GCP.DLP reference
ContentPolicy
Section titled “ContentPolicy”Source:
src/GCP/DLP/ContentPolicy.ts
A location-scoped Cloud DLP content policy.
Content policies have no labels field, so Alchemy stamps ownership
into the display name for list / nuke. Location and id are identity
— changing them replaces the policy. Display name, inspect config, and
rules update in place.
ContentPolicy: Creating a Content Policy
Section titled “ContentPolicy: Creating a Content Policy”const policy = yield* GCP.DLP.ContentPolicy("BlockEmail", { displayName: "block-email", inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] }, rules: [ { conditions: [ { infoTypeCondition: { infoTypes: { infoTypeNames: ["EMAIL_ADDRESS"] }, }, }, ], action: { returnVerdict: "BLOCK" }, }, ], defaultAction: { returnVerdict: "ALLOW" },});DeidentifyTemplate
Section titled “DeidentifyTemplate”Source:
src/GCP/DLP/DeidentifyTemplate.ts
A project-scoped Cloud DLP de-identify template.
Templates have no labels field, so Alchemy stamps ownership into the
description for list / nuke. Template id is identity — changing it
replaces the template. Display name, description, and de-identify
config update in place.
DeidentifyTemplate: Creating a Deidentify Template
Section titled “DeidentifyTemplate: Creating a Deidentify Template”const template = yield* GCP.DLP.DeidentifyTemplate("Emails", { displayName: "redact emails", description: "replace email findings", deidentifyConfig: { infoTypeTransformations: { transformations: [ { infoTypes: [{ name: "EMAIL_ADDRESS" }], primitiveTransformation: { replaceWithInfoTypeConfig: {} }, }, ], }, },});DeidentifyTemplate: Updating a Deidentify Template
Section titled “DeidentifyTemplate: Updating a Deidentify Template”const template = yield* GCP.DLP.DeidentifyTemplate("Emails", { displayName: "redact emails and phones", deidentifyConfig: { infoTypeTransformations: { transformations: [ { infoTypes: [ { name: "EMAIL_ADDRESS" }, { name: "PHONE_NUMBER" }, ], primitiveTransformation: { replaceWithInfoTypeConfig: {} }, }, ], }, },});DiscoveryConfig
Section titled “DiscoveryConfig”Source:
src/GCP/DLP/DiscoveryConfig.ts
A location-scoped Cloud DLP discovery config.
Discovery configs have no labels field, so Alchemy stamps ownership
into the display name for list / nuke. Location and id are identity
— changing them replaces the config. Display name, status, targets,
and templates update in place.
DiscoveryConfig: Creating a Discovery Config
Section titled “DiscoveryConfig: Creating a Discovery Config”const template = yield* GCP.DLP.LocationsInspectTemplate("Emails", { location: "us", inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },});const config = yield* GCP.DLP.DiscoveryConfig("Profiles", { location: "us", displayName: "paused storage", status: "PAUSED", inspectTemplates: [template.name], targets: [ { cloudStorageTarget: { filter: { others: {} }, disabled: {}, }, }, ],});DlpJob
Section titled “DlpJob”Source:
src/GCP/DLP/DlpJob.ts
A project-scoped Cloud DLP inspect or risk-analysis job.
DLP jobs have no labels or description field. For inspect jobs Alchemy
stamps ownership into storageConfig.hybridOptions.labels so list /
nuke can find them. Jobs are not updatable — changing jobId,
inspectJob, or riskJob replaces the job.
DlpJob: Creating a DLP Job
Section titled “DlpJob: Creating a DLP Job”const job = yield* GCP.DLP.DlpJob("Scan", { inspectJob: { inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] }, storageConfig: { hybridOptions: { description: "hybrid scan" } }, },});InspectTemplate
Section titled “InspectTemplate”Source:
src/GCP/DLP/InspectTemplate.ts
A project-scoped Cloud DLP inspect template.
Templates have no labels field, so Alchemy stamps ownership into the
description for list / nuke. Template id is identity — changing it
replaces the template. Display name, description, and inspect config
update in place.
