP_PORT",
defaultPort: 443,
});

RegionNetworkEndpointGroup: Private Service Connect

Section titled “RegionNetworkEndpointGroup: Private Service Connect”
const neg = yield* GCP.Compute.RegionNetworkEndpointGroup("Kms", {
networkEndpointType: "PRIVATE_SERVICE_CONNECT",
pscTargetService: "us-central1-cloudkms.googleapis.com",
subnetwork:
"projects/{project}/regions/us-central1/subnetworks/default",
});

Source: src/GCP/Compute/RegionNetworkFirewallPolicy.ts

A regional network firewall policy attached to a VPC network.

Policies live under projects/{project}/regions/{region}/firewallPolicies and are identified by a user-provided RFC1035 name. Name, region, and policyType are immutable — changing any of them replaces the policy. Description updates in place via regionNetworkFirewallPolicies.patch. Rules are synced with addRule / patchRule / removeRule.

Compute Engine network firewall policies have no resource labels. Alchemy stamps ownership into the description so read / list (and pnpm nuke:gcp) can find them.

RegionNetworkFirewallPolicy: Creating a Regional Network Firewall Policy

Section titled “RegionNetworkFirewallPolicy: Creating a Regional Network Firewall Policy”
const policy = yield* GCP.Compute.RegionNetworkFirewallPolicy("VpcFw", {
region: "us-central1",
description: "allow internal http",
rules: [
{
action: "allow",
priority: 1000,
direction: "INGRESS",
match: {
srcIpRanges: ["10.0.0.0/8"],
layer4Configs: [{ ipProtocol: "tcp", ports: ["80"] }],
},
},
],
});

Source: src/GCP/Compute/RegionNotificationEndpoint.ts

A regional Compute Engine notification endpoint.

Notification endpoints receive gRPC callbacks when a health-check service detects backend status changes. This resource maps to the regionNotificationEndpoints collection. There is no update API and no labels field — Alchemy stamps ownership into the description so nuke can find leaked endpoints. Changing any user-facing field replaces the resource.

RegionNotificationEndpoint: Creating a Notification Endpoint

Section titled “RegionNotificationEndpoint: Creating a Notification Endpoint”

Generated name

const endpoint = yield* GCP.Compute.RegionNotificationEndpoint("Health", {
region: "us-central1",
grpcSettings: { endpoint: "health.example.com:443" },
});

Named endpoint with retry settings

const endpoint = yield* GCP.Compute.RegionNotificationEndpoint("Health", {
notificationEndpointName: "app-health",
region: "us-central1",
description: "regional health callbacks",
grpcSettings: {
endpoint: "health.example.com:443",
retryDurationSec: 30,
},
});

Source: src/GCP/Compute/RegionSecurityPolicy.ts

A regional Cloud Armor security policy that filters HTTP(S) requests targeting regional backend services.

Type and region are immutable — changing either replaces the policy. Description, advanced options, Adaptive Protection, reCAPTCHA, DDoS config, and user-defined fields update in place via regionSecurityPolicies.patch. Rules are synced with addRule / patchRule / removeRule (not patch). Labels are applied with setLabels after the policy exists.

RegionSecurityPolicy: Creating a Regional Security Policy

Section titled “RegionSecurityPolicy: Creating a Regional Security Policy”
const policy = yield* GCP.Compute.RegionSecurityPolicy("Armor", {
region: "us-central1",
description: "deny a scanner",
rules: [
{
action: "deny(403)",
priority: 1000,
description: "block scanner",
match: {
versionedExpr: "SRC_IPS_V1",
config: { srcIpRanges: ["9.9.9.0/24"] },
},
},
],
});

Source: src/GCP/Compute/RegionSnapshot.ts

A regional Compute Engine persistent-disk snapshot.

Regional snapshots are created from a regional disk (or instant snapshot) and stored in the same region. Name, source, type, storage locations, chain name, description, and region are immutable — changing them replaces the snapshot. Labels are updated in place via regionSnapshots.setLabels.

RegionSnapshot: Creating a Regional Snapshot

Section titled “RegionSnapshot: Creating a Regional Snapshot”
const disk = yield* GCP.Compute.RegionDisk("data", {
region: "us-central1",
sizeGb: 200,
});
const snapshot = yield* GCP.Compute.RegionSnapshot("nightly", {
region: "us-central1",
sourceDisk: disk.selfLink,
});

Source: src/GCP/Compute/RegionSslCertificate.ts

A regional Compute Engine SSL certificate for HTTPS load balancing.

Maps to the regionSslCertificates collection (the global sslCertificates collection is GCP.Compute.SslCertificate). Certificates cannot be updated in place — every user-facing field is immutable and changing it replaces the resource. Compute SSL certificates have no labels field, so Alchemy stamps ownership into the description for list / nuke.

RegionSslCertificate: Creating a Self-Managed Certificate

Section titled “RegionSslCertificate: Creating a Self-Managed Certificate”

Generated name

const cert = yield* GCP.Compute.RegionSslCertificate("Frontend", {
region: "us-central1",
certificate: pemCertificate,
privateKey: pemPrivateKey,
});

Named certificate with a description

const cert = yield* GCP.Compute.RegionSslCertificate("Frontend", {
sslCertificateName: "app-frontend-tls",
region: "us-central1",
description: "prod frontend",
certificate: pemCertificate,
privateKey: pemPrivateKey,
});

Source: src/GCP/Compute/RegionSslPolicy.ts

A regional Compute Engine SSL policy for HTTPS and SSL load balancing.

