Skip to content

GCP.DLP reference

Source: src/GCP/DLP/ContentPolicy.ts

A location-scoped Cloud DLP content policy.

Content policies have no labels field, so Alchemy stamps ownership into the display name for list / nuke. Location and id are identity — changing them replaces the policy. Display name, inspect config, and rules update in place.

const policy = yield* GCP.DLP.ContentPolicy("BlockEmail", {
displayName: "block-email",
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
rules: [
{
conditions: [
{
infoTypeCondition: {
infoTypes: { infoTypeNames: ["EMAIL_ADDRESS"] },
},
},
],
action: { returnVerdict: "BLOCK" },
},
],
defaultAction: { returnVerdict: "ALLOW" },
});

Source: src/GCP/DLP/DeidentifyTemplate.ts

A project-scoped Cloud DLP de-identify template.

Templates have no labels field, so Alchemy stamps ownership into the description for list / nuke. Template id is identity — changing it replaces the template. Display name, description, and de-identify config update in place.

DeidentifyTemplate: Creating a Deidentify Template

Section titled “DeidentifyTemplate: Creating a Deidentify Template”
const template = yield* GCP.DLP.DeidentifyTemplate("Emails", {
displayName: "redact emails",
description: "replace email findings",
deidentifyConfig: {
infoTypeTransformations: {
transformations: [
{
infoTypes: [{ name: "EMAIL_ADDRESS" }],
primitiveTransformation: { replaceWithInfoTypeConfig: {} },
},
],
},
},
});

DeidentifyTemplate: Updating a Deidentify Template

Section titled “DeidentifyTemplate: Updating a Deidentify Template”
const template = yield* GCP.DLP.DeidentifyTemplate("Emails", {
displayName: "redact emails and phones",
deidentifyConfig: {
infoTypeTransformations: {
transformations: [
{
infoTypes: [
{ name: "EMAIL_ADDRESS" },
{ name: "PHONE_NUMBER" },
],
primitiveTransformation: { replaceWithInfoTypeConfig: {} },
},
],
},
},
});

Source: src/GCP/DLP/DiscoveryConfig.ts

A location-scoped Cloud DLP discovery config.

Discovery configs have no labels field, so Alchemy stamps ownership into the display name for list / nuke. Location and id are identity — changing them replaces the config. Display name, status, targets, and templates update in place.

DiscoveryConfig: Creating a Discovery Config

Section titled “DiscoveryConfig: Creating a Discovery Config”
const template = yield* GCP.DLP.LocationsInspectTemplate("Emails", {
location: "us",
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
});
const config = yield* GCP.DLP.DiscoveryConfig("Profiles", {
location: "us",
displayName: "paused storage",
status: "PAUSED",
inspectTemplates: [template.name],
targets: [
{
cloudStorageTarget: {
filter: { others: {} },
disabled: {},
},
},
],
});

Source: src/GCP/DLP/DlpJob.ts

A project-scoped Cloud DLP inspect or risk-analysis job.

DLP jobs have no labels or description field. For inspect jobs Alchemy stamps ownership into storageConfig.hybridOptions.labels so list / nuke can find them. Jobs are not updatable — changing jobId, inspectJob, or riskJob replaces the job.

const job = yield* GCP.DLP.DlpJob("Scan", {
inspectJob: {
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
storageConfig: { hybridOptions: { description: "hybrid scan" } },
},
});

Source: src/GCP/DLP/InspectTemplate.ts

A project-scoped Cloud DLP inspect template.

Templates have no labels field, so Alchemy stamps ownership into the description for list / nuke. Template id is identity — changing it replaces the template. Display name, description, and inspect config update in place.

InspectTemplate: Creating an Inspect Template

Section titled “InspectTemplate: Creating an Inspect Template”
const template = yield* GCP.DLP.InspectTemplate("Emails", {
displayName: "emails",
description: "find email addresses",
inspectConfig: {
infoTypes: [{ name: "EMAIL_ADDRESS" }],
includeQuote: true,
},
});

InspectTemplate: Updating an Inspect Template

Section titled “InspectTemplate: Updating an Inspect Template”
const template = yield* GCP.DLP.InspectTemplate("Emails", {
displayName: "emails and phones",
inspectConfig: {
infoTypes: [{ name: "EMAIL_ADDRESS" }, { name: "PHONE_NUMBER" }],
includeQuote: true,
},
});

Source: src/GCP/DLP/JobTrigger.ts

A project-scoped Cloud DLP job trigger.