InspectTemplate: Creating an Inspect Template
Section titled “InspectTemplate: Creating an Inspect Template”const template = yield* GCP.DLP.InspectTemplate("Emails", { displayName: "emails", description: "find email addresses", inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }], includeQuote: true, },});InspectTemplate: Updating an Inspect Template
Section titled “InspectTemplate: Updating an Inspect Template”const template = yield* GCP.DLP.InspectTemplate("Emails", { displayName: "emails and phones", inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }, { name: "PHONE_NUMBER" }], includeQuote: true, },});JobTrigger
Section titled “JobTrigger”Source:
src/GCP/DLP/JobTrigger.ts
A project-scoped Cloud DLP job trigger.
Job triggers have no labels field, so Alchemy stamps ownership into
the description for list / nuke. Trigger id is identity — changing
it replaces the trigger. Display name, description, status, inspect
job, and schedule update in place.
JobTrigger: Creating a Job Trigger
Section titled “JobTrigger: Creating a Job Trigger”const trigger = yield* GCP.DLP.JobTrigger("Nightly", { displayName: "nightly hybrid", status: "PAUSED", inspectJob: { inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] }, storageConfig: { hybridOptions: { description: "hybrid" } }, }, triggers: [{ manual: {} }],});JobTrigger: Updating a Job Trigger
Section titled “JobTrigger: Updating a Job Trigger”const trigger = yield* GCP.DLP.JobTrigger("Nightly", { displayName: "nightly hybrid v2", status: "PAUSED", inspectJob: { inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] }, storageConfig: { hybridOptions: { description: "hybrid" } }, }, triggers: [{ manual: {} }],});LocationsDeidentifyTemplate
Section titled “LocationsDeidentifyTemplate”Source:
src/GCP/DLP/LocationsDeidentifyTemplate.ts
A location-scoped Cloud DLP de-identify template.
Templates have no labels field, so Alchemy stamps ownership into the
description for list / nuke. Location and template id are identity —
changing them replaces the template. Display name, description, and
de-identify config update in place.
LocationsDeidentifyTemplate: Creating a Location Deidentify Template
Section titled “LocationsDeidentifyTemplate: Creating a Location Deidentify Template”const template = yield* GCP.DLP.LocationsDeidentifyTemplate("Emails", { location: "global", displayName: "redact emails", deidentifyConfig: { infoTypeTransformations: { transformations: [ { infoTypes: [{ name: "EMAIL_ADDRESS" }], primitiveTransformation: { replaceWithInfoTypeConfig: {} }, }, ], }, },});LocationsDlpJob
Section titled “LocationsDlpJob”Source:
src/GCP/DLP/LocationsDlpJob.ts
A regional Cloud DLP job (projects.locations.dlpJobs).
Creating a DlpJob starts it immediately. Inspect jobs are stored as
i-{jobId} and risk jobs as r-{jobId}. There is no update API, so
reconcile is observe-ensure (create if missing). Delete cancels a
running/active job, then deletes it. DLP jobs have no labels field —
Alchemy stamps ownership into hybrid inspect storageConfig.hybridOptions
(labels + description) so list / nuke can find them.
LocationsDlpJob: Creating a DLP Job
Section titled “LocationsDlpJob: Creating a DLP Job”const job = yield* GCP.DLP.LocationsDlpJob("Scan", { inspectJob: { inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] }, storageConfig: { hybridOptions: { description: "inbox" } }, },});LocationsInspectTemplate
Section titled “LocationsInspectTemplate”Source:
src/GCP/DLP/LocationsInspectTemplate.ts
A regional Cloud DLP inspect template
(projects.locations.inspectTemplates).
Inspect templates have no labels field, so Alchemy stamps ownership
into the description for list / nuke. Location and id are identity —
changing them replaces the template. Display name, description, and
inspect config update in place.