SSL policies control the TLS versions and cipher suites offered by regional Application Load Balancers and proxy Network Load Balancers. This resource maps to the regionSslPolicies collection (the global sslPolicies collection is GCP.Compute.SslPolicy). Compute SslPolicy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked policies.

RegionSslPolicy: Creating a Regional SSL Policy

Section titled “RegionSslPolicy: Creating a Regional SSL Policy”

Generated name (COMPATIBLE, TLS 1.0)

const policy = yield* GCP.Compute.RegionSslPolicy("Frontend", {
region: "us-central1",
});

Modern profile and TLS 1.2

const policy = yield* GCP.Compute.RegionSslPolicy("Frontend", {
region: "us-central1",
description: "prod frontend",
profile: "MODERN",
minTlsVersion: "TLS_1_2",
});

Source: src/GCP/Compute/RegionTargetHttpProxy.ts

A regional Compute Engine target HTTP proxy.

Regional target HTTP proxies are referenced by regional forwarding rules and point at a regional URL map that routes host/path to a backend service or redirect. This resource maps to the regionTargetHttpProxies collection (targetHttpProxies is GCP.Compute.TargetHttpProxy). Compute RegionTargetHttpProxy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked proxies. The only in-place mutation is setUrlMap; name, region, description, proxyBind, and httpKeepAliveTimeoutSec replace the proxy.

RegionTargetHttpProxy: Creating a Regional Target HTTP Proxy

Section titled “RegionTargetHttpProxy: Creating a Regional Target HTTP Proxy”

Generated name in front of a regional URL map

const map = yield* GCP.Compute.RegionUrlMap("web", {
region: "us-central1",
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "example.com",
stripQuery: false,
},
});
const proxy = yield* GCP.Compute.RegionTargetHttpProxy("http", {
region: "us-central1",
urlMap: map.urlMapName,
});

Explicit name and description

const proxy = yield* GCP.Compute.RegionTargetHttpProxy("http", {
targetHttpProxyName: "app-http",
region: "us-central1",
description: "public http frontend",
urlMap: map.selfLink,
});

Source: src/GCP/Compute/RegionTargetHttpsProxy.ts

A regional Compute Engine target HTTPS proxy.

Regional target HTTPS proxies terminate HTTPS for regional Application Load Balancers. A forwarding rule points at the proxy; the proxy points at a regional URL map and one or more regional SSL certificates.

This resource maps to the regionTargetHttpsProxies collection (the global targetHttpsProxies collection is GCP.Compute.TargetHttpsProxy). Compute RegionTargetHttpsProxy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked proxies. Url map and certificates update in place; name and region replace.

RegionTargetHttpsProxy: Creating a Regional Target HTTPS Proxy

Section titled “RegionTargetHttpsProxy: Creating a Regional Target HTTPS Proxy”
const map = yield* GCP.Compute.RegionUrlMap("web", {
region: "us-central1",
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "example.com",
stripQuery: false,
},
});
const cert = yield* GCP.Compute.RegionSslCertificate("tls", {
region: "us-central1",
certificate: pemCertificate,
privateKey: pemPrivateKey,
});
const proxy = yield* GCP.Compute.RegionTargetHttpsProxy("https", {
region: "us-central1",
urlMap: map.urlMapName,
sslCertificates: [cert.sslCertificateName],
});

Source: src/GCP/Compute/RegionTargetTcpProxy.ts

A regional Compute Engine target TCP proxy.

Regional target TCP proxies are referenced by regional forwarding rules and point at a regional backend service. They are a component of regional proxy Network Load Balancers. This resource maps to the regionTargetTcpProxies collection (the global targetTcpProxies collection is GCP.Compute.TargetTcpProxy). Compute RegionTargetTcpProxy has no labels field and no in-place update API (setBackendService exists only on the global collection). Alchemy ownership is stored in the description so nuke can find leaked proxies. Changing the backend, proxy header, description, proxyBind, or load-balancing scheme deletes and recreates the proxy so the observed backend always matches.

RegionTargetTcpProxy: Creating a Regional Target TCP Proxy

Section titled “RegionTargetTcpProxy: Creating a Regional Target TCP Proxy”
const backend = yield* GCP.Compute.RegionBackendService("tcp", {
region: "us-central1",
protocol: "TCP",
loadBalancingScheme: "INTERNAL_MANAGED",
});
const proxy = yield* GCP.Compute.RegionTargetTcpProxy("tcp", {
region: "us-central1",
service: backend.name,
});

Source: src/GCP/Compute/RegionUrlMap.ts

A regional Compute Engine URL map.

Regional URL maps route hostnames and URL paths to a regional backend service or HTTP redirect. They back internal Application Load Balancers and regional external / internal Application Load Balancers. This resource maps to the regionUrlMaps collection (the global urlMaps collection is GCP.Compute.UrlMap). Compute RegionUrlMap has no labels field — Alchemy ownership is stored in the description so nuke can find leaked maps.

One of defaultService, defaultUrlRedirect, or defaultRouteAction.weightedBackendServices is required.

Generated name with a default HTTPS redirect

const map = yield* GCP.Compute.RegionUrlMap("web", {
region: "us-central1",
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "example.com",
stripQuery: false,
},
});

Host rules and path matchers

const map = yield* GCP.Compute.RegionUrlMap("web", {
description: "public https",
defaultUrlRedirect: {
httpsRedirect: true,
stripQuery: false,
},
hostRules: [{ hosts: ["example.com"], pathMatcher: "all" }],
pathMatchers: [
{
name: "all",
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "www.example.com",
stripQuery: false,
},
},
],
});

Default regional backend service

const map = yield* GCP.Compute.RegionUrlMap("web", {
defaultService: backend.selfLink,
});

Source: src/GCP/Compute/Reservation.ts

A zonal Compute Engine capacity reservation.