Job triggers have no labels field, so Alchemy stamps ownership into the description for list / nuke. Trigger id is identity — changing it replaces the trigger. Display name, description, status, inspect job, and schedule update in place.

const trigger = yield* GCP.DLP.JobTrigger("Nightly", {
displayName: "nightly hybrid",
status: "PAUSED",
inspectJob: {
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
storageConfig: { hybridOptions: { description: "hybrid" } },
},
triggers: [{ manual: {} }],
});
const trigger = yield* GCP.DLP.JobTrigger("Nightly", {
displayName: "nightly hybrid v2",
status: "PAUSED",
inspectJob: {
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
storageConfig: { hybridOptions: { description: "hybrid" } },
},
triggers: [{ manual: {} }],
});

Source: src/GCP/DLP/LocationsDeidentifyTemplate.ts

A location-scoped Cloud DLP de-identify template.

Templates have no labels field, so Alchemy stamps ownership into the description for list / nuke. Location and template id are identity — changing them replaces the template. Display name, description, and de-identify config update in place.

LocationsDeidentifyTemplate: Creating a Location Deidentify Template

Section titled “LocationsDeidentifyTemplate: Creating a Location Deidentify Template”
const template = yield* GCP.DLP.LocationsDeidentifyTemplate("Emails", {
location: "global",
displayName: "redact emails",
deidentifyConfig: {
infoTypeTransformations: {
transformations: [
{
infoTypes: [{ name: "EMAIL_ADDRESS" }],
primitiveTransformation: { replaceWithInfoTypeConfig: {} },
},
],
},
},
});

Source: src/GCP/DLP/LocationsDlpJob.ts

A regional Cloud DLP job (projects.locations.dlpJobs).

Creating a DlpJob starts it immediately. Inspect jobs are stored as i-{jobId} and risk jobs as r-{jobId}. There is no update API, so reconcile is observe-ensure (create if missing). Delete cancels a running/active job, then deletes it. DLP jobs have no labels field — Alchemy stamps ownership into hybrid inspect storageConfig.hybridOptions (labels + description) so list / nuke can find them.

const job = yield* GCP.DLP.LocationsDlpJob("Scan", {
inspectJob: {
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
storageConfig: { hybridOptions: { description: "inbox" } },
},
});

Source: src/GCP/DLP/LocationsInspectTemplate.ts

A regional Cloud DLP inspect template (projects.locations.inspectTemplates).

Inspect templates have no labels field, so Alchemy stamps ownership into the description for list / nuke. Location and id are identity — changing them replaces the template. Display name, description, and inspect config update in place.

LocationsInspectTemplate: Creating an Inspect Template

Section titled “LocationsInspectTemplate: Creating an Inspect Template”
const template = yield* GCP.DLP.LocationsInspectTemplate("Email", {
displayName: "email",
description: "detect email addresses",
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
});

LocationsInspectTemplate: Updating an Inspect Template

Section titled “LocationsInspectTemplate: Updating an Inspect Template”
const template = yield* GCP.DLP.LocationsInspectTemplate("Email", {
displayName: "email",
description: "detect email addresses v2",
inspectConfig: {
infoTypes: [{ name: "EMAIL_ADDRESS" }],
minLikelihood: "LIKELY",
includeQuote: true,
},
});

Source: src/GCP/DLP/LocationsJobTrigger.ts

A regional Cloud DLP job trigger (projects.locations.jobTriggers).

Job triggers have no labels field, so Alchemy stamps ownership into the description for list / nuke. Location and id are identity — changing them replaces the trigger. Display name, description, status, inspect job, and triggers update in place.

LocationsJobTrigger: Creating a Job Trigger

Section titled “LocationsJobTrigger: Creating a Job Trigger”
const trigger = yield* GCP.DLP.LocationsJobTrigger("Inbox", {
displayName: "inbox scan",
description: "paused hybrid inspect",
status: "PAUSED",
inspectJob: {
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
storageConfig: { hybridOptions: {} },
},
triggers: [{ manual: {} }],
});

LocationsJobTrigger: Updating a Job Trigger

Section titled “LocationsJobTrigger: Updating a Job Trigger”
const trigger = yield* GCP.DLP.LocationsJobTrigger("Inbox", {
displayName: "inbox scan",
description: "paused hybrid inspect v2",
status: "PAUSED",
inspectJob: {
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
storageConfig: { hybridOptions: {} },
},
triggers: [{ manual: {} }],
});

Source: src/GCP/DLP/LocationsStoredInfoType.ts

A regional Cloud DLP stored info type (projects.locations.storedInfoTypes).