LocationsInspectTemplate: Creating an Inspect Template
Section titled “LocationsInspectTemplate: Creating an Inspect Template”const template = yield* GCP.DLP.LocationsInspectTemplate("Email", { displayName: "email", description: "detect email addresses", inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },});LocationsInspectTemplate: Updating an Inspect Template
Section titled “LocationsInspectTemplate: Updating an Inspect Template”const template = yield* GCP.DLP.LocationsInspectTemplate("Email", { displayName: "email", description: "detect email addresses v2", inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }], minLikelihood: "LIKELY", includeQuote: true, },});LocationsJobTrigger
Section titled “LocationsJobTrigger”Source:
src/GCP/DLP/LocationsJobTrigger.ts
A regional Cloud DLP job trigger (projects.locations.jobTriggers).
Job triggers have no labels field, so Alchemy stamps ownership into the
description for list / nuke. Location and id are identity — changing
them replaces the trigger. Display name, description, status, inspect
job, and triggers update in place.
LocationsJobTrigger: Creating a Job Trigger
Section titled “LocationsJobTrigger: Creating a Job Trigger”const trigger = yield* GCP.DLP.LocationsJobTrigger("Inbox", { displayName: "inbox scan", description: "paused hybrid inspect", status: "PAUSED", inspectJob: { inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] }, storageConfig: { hybridOptions: {} }, }, triggers: [{ manual: {} }],});LocationsJobTrigger: Updating a Job Trigger
Section titled “LocationsJobTrigger: Updating a Job Trigger”const trigger = yield* GCP.DLP.LocationsJobTrigger("Inbox", { displayName: "inbox scan", description: "paused hybrid inspect v2", status: "PAUSED", inspectJob: { inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] }, storageConfig: { hybridOptions: {} }, }, triggers: [{ manual: {} }],});LocationsStoredInfoType
Section titled “LocationsStoredInfoType”Source:
src/GCP/DLP/LocationsStoredInfoType.ts
A regional Cloud DLP stored info type
(projects.locations.storedInfoTypes).
Stored info types have no labels field, so Alchemy stamps ownership
into the config description for list / nuke. Location and id are
identity — changing them replaces the resource. Display name,
description, and detector config update in place (a new version).
LocationsStoredInfoType: Creating a Stored Info Type
Section titled “LocationsStoredInfoType: Creating a Stored Info Type”const infoType = yield* GCP.DLP.LocationsStoredInfoType("Badge", { displayName: "badge numbers", description: "employee badges", regex: { pattern: "EMP[0-9]{6}" },});LocationsStoredInfoType: Updating a Stored Info Type
Section titled “LocationsStoredInfoType: Updating a Stored Info Type”const infoType = yield* GCP.DLP.LocationsStoredInfoType("Badge", { displayName: "badge numbers", description: "employee badges v2", regex: { pattern: "EMP[0-9]{8}" },});OrganizationsDeidentifyTemplate
Section titled “OrganizationsDeidentifyTemplate”Source:
src/GCP/DLP/OrganizationsDeidentifyTemplate.ts
An organization-scoped Sensitive Data Protection de-identify template.
Templates have no labels field — Alchemy stamps ownership into the
description so list / nuke can find them. Template id and organization
are identity. Display name, description, and de-identify config update
in place.
OrganizationsDeidentifyTemplate: Creating a Deidentify Template
Section titled “OrganizationsDeidentifyTemplate: Creating a Deidentify Template”Redact matched infoTypes
const template = yield* GCP.DLP.OrganizationsDeidentifyTemplate( "RedactEmail", { displayName: "redact-email", deidentifyConfig: { infoTypeTransformations: { transformations: [ { primitiveTransformation: { replaceWithInfoTypeConfig: {} }, }, ], }, }, },);Named template on an explicit organization
const template = yield* GCP.DLP.OrganizationsDeidentifyTemplate( "RedactEmail", { organization: "organizations/123456789", templateId: "redact-email", deidentifyConfig: { infoTypeTransformations: { transformations: [ { primitiveTransformation: { replaceWithInfoTypeConfig: {} }, }, ], }, }, },);OrganizationsInspectTemplate
Section titled “OrganizationsInspectTemplate”Source:
src/GCP/DLP/OrganizationsInspectTemplate.ts
An organization-scoped Sensitive Data Protection inspect template.
Templates have no labels field — Alchemy stamps ownership into the
description so list / nuke can find them. Template id and organization
are identity. Display name, description, and inspect config update in
place.