Reservations hold VM capacity in a zone even when the reserved VMs are not running. Compute Engine has no labels on this resource, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

Name, zone, machine shape, specificReservationRequired, and deploymentType are immutable — changing them replaces the reservation. specificReservation.count resizes in place. Description and share settings update in place via reservations.patch.

One n1-standard-1 in the default zone

const reserved = yield* GCP.Compute.Reservation("Burst", {
specificReservation: {
count: 1,
instanceProperties: { machineType: "n1-standard-1" },
},
specificReservationRequired: true,
});

Named reservation with a description

const reserved = yield* GCP.Compute.Reservation("Burst", {
reservationName: "app-burst",
zone: "us-central1-a",
description: "on-demand burst capacity",
specificReservation: {
count: 2,
instanceProperties: { machineType: "n1-standard-1" },
},
});
const reserved = yield* GCP.Compute.Reservation("Burst", {
reservationName: "app-burst",
specificReservation: {
count: 4,
instanceProperties: { machineType: "n1-standard-1" },
},
});

Source: src/GCP/Compute/ResourcePolicy.ts

A regional Compute Engine resource policy.

Resource policies schedule snapshots, start/stop VMs, or describe placement. Compute Engine has no labels on this resource, so Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

Name, region, and policy kind (snapshotSchedulePolicy vs instanceSchedulePolicy vs placement/workload/consistency) are immutable — changing them replaces the policy. Description and the nested snapshot / instance schedules update in place via resourcePolicies.patch.

ResourcePolicy: Creating a Resource Policy

Section titled “ResourcePolicy: Creating a Resource Policy”

Daily snapshot schedule

const nightly = yield* GCP.Compute.ResourcePolicy("Nightly", {
snapshotSchedulePolicy: {
schedule: {
dailySchedule: { daysInCycle: 1, startTime: "04:00" },
},
retentionPolicy: { maxRetentionDays: 7 },
},
});

Named policy with labels in the snapshot properties

const backups = yield* GCP.Compute.ResourcePolicy("Backups", {
resourcePolicyName: "app-disk-nightly",
region: "us-central1",
description: "nightly disk snapshots",
snapshotSchedulePolicy: {
schedule: {
dailySchedule: { daysInCycle: 1, startTime: "04:00" },
},
retentionPolicy: {
maxRetentionDays: 14,
onSourceDiskDelete: "KEEP_AUTO_SNAPSHOTS",
},
snapshotProperties: {
storageLocations: ["us"],
labels: { env: "prod" },
},
},
});
const hours = yield* GCP.Compute.ResourcePolicy("OfficeHours", {
instanceSchedulePolicy: {
timeZone: "America/Chicago",
vmStartSchedule: { schedule: "0 8 * * 1-5" },
vmStopSchedule: { schedule: "0 18 * * 1-5" },
},
});

Source: src/GCP/Compute/RolloutPlan.ts

A project-global Compute Engine rollout plan.

Rollout plans divide a large change (for example a global VM extension policy) into waves. Compute Engine has no labels and no update method on this resource, so Alchemy stamps ownership into the description and treats name, scope, description, and waves as replacement triggers.

Single-wave zonal plan

const plan = yield* GCP.Compute.RolloutPlan("Fleet", {
waves: [
{
displayName: "central",
selectors: [
{
locationSelector: {
includedLocations: ["us-central1-a"],
},
},
],
validation: {
type: "time",
timeBasedValidationMetadata: { waitDuration: "0s" },
},
},
],
});

Named plan with a description

const plan = yield* GCP.Compute.RolloutPlan("Fleet", {
rolloutPlanName: "ops-agent-rollout",
description: "ops-agent canary",
locationScope: "ZONAL",
waves: [
{
selectors: [
{
locationSelector: {
includedLocations: ["us-central1-a", "us-central1-b"],
},
},
],
validation: { type: "manual" },
},
],
});

Source: src/GCP/Compute/Route.ts

A VPC static route.

Routes tell instances where to send packets whose destination matches destRange. Compute Engine has no update API for routes — every user-facing field is immutable and changing it replaces the resource. Ownership is stamped into the description because routes have no labels.

Default internet route on the default network

const route = yield* GCP.Compute.Route("internet", {
destRange: "0.0.0.0/0",
network: "default",
nextHopGateway: "default-internet-gateway",
});

Named route with priority and tags

const route = yield* GCP.Compute.Route("tagged", {
routeName: "app-egress",
destRange: "192.0.2.0/24",
network: "default",
nextHopGateway: "default-internet-gateway",
priority: 100,
tags: ["egress"],
description: "test-net egress",
});

Next hop IP

const route = yield* GCP.Compute.Route("appliance", {
destRange: "10.200.0.0/16",
network: "default",
nextHopIp: "10.128.0.5",
});

Source: src/GCP/Compute/Router.ts

A regional Cloud Router.

Cloud Routers advertise VPC routes over BGP to VPN tunnels and interconnects, and they host Cloud NAT. Compute Router has no labels field — Alchemy stamps alchemy-stack / alchemy-stage / alchemy-id into the description so list and pnpm nuke:gcp can find owned routers.

Name, region, network, encryptedInterconnectRouter, and nccGateway are immutable. Description and BGP (ASN, advertise mode, advertised ranges, keepalive) and Cloud NAT gateways (nats) update in place via routers.patch.