Stored info types have no labels field, so Alchemy stamps ownership into the config description for list / nuke. Location and id are identity — changing them replaces the resource. Display name, description, and detector config update in place (a new version).

LocationsStoredInfoType: Creating a Stored Info Type

Section titled “LocationsStoredInfoType: Creating a Stored Info Type”
const infoType = yield* GCP.DLP.LocationsStoredInfoType("Badge", {
displayName: "badge numbers",
description: "employee badges",
regex: { pattern: "EMP[0-9]{6}" },
});

LocationsStoredInfoType: Updating a Stored Info Type

Section titled “LocationsStoredInfoType: Updating a Stored Info Type”
const infoType = yield* GCP.DLP.LocationsStoredInfoType("Badge", {
displayName: "badge numbers",
description: "employee badges v2",
regex: { pattern: "EMP[0-9]{8}" },
});

Source: src/GCP/DLP/OrganizationsDeidentifyTemplate.ts

An organization-scoped Sensitive Data Protection de-identify template.

Templates have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Template id and organization are identity. Display name, description, and de-identify config update in place.

OrganizationsDeidentifyTemplate: Creating a Deidentify Template

Section titled “OrganizationsDeidentifyTemplate: Creating a Deidentify Template”

Redact matched infoTypes

const template = yield* GCP.DLP.OrganizationsDeidentifyTemplate(
"RedactEmail",
{
displayName: "redact-email",
deidentifyConfig: {
infoTypeTransformations: {
transformations: [
{
primitiveTransformation: { replaceWithInfoTypeConfig: {} },
},
],
},
},
},
);

Named template on an explicit organization

const template = yield* GCP.DLP.OrganizationsDeidentifyTemplate(
"RedactEmail",
{
organization: "organizations/123456789",
templateId: "redact-email",
deidentifyConfig: {
infoTypeTransformations: {
transformations: [
{
primitiveTransformation: { replaceWithInfoTypeConfig: {} },
},
],
},
},
},
);

Source: src/GCP/DLP/OrganizationsInspectTemplate.ts

An organization-scoped Sensitive Data Protection inspect template.

Templates have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Template id and organization are identity. Display name, description, and inspect config update in place.

OrganizationsInspectTemplate: Creating an Inspect Template

Section titled “OrganizationsInspectTemplate: Creating an Inspect Template”

Detect email addresses

const template = yield* GCP.DLP.OrganizationsInspectTemplate("Emails", {
displayName: "emails",
inspectConfig: {
infoTypes: [{ name: "EMAIL_ADDRESS" }],
includeQuote: true,
},
});

Named template on an explicit organization

const template = yield* GCP.DLP.OrganizationsInspectTemplate("Emails", {
organization: "organizations/123456789",
templateId: "emails",
inspectConfig: {
infoTypes: [{ name: "EMAIL_ADDRESS" }],
},
});

Source: src/GCP/DLP/OrganizationsLocationsConnection.ts

An organization-scoped Sensitive Data Protection connection to an external data source (Cloud SQL).

Connections have no labels or description field, so list returns an empty set — nuke cannot discover them from the cloud. Organization, location, Cloud SQL connectionName, and databaseEngine are identity. State, credentials, and maxConnections update in place. The connection id is assigned by the API.

OrganizationsLocationsConnection: Creating a Connection

Section titled “OrganizationsLocationsConnection: Creating a Connection”
const connection = yield* GCP.DLP.OrganizationsLocationsConnection(
"Warehouse",
{
location: "us-central1",
state: "AVAILABLE",
cloudSql: {
connectionName: "my-project:us-central1:warehouse",
databaseEngine: "DATABASE_ENGINE_POSTGRES",
maxConnections: 2,
cloudSqlIam: {},
},
},
);

Source: src/GCP/DLP/OrganizationsLocationsDeidentifyTemplate.ts

A location-scoped Sensitive Data Protection de-identify template on an organization.

Templates have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Template id, organization, and location are identity. Display name, description, and de-identify config update in place.