OrganizationsInspectTemplate: Creating an Inspect Template
Section titled “OrganizationsInspectTemplate: Creating an Inspect Template”Detect email addresses
const template = yield* GCP.DLP.OrganizationsInspectTemplate("Emails", { displayName: "emails", inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }], includeQuote: true, },});Named template on an explicit organization
const template = yield* GCP.DLP.OrganizationsInspectTemplate("Emails", { organization: "organizations/123456789", templateId: "emails", inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }], },});OrganizationsLocationsConnection
Section titled “OrganizationsLocationsConnection”Source:
src/GCP/DLP/OrganizationsLocationsConnection.ts
An organization-scoped Sensitive Data Protection connection to an external data source (Cloud SQL).
Connections have no labels or description field, so list returns an
empty set — nuke cannot discover them from the cloud. Organization,
location, Cloud SQL connectionName, and databaseEngine are identity.
State, credentials, and maxConnections update in place. The connection
id is assigned by the API.
OrganizationsLocationsConnection: Creating a Connection
Section titled “OrganizationsLocationsConnection: Creating a Connection”const connection = yield* GCP.DLP.OrganizationsLocationsConnection( "Warehouse", { location: "us-central1", state: "AVAILABLE", cloudSql: { connectionName: "my-project:us-central1:warehouse", databaseEngine: "DATABASE_ENGINE_POSTGRES", maxConnections: 2, cloudSqlIam: {}, }, },);OrganizationsLocationsDeidentifyTemplate
Section titled “OrganizationsLocationsDeidentifyTemplate”Source:
src/GCP/DLP/OrganizationsLocationsDeidentifyTemplate.ts
A location-scoped Sensitive Data Protection de-identify template on an organization.
Templates have no labels field — Alchemy stamps ownership into the
description so list / nuke can find them. Template id, organization,
and location are identity. Display name, description, and de-identify
config update in place.
OrganizationsLocationsDeidentifyTemplate: Creating a Location Deidentify Template
Section titled “OrganizationsLocationsDeidentifyTemplate: Creating a Location Deidentify Template”const template = yield* GCP.DLP.OrganizationsLocationsDeidentifyTemplate( "RedactPhone", { location: "us-central1", deidentifyConfig: { infoTypeTransformations: { transformations: [ { primitiveTransformation: { replaceWithInfoTypeConfig: {} }, }, ], }, }, },);OrganizationsLocationsDiscoveryConfig
Section titled “OrganizationsLocationsDiscoveryConfig”Source:
src/GCP/DLP/OrganizationsLocationsDiscoveryConfig.ts
An organization-scoped Sensitive Data Protection discovery config that scans storage and builds data profiles.
Discovery configs have no labels field — Alchemy stamps ownership into
the display name so list / nuke can find them. Config id, organization,
and location are identity. Status, targets, and org config update in
place. Keep status as PAUSED unless the organization should be
scanned.
OrganizationsLocationsDiscoveryConfig: Creating a Discovery Config
Section titled “OrganizationsLocationsDiscoveryConfig: Creating a Discovery Config”const config = yield* GCP.DLP.OrganizationsLocationsDiscoveryConfig( "OrgProfiles", { status: "PAUSED", orgConfig: { projectId: "my-project", location: { organizationId: "123456789" }, }, targets: [ { bigQueryTarget: { filter: { otherTables: {} }, disabled: {}, }, }, ], },);OrganizationsLocationsInspectTemplate
Section titled “OrganizationsLocationsInspectTemplate”Source:
src/GCP/DLP/OrganizationsLocationsInspectTemplate.ts
A location-scoped Sensitive Data Protection inspect template on an organization.
Templates have no labels field — Alchemy stamps ownership into the
description so list / nuke can find them. Template id, organization,
and location are identity. Display name, description, and inspect
config update in place.