Generated name on a custom-mode VPC

const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const router = yield* GCP.Compute.Router("Edge", {
network: network.networkName,
});

Named router with BGP

const router = yield* GCP.Compute.Router("Edge", {
routerName: "app-router",
region: "us-central1",
network: "app-vpc",
description: "edge bgp",
bgp: { asn: 65001, advertiseMode: "DEFAULT" },
});
const egressIp = yield* GCP.Compute.Address("EgressIp", {
addressType: "EXTERNAL",
});
const router = yield* GCP.Compute.Router("Nat", {
network: network.networkName,
nats: [
{
name: "egress",
sourceSubnetworkIpRangesToNat: "LIST_OF_SUBNETWORKS",
subnetworks: [{ name: subnet.subnetworkName }],
natIpAllocateOption: "MANUAL_ONLY",
natIps: [egressIp.selfLink.as<string>()],
logConfig: { enable: true, filter: "ERRORS_ONLY" },
},
],
});
const router = yield* GCP.Compute.Router("Edge", {
network: network.networkName,
bgp: {
asn: 65001,
advertiseMode: "CUSTOM",
advertisedGroups: ["ALL_SUBNETS"],
advertisedIpRanges: [
{ range: "10.0.0.0/8", description: "rfc1918" },
],
},
});

Source: src/GCP/Compute/SecurityPolicy.ts

A global Cloud Armor security policy that filters HTTP(S) requests targeting backend services (and, for CLOUD_ARMOR_EDGE, backend buckets).

Type is immutable — changing it replaces the policy. Name is immutable. Description, advanced options, Adaptive Protection, reCAPTCHA, DDoS config, and user-defined fields update in place via securityPolicies.patch. Rules are synced with addRule / patchRule / removeRule (not patch). Labels are applied with setLabels after the policy exists.

SecurityPolicy: Creating a Security Policy

Section titled “SecurityPolicy: Creating a Security Policy”

Generated name with a deny rule

const policy = yield* GCP.Compute.SecurityPolicy("Armor", {
description: "deny a scanner",
rules: [
{
action: "deny(403)",
priority: 1000,
description: "block scanner",
match: {
versionedExpr: "SRC_IPS_V1",
config: { srcIpRanges: ["9.9.9.0/24"] },
},
},
],
});

Named policy with labels

const policy = yield* GCP.Compute.SecurityPolicy("Armor", {
securityPolicyName: "app-armor",
type: "CLOUD_ARMOR",
description: "prod WAF",
labels: { env: "prod" },
});
const policy = yield* GCP.Compute.SecurityPolicy("Armor", {
advancedOptionsConfig: {
jsonParsing: "STANDARD",
logLevel: "VERBOSE",
},
});

Source: src/GCP/Compute/ServiceAttachment.ts

A regional Compute Engine Private Service Connect service attachment.

A service attachment is how a producer exposes an internal load balancer (or other target service) to consumers over Private Service Connect. It points at a producer forwarding rule, lists NAT subnets with purpose PRIVATE_SERVICE_CONNECT, and admits consumers either automatically or via accept/reject lists.

Compute ServiceAttachment has no labels field — Alchemy ownership is stored in the description so nuke can find leaked attachments.

ServiceAttachment: Creating a Service Attachment

Section titled “ServiceAttachment: Creating a Service Attachment”

Generated name, automatic accept

const attachment = yield* GCP.Compute.ServiceAttachment("Producer", {
region: "us-central1",
targetService: forwardingRule.selfLink,
natSubnets: [natSubnet.selfLink],
connectionPreference: "ACCEPT_AUTOMATIC",
enableProxyProtocol: false,
});

Named attachment with labels

const attachment = yield* GCP.Compute.ServiceAttachment("Producer", {
serviceAttachmentName: "app-psc",
region: "us-central1",
targetService: forwardingRule.selfLink,
natSubnets: [natSubnet.selfLink],
description: "private service connect",
labels: { env: "prod" },
});
const attachment = yield* GCP.Compute.ServiceAttachment("Producer", {
targetService: forwardingRule.selfLink,
natSubnets: [natSubnet.selfLink],
connectionPreference: "ACCEPT_MANUAL",
consumerAcceptLists: [
{ projectIdOrNum: "my-consumer-project", connectionLimit: 10 },
],
reconcileConnections: true,
});

Source: src/GCP/Compute/Snapshot.ts

A global Compute Engine persistent-disk snapshot.

Snapshots are created from a source disk (or instant snapshot). Name, source, type, storage locations, chain name, and description are immutable — changing them replaces the snapshot. Labels are updated in place via snapshots.setLabels.

Snapshot of a disk

const disk = yield* GCP.Compute.Disk("data", {
zone: "us-central1-a",
sizeGb: 10,
});
const snapshot = yield* GCP.Compute.Snapshot("nightly", {
sourceDisk: disk.selfLink,
});

Explicit name, archive type, and labels

const snapshot = yield* GCP.Compute.Snapshot("nightly", {
snapshotName: "app-data-nightly",
sourceDisk: "zones/us-central1-a/disks/app-data",
snapshotType: "ARCHIVE",
storageLocations: ["us-central1"],
labels: { env: "prod" },
});

Source: src/GCP/Compute/SslCertificate.ts

A global Compute Engine SSL certificate for HTTPS / SSL load balancing.

Maps to the global sslCertificates collection (regionSslCertificates is a separate resource). Certificates cannot be updated in place — every user-facing field is immutable and changing it replaces the resource. Compute SSL certificates have no labels field, so Alchemy stamps ownership into the description for list / nuke.