OrganizationsLocationsInspectTemplate: Creating a Location Inspect Template
Section titled “OrganizationsLocationsInspectTemplate: Creating a Location Inspect Template”const template = yield* GCP.DLP.OrganizationsLocationsInspectTemplate( "Phones", { location: "us-central1", inspectConfig: { infoTypes: [{ name: "PHONE_NUMBER" }], includeQuote: true, }, },);OrganizationsLocationsJobTrigger
Section titled “OrganizationsLocationsJobTrigger”Source:
src/GCP/DLP/OrganizationsLocationsJobTrigger.ts
An organization-scoped Sensitive Data Protection job trigger that inspects storage on a schedule.
Job triggers have no labels field — Alchemy stamps ownership into the
description so list / nuke can find them. Trigger id, organization,
and location are identity. Display name, description, status, triggers,
and inspect job update in place. Keep status as PAUSED unless jobs
should run.
OrganizationsLocationsJobTrigger: Creating a Job Trigger
Section titled “OrganizationsLocationsJobTrigger: Creating a Job Trigger”const trigger = yield* GCP.DLP.OrganizationsLocationsJobTrigger( "ScanBucket", { status: "PAUSED", triggers: [ { schedule: { recurrencePeriodDuration: "86400s" } }, ], inspectJob: { inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] }, storageConfig: { cloudStorageOptions: { fileSet: { url: "gs://my-bucket/" }, }, }, }, },);OrganizationsLocationsStoredInfoType
Section titled “OrganizationsLocationsStoredInfoType”Source:
src/GCP/DLP/OrganizationsLocationsStoredInfoType.ts
An organization-scoped Sensitive Data Protection stored infoType (custom dictionary or regex detector).
Stored infoTypes have no labels field — Alchemy stamps ownership into
config.description so list / nuke can find them. Id, organization,
and location are identity. Config updates create a new version.
OrganizationsLocationsStoredInfoType: Creating a Stored InfoType
Section titled “OrganizationsLocationsStoredInfoType: Creating a Stored InfoType”const infoType = yield* GCP.DLP.OrganizationsLocationsStoredInfoType( "EmployeeIds", { location: "us-central1", config: { displayName: "employee-ids", dictionary: { wordList: { words: ["E12345", "E67890"] } }, }, },);OrganizationStoredInfoType
Section titled “OrganizationStoredInfoType”Source:
src/GCP/DLP/OrganizationStoredInfoType.ts
An organization-scoped Cloud DLP stored info type.
Stored info types have no labels field, so Alchemy stamps ownership
into the config description for list / nuke. Organization and id are
identity — changing them replaces the resource. Display name,
description, and detector config update in place (a new version).
OrganizationStoredInfoType: Creating a Stored Info Type
Section titled “OrganizationStoredInfoType: Creating a Stored Info Type”const infoType = yield* GCP.DLP.OrganizationStoredInfoType("EmployeeId", { displayName: "employee ids", description: "badge numbers", regex: { pattern: "EMP[0-9]{6}" },});OrganizationStoredInfoType: Updating a Stored Info Type
Section titled “OrganizationStoredInfoType: Updating a Stored Info Type”const infoType = yield* GCP.DLP.OrganizationStoredInfoType("EmployeeId", { displayName: "employee ids", description: "badge numbers v2", regex: { pattern: "EMP[0-9]{8}" },});StoredInfoType
Section titled “StoredInfoType”Source:
src/GCP/DLP/StoredInfoType.ts
A project-scoped Cloud DLP stored info type
(projects.storedInfoTypes, global processing location).
Stored info types have no labels field, so Alchemy stamps ownership
into the config description for list / nuke. Id is identity —
changing it replaces the resource. Display name, description, and
detector config update in place (a new version).
StoredInfoType: Creating a Stored Info Type
Section titled “StoredInfoType: Creating a Stored Info Type”const infoType = yield* GCP.DLP.StoredInfoType("Account", { displayName: "account ids", description: "internal account numbers", regex: { pattern: "ACCT[0-9]{8}" },});StoredInfoType: Updating a Stored Info Type
Section titled “StoredInfoType: Updating a Stored Info Type”const infoType = yield* GCP.DLP.StoredInfoType("Account", { displayName: "account ids", description: "internal account numbers v2", regex: { pattern: "ACCT[0-9]{10}" },});