SslCertificate: Creating a Self-Managed Certificate

Section titled “SslCertificate: Creating a Self-Managed Certificate”

Generated name

const cert = yield* GCP.Compute.SslCertificate("Frontend", {
certificate: pemCertificate,
privateKey: pemPrivateKey,
});

Named certificate with a description

const cert = yield* GCP.Compute.SslCertificate("Frontend", {
sslCertificateName: "app-frontend-tls",
description: "prod frontend",
certificate: pemCertificate,
privateKey: pemPrivateKey,
});

SslCertificate: Google-Managed Certificates

Section titled “SslCertificate: Google-Managed Certificates”
const cert = yield* GCP.Compute.SslCertificate("Frontend", {
type: "MANAGED",
managed: { domains: ["www.example.com"] },
});

Source: src/GCP/Compute/SslPolicy.ts

A global Compute Engine SSL policy for HTTPS and SSL load balancing.

SSL policies control the TLS versions and cipher suites offered by Application Load Balancers and proxy Network Load Balancers. This resource maps to the global sslPolicies collection (regionSslPolicies is a separate resource). Compute SslPolicy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked policies.

Generated name (COMPATIBLE, TLS 1.0)

const policy = yield* GCP.Compute.SslPolicy("Frontend", {});

Modern profile and TLS 1.2

const policy = yield* GCP.Compute.SslPolicy("Frontend", {
description: "prod frontend",
profile: "MODERN",
minTlsVersion: "TLS_1_2",
});
const policy = yield* GCP.Compute.SslPolicy("Frontend", {
profile: "CUSTOM",
minTlsVersion: "TLS_1_2",
customFeatures: [
"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256",
"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256",
],
});

Source: src/GCP/Compute/StartInstance.ts

Runtime binding for Compute Engine instances.start.

Bind this operation to an Instance in a Function/Action init phase. Provide StartInstanceHttp.

const startInstance = yield* GCP.Compute.StartInstance(vm);
yield* startInstance();

Source: src/GCP/Compute/StartInstanceHttp.ts Kind: Layer · Provides: GCP.Compute.StartInstance

HTTP implementation of StartInstance.

Grants roles/compute.instanceAdmin.v1 on the bound instance only, because no narrower predefined role contains compute.instances.start.

Source: src/GCP/Compute/StopInstance.ts

Runtime binding for Compute Engine instances.stop.

Bind this operation to an Instance in a Function/Action init phase. Provide StopInstanceHttp.

const stopInstance = yield* GCP.Compute.StopInstance(vm);
yield* stopInstance();

Source: src/GCP/Compute/StopInstanceHttp.ts Kind: Layer · Provides: GCP.Compute.StopInstance

HTTP implementation of StopInstance.

Grants roles/compute.instanceAdmin.v1 on the bound instance only, because no narrower predefined role contains compute.instances.stop.

Source: src/GCP/Compute/StoragePool.ts

A zonal Compute Engine Hyperdisk storage pool.

Storage pools pre-purchase Hyperdisk capacity, IOPS, and throughput. Changing zone, storagePoolType, capacityProvisioningType, or performanceProvisioningType replaces the pool. Capacity, IOPS, throughput, labels, and description update in place.

Hyperdisk Balanced pool

const pool = yield* GCP.Compute.StoragePool("disks", {
storagePoolType: "hyperdisk-balanced",
poolProvisionedCapacityGb: 10240,
poolProvisionedIops: 10000,
poolProvisionedThroughput: 1024,
labels: { env: "prod" },
});

Named pool in a specific zone

const pool = yield* GCP.Compute.StoragePool("disks", {
storagePoolName: "app-hyperdisk",
zone: "us-central1-a",
description: "shared hyperdisk capacity",
poolProvisionedCapacityGb: 10240,
});

Source: src/GCP/Compute/Subnetwork.ts

A Google Compute Engine VPC subnetwork (subnet).

Subnets are regional partitions of a VPC with one primary IPv4 range and optional secondary ranges. Compute Subnetwork has no labels field — Alchemy stamps alchemy-stack / alchemy-stage / alchemy-id into the description so list and pnpm nuke:gcp can identify owned subnets.

The parent VPC must be custom mode (autoCreateSubnetworks: false) unless you are attaching to an auto-mode network’s existing range.

Subnet in a custom-mode VPC

const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const subnet = yield* GCP.Compute.Subnetwork("Private", {
network: network.networkName,
ipCidrRange: "10.0.0.0/24",
});

Explicit name, region, and Private Google Access

const subnet = yield* GCP.Compute.Subnetwork("Private", {
subnetworkName: "app-private",
region: "us-central1",
network: "app-vpc",
ipCidrRange: "10.10.0.0/24",
privateIpGoogleAccess: true,
description: "application private subnet",
});
const subnet = yield* GCP.Compute.Subnetwork("Private", {
network: network.networkName,
ipCidrRange: "10.10.0.0/24",
secondaryIpRanges: [
{ rangeName: "pods", ipCidrRange: "10.10.1.0/24" },
],
});

Source: src/GCP/Compute/TargetGrpcProxy.ts

A global Compute Engine target gRPC proxy.

Target gRPC proxies are referenced by global forwarding rules with load-balancing scheme INTERNAL_SELF_MANAGED (Traffic Director) and point at a URL map whose backend services use protocol GRPC. This resource maps to the global targetGrpcProxies collection. Compute TargetGrpcProxy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked proxies.

TargetGrpcProxy: Creating a Target gRPC Proxy

Section titled “TargetGrpcProxy: Creating a Target gRPC Proxy”

Generated name in front of a gRPC URL map

const backend = yield* GCP.Compute.BackendService("grpc", {
protocol: "GRPC",
loadBalancingScheme: "INTERNAL_SELF_MANAGED",
});
const map = yield* GCP.Compute.UrlMap("grpc", {
defaultService: backend.selfLink,
});
const proxy = yield* GCP.Compute.TargetGrpcProxy("grpc", {
urlMap: map.urlMapName,
});

Explicit name, description, and proxyless validation

const proxy = yield* GCP.Compute.TargetGrpcProxy("grpc", {
targetGrpcProxyName: "app-grpc",
description: "traffic director frontend",
urlMap: map.selfLink,
validateForProxyless: true,
});

Source: src/GCP/Compute/TargetHttpProxy.ts

A global Compute Engine target HTTP proxy.

Target HTTP proxies are referenced by global forwarding rules and point at a URL map that routes host/path to a backend service, backend bucket, or redirect. This resource maps to the global targetHttpProxies collection (regionTargetHttpProxies is a separate resource). Compute TargetHttpProxy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked proxies.

TargetHttpProxy: Creating a Target HTTP Proxy

Section titled “TargetHttpProxy: Creating a Target HTTP Proxy”

Generated name in front of a URL map

const map = yield* GCP.Compute.UrlMap("web", {
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "example.com",
stripQuery: false,
},
});
const proxy = yield* GCP.Compute.TargetHttpProxy("http", {
urlMap: map.urlMapName,
});

Explicit name and description

const proxy = yield* GCP.Compute.TargetHttpProxy("http", {
targetHttpProxyName: "app-http",
description: "public http frontend",
urlMap: map.selfLink,
});

Source: src/GCP/Compute/TargetHttpsProxy.ts

A global Compute Engine target HTTPS proxy.

Target HTTPS proxies terminate HTTPS for global external Application Load Balancers, classic Application Load Balancers, cross-region internal Application Load Balancers, and Traffic Director. A forwarding rule points at the proxy; the proxy points at a URL map and one or more SSL certificates (or a Certificate Manager map).

This resource maps to the global targetHttpsProxies collection (regionTargetHttpsProxies is a separate resource). Compute TargetHttpsProxy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked proxies.

TargetHttpsProxy: Creating a Target HTTPS Proxy

Section titled “TargetHttpsProxy: Creating a Target HTTPS Proxy”

Generated name in front of a URL map

const map = yield* GCP.Compute.UrlMap("web", {
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "example.com",
stripQuery: false,
},
});
const cert = yield* GCP.Compute.SslCertificate("tls", {
certificate: pemCertificate,
privateKey: pemPrivateKey,
});
const proxy = yield* GCP.Compute.TargetHttpsProxy("https", {
urlMap: map.urlMapName,
sslCertificates: [cert.sslCertificateName],
});

Explicit name, QUIC, and description

const proxy = yield* GCP.Compute.TargetHttpsProxy("https", {
targetHttpsProxyName: "web-https",
urlMap: map.selfLink,
sslCertificates: [cert.selfLink],
quicOverride: "ENABLE",
description: "public https",
});

TargetHttpsProxy: Updating a Target HTTPS Proxy

Section titled “TargetHttpsProxy: Updating a Target HTTPS Proxy”
const proxy = yield* GCP.Compute.TargetHttpsProxy("https", {
targetHttpsProxyName: "web-https",
urlMap: map.urlMapName,
sslCertificates: [nextCert.sslCertificateName],
quicOverride: "ENABLE",
});

Source: src/GCP/Compute/TargetInstance.ts

A zonal Compute Engine target instance.

Target instances terminate protocol-forwarding traffic (ESP, AH, TCP, UDP) for one or more forwarding rules. The backend VM should enable IP forwarding (canIpForward). Compute TargetInstance has no labels field — Alchemy ownership is stored in the description so nuke can find leaked resources. Name, zone, instance, network, NAT policy, and description are immutable; only securityPolicy updates in place.

TargetInstance: Creating a Target Instance

Section titled “TargetInstance: Creating a Target Instance”

Generated name in front of a VM

const vm = yield* GCP.Compute.Instance("web", {
zone: "us-central1-a",
canIpForward: true,
});
const target = yield* GCP.Compute.TargetInstance("protocol", {
instance: vm.instanceName,
zone: vm.zone,
});

Explicit name, description, and network

const target = yield* GCP.Compute.TargetInstance("protocol", {
targetInstanceName: "app-protocol",
description: "esp frontend",
instance: vm.selfLink,
zone: "us-central1-a",
network: "default",
natPolicy: "NO_NAT",
});

Source: src/GCP/Compute/TargetPool.ts

A regional Compute Engine target pool.

Target pools are the backend for external network load balancers (target-pool forwarding rules). Members are zonal instances in the same region. Health checking uses legacy HttpHealthCheck resources only. Compute TargetPool has no labels field — Alchemy ownership is stored in the description so nuke can find leaked pools.

Generated name

const pool = yield* GCP.Compute.TargetPool("backends", {});

Named pool with session affinity

const pool = yield* GCP.Compute.TargetPool("backends", {
targetPoolName: "app-nlb",
region: "us-central1",
sessionAffinity: "CLIENT_IP",
description: "network load balancer",
});
const backup = yield* GCP.Compute.TargetPool("failover", {});
const primary = yield* GCP.Compute.TargetPool("backends", {
backupPool: backup.selfLink,
failoverRatio: 0.5,
});
const pool = yield* GCP.Compute.TargetPool("backends", {
instances: [
"projects/{project}/zones/us-central1-a/instances/web-1",
"us-central1-b/web-2",
],
});

Source: src/GCP/Compute/TargetSslProxy.ts

A global Compute Engine target SSL proxy.

Target SSL proxies terminate SSL/TLS for Proxy Network Load Balancers (SSL proxy). A forwarding rule points at the proxy; the proxy points at a backend service (protocol SSL) and one or more SSL certificates (or a Certificate Manager map).

This resource maps to the global targetSslProxies collection. Compute TargetSslProxy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked proxies. Description is immutable after create.

TargetSslProxy: Creating a Target SSL Proxy

Section titled “TargetSslProxy: Creating a Target SSL Proxy”

Generated name in front of an SSL backend

const check = yield* GCP.Compute.HealthCheck("ssl", {
type: "TCP",
tcpHealthCheck: { port: 443 },
});
const backend = yield* GCP.Compute.BackendService("ssl", {
protocol: "SSL",
healthChecks: [check.selfLink],
});
const cert = yield* GCP.Compute.SslCertificate("tls", {
certificate: pemCertificate,
privateKey: pemPrivateKey,
});
const proxy = yield* GCP.Compute.TargetSslProxy("ssl", {
service: backend.name,
sslCertificates: [cert.sslCertificateName],
});

Explicit name, PROXY protocol, and description

const proxy = yield* GCP.Compute.TargetSslProxy("ssl", {
targetSslProxyName: "web-ssl",
service: backend.selfLink,
sslCertificates: [cert.selfLink],
proxyHeader: "PROXY_V1",
description: "public ssl",
});

TargetSslProxy: Updating a Target SSL Proxy

Section titled “TargetSslProxy: Updating a Target SSL Proxy”
const proxy = yield* GCP.Compute.TargetSslProxy("ssl", {
targetSslProxyName: "web-ssl",
service: nextBackend.name,
sslCertificates: [nextCert.sslCertificateName],
proxyHeader: "PROXY_V1",
});

Source: src/GCP/Compute/TargetTcpProxy.ts

A global Compute Engine target TCP proxy.

Target TCP proxies are referenced by global forwarding rules and point at a backend service. They are a component of Proxy Network Load Balancers (classic and global external). This resource maps to the global targetTcpProxies collection (regionTargetTcpProxies is a separate resource). Compute TargetTcpProxy has no labels field — Alchemy ownership is stored in the description so nuke can find leaked proxies.

The API can update the backend service and proxy header in place. targetTcpProxyName, description, proxyBind, and loadBalancingScheme replace the resource.

TargetTcpProxy: Creating a Target TCP Proxy

Section titled “TargetTcpProxy: Creating a Target TCP Proxy”

Generated name in front of a TCP backend service

const backend = yield* GCP.Compute.BackendService("tcp", {
protocol: "TCP",
loadBalancingScheme: "EXTERNAL",
});
const proxy = yield* GCP.Compute.TargetTcpProxy("tcp", {
service: backend.name,
});

Explicit name, PROXY protocol, and description

const proxy = yield* GCP.Compute.TargetTcpProxy("tcp", {
targetTcpProxyName: "app-tcp",
description: "public tcp frontend",
service: backend.selfLink,
proxyHeader: "PROXY_V1",
});

TargetTcpProxy: Updating a Target TCP Proxy

Section titled “TargetTcpProxy: Updating a Target TCP Proxy”
const proxy = yield* GCP.Compute.TargetTcpProxy("tcp", {
targetTcpProxyName: "app-tcp",
service: otherBackend.name,
proxyHeader: "PROXY_V1",
});

Source: src/GCP/Compute/TargetVpnGateway.ts

A regional Compute Engine Classic VPN gateway (targetVpnGateway).

Classic VPN attaches a single gateway to a VPC in one region. Prefer HA VPN (VpnGateway) for new deployments. Labels are the only in-place update (targetVpnGateways.setLabels); name, region, network, and description replace the gateway.

TargetVpnGateway: Creating a TargetVpnGateway

Section titled “TargetVpnGateway: Creating a TargetVpnGateway”

Generated name on a custom VPC

const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const gateway = yield* GCP.Compute.TargetVpnGateway("Gateway", {
network: network.networkName,
});

Named gateway with labels

const gateway = yield* GCP.Compute.TargetVpnGateway("Gateway", {
targetVpnGatewayName: "app-classic-vpn",
region: "us-central1",
network: "default",
description: "classic vpn",
labels: { env: "prod" },
});

Source: src/GCP/Compute/UrlMap.ts

A global Compute Engine URL map.

URL maps route hostnames and URL paths to a backend service, backend bucket, or HTTP redirect. This resource maps to the global urlMaps collection (regionUrlMaps is a separate resource). Compute UrlMap has no labels field — Alchemy ownership is stored in the description so nuke can find leaked maps.

One of defaultService, defaultUrlRedirect, or defaultRouteAction.weightedBackendServices is required.

Generated name with a default HTTPS redirect

const map = yield* GCP.Compute.UrlMap("web", {
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "example.com",
stripQuery: false,
},
});

Host rules and path matchers

const map = yield* GCP.Compute.UrlMap("web", {
description: "public https",
defaultUrlRedirect: {
httpsRedirect: true,
stripQuery: false,
},
hostRules: [{ hosts: ["example.com"], pathMatcher: "all" }],
pathMatchers: [
{
name: "all",
defaultUrlRedirect: {
httpsRedirect: true,
hostRedirect: "www.example.com",
stripQuery: false,
},
},
],
});

Default backend service

const map = yield* GCP.Compute.UrlMap("web", {
defaultService: backend.selfLink,
});

Source: src/GCP/Compute/VpnGateway.ts

A regional Compute Engine HA VPN gateway.

HA VPN is a high-availability Cloud VPN that attaches two interfaces to a VPC in a single region. Labels are the only in-place update (vpnGateways.setLabels); name, region, network, description, IP version, stack type, and interconnect attachments replace the gateway.

Generated name on a custom VPC

const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const gateway = yield* GCP.Compute.VpnGateway("Gateway", {
network: network.networkName,
});

Named gateway with labels

const gateway = yield* GCP.Compute.VpnGateway("Gateway", {
vpnGatewayName: "app-vpn",
region: "us-central1",
network: "default",
description: "ha vpn",
labels: { env: "prod" },
});
const gateway = yield* GCP.Compute.VpnGateway("Gateway", {
network: "default",
stackType: "IPV4_IPV6",
});

Source: src/GCP/Compute/VpnTunnel.ts

A regional Compute Engine Cloud VPN tunnel.

HA VPN tunnels attach to a VpnGateway plus a Cloud Router and a peer (peerExternalGateway or peerGcpGateway). Classic VPN tunnels attach to a TargetVpnGateway and a peerIp. Labels are the only in-place update (vpnTunnels.setLabels); every other field replaces the tunnel.

HA VPN to an external peer

const network = yield* GCP.Compute.Network("Vpc", {
autoCreateSubnetworks: false,
});
const gateway = yield* GCP.Compute.VpnGateway("Gateway", {
network: network.networkName,
});
const router = yield* GCP.Compute.Router("Edge", {
network: network.networkName,
bgp: { asn: 64514 },
});
const peer = yield* GCP.Compute.ExternalVpnGateway("Peer", {
redundancyType: "SINGLE_IP_INTERNALLY_REDUNDANT",
interfaces: [{ id: 0, ipAddress: "15.0.0.120" }],
});
const tunnel = yield* GCP.Compute.VpnTunnel("Tunnel", {
vpnGateway: gateway.vpnGatewayName,
vpnGatewayInterface: 0,
peerExternalGateway: peer.externalVpnGatewayName,
peerExternalGatewayInterface: 0,
router: router.routerName,
sharedSecret: "replace-me-with-a-secret",
});

Named tunnel with labels

const tunnel = yield* GCP.Compute.VpnTunnel("Tunnel", {
vpnTunnelName: "app-tunnel",
region: "us-central1",
vpnGateway: "app-vpn",
vpnGatewayInterface: 0,
peerGcpGateway: "peer-vpn",
router: "app-router",
sharedSecret: "replace-me-with-a-secret",
labels: { env: "prod" },
});
const tunnel = yield* GCP.Compute.VpnTunnel("Tunnel", {
targetVpnGateway: gateway.targetVpnGatewayName,
peerIp: "15.0.0.120",
sharedSecret: "replace-me-with-a-secret",
localTrafficSelector: ["10.0.0.0/16"],
remoteTrafficSelector: ["172.16.0.0/16"],
});

Source: src/GCP/Compute/WireGroup.ts

A global Compute Engine wire group on a cross-site network.

Wire groups connect Interconnect endpoints across metros. Compute Engine has no labels on this resource, so Alchemy stamps ownership into the description so list / pnpm nuke:gcp can find them.

Name and parent crossSiteNetwork are immutable — changing them replaces the group. adminEnabled, wireProperties, endpoints, and description update in place via wireGroups.patch.

const wires = yield* GCP.Compute.WireGroup("metro", {
crossSiteNetwork: network.crossSiteNetworkName,
description: "nyc-to-sfo",
wireProperties: {
bandwidthUnmetered: "10",
bandwidthAllocation: "SHARED_WITH_WIRE_GROUP",
},
endpoints: {
nyc: {
interconnects: {
a: { interconnect: "global/interconnects/nyc-a", vlanTags: [100] },
},
},
sfo: {
interconnects: {
a: { interconnect: "global/interconnects/sfo-a", vlanTags: [100] },
},
},
},
});

Source: src/GCP/Compute/ZoneVmExtensionPolicy.ts

A zonal Compute Engine VM extension policy.

Zone VM extension policies install Google-provided extensions (Ops Agent, SAP, workload) on VMs that match label selectors. Compute Engine has no labels on this resource, so Alchemy stamps ownership into the description so list / pnpm nuke:gcp can find them.

Name and zone are immutable — changing them replaces the policy. Description, priority, selectors, and extension configurations update in place via zoneVmExtensionPolicies.patch.

ZoneVmExtensionPolicy: Creating a Zone VM Extension Policy

Section titled “ZoneVmExtensionPolicy: Creating a Zone VM Extension Policy”

Install Ops Agent on labeled VMs

const policy = yield* GCP.Compute.ZoneVmExtensionPolicy("Ops", {
zone: "us-central1-a",
extensionPolicies: {
"ops-agent": { pinnedVersion: "2.58.0" },
},
instanceSelectors: [
{ labelSelector: { inclusionLabels: { env: "prod" } } },
],
});

Named policy with a description

const policy = yield* GCP.Compute.ZoneVmExtensionPolicy("Ops", {
vmExtensionPolicyName: "ops-agent-prod",
description: "ops-agent for prod VMs",
priority: 500,
extensionPolicies: { "ops-agent": {} },
instanceSelectors: [
{ labelSelector: { inclusionLabels: { role: "app" } } },
],
});