OrganizationsLocationsDeidentifyTemplate: Creating a Location Deidentify Template

Section titled “OrganizationsLocationsDeidentifyTemplate: Creating a Location Deidentify Template”
const template = yield* GCP.DLP.OrganizationsLocationsDeidentifyTemplate(
"RedactPhone",
{
location: "us-central1",
deidentifyConfig: {
infoTypeTransformations: {
transformations: [
{
primitiveTransformation: { replaceWithInfoTypeConfig: {} },
},
],
},
},
},
);

Source: src/GCP/DLP/OrganizationsLocationsDiscoveryConfig.ts

An organization-scoped Sensitive Data Protection discovery config that scans storage and builds data profiles.

Discovery configs have no labels field — Alchemy stamps ownership into the display name so list / nuke can find them. Config id, organization, and location are identity. Status, targets, and org config update in place. Keep status as PAUSED unless the organization should be scanned.

OrganizationsLocationsDiscoveryConfig: Creating a Discovery Config

Section titled “OrganizationsLocationsDiscoveryConfig: Creating a Discovery Config”
const config = yield* GCP.DLP.OrganizationsLocationsDiscoveryConfig(
"OrgProfiles",
{
status: "PAUSED",
orgConfig: {
projectId: "my-project",
location: { organizationId: "123456789" },
},
targets: [
{
bigQueryTarget: {
filter: { otherTables: {} },
disabled: {},
},
},
],
},
);

Source: src/GCP/DLP/OrganizationsLocationsInspectTemplate.ts

A location-scoped Sensitive Data Protection inspect template on an organization.

Templates have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Template id, organization, and location are identity. Display name, description, and inspect config update in place.

OrganizationsLocationsInspectTemplate: Creating a Location Inspect Template

Section titled “OrganizationsLocationsInspectTemplate: Creating a Location Inspect Template”
const template = yield* GCP.DLP.OrganizationsLocationsInspectTemplate(
"Phones",
{
location: "us-central1",
inspectConfig: {
infoTypes: [{ name: "PHONE_NUMBER" }],
includeQuote: true,
},
},
);

Source: src/GCP/DLP/OrganizationsLocationsJobTrigger.ts

An organization-scoped Sensitive Data Protection job trigger that inspects storage on a schedule.

Job triggers have no labels field — Alchemy stamps ownership into the description so list / nuke can find them. Trigger id, organization, and location are identity. Display name, description, status, triggers, and inspect job update in place. Keep status as PAUSED unless jobs should run.

OrganizationsLocationsJobTrigger: Creating a Job Trigger

Section titled “OrganizationsLocationsJobTrigger: Creating a Job Trigger”
const trigger = yield* GCP.DLP.OrganizationsLocationsJobTrigger(
"ScanBucket",
{
status: "PAUSED",
triggers: [
{ schedule: { recurrencePeriodDuration: "86400s" } },
],
inspectJob: {
inspectConfig: { infoTypes: [{ name: "EMAIL_ADDRESS" }] },
storageConfig: {
cloudStorageOptions: {
fileSet: { url: "gs://my-bucket/" },
},
},
},
},
);

Source: src/GCP/DLP/OrganizationsLocationsStoredInfoType.ts

An organization-scoped Sensitive Data Protection stored infoType (custom dictionary or regex detector).

Stored infoTypes have no labels field — Alchemy stamps ownership into config.description so list / nuke can find them. Id, organization, and location are identity. Config updates create a new version.

OrganizationsLocationsStoredInfoType: Creating a Stored InfoType

Section titled “OrganizationsLocationsStoredInfoType: Creating a Stored InfoType”
const infoType = yield* GCP.DLP.OrganizationsLocationsStoredInfoType(
"EmployeeIds",
{
location: "us-central1",
config: {
displayName: "employee-ids",
dictionary: { wordList: { words: ["E12345", "E67890"] } },
},
},
);

Source: src/GCP/DLP/OrganizationStoredInfoType.ts

An organization-scoped Cloud DLP stored info type.

Stored info types have no labels field, so Alchemy stamps ownership into the config description for list / nuke. Organization and id are identity — changing them replaces the resource. Display name, description, and detector config update in place (a new version).

OrganizationStoredInfoType: Creating a Stored Info Type

Section titled “OrganizationStoredInfoType: Creating a Stored Info Type”
const infoType = yield* GCP.DLP.OrganizationStoredInfoType("EmployeeId", {
displayName: "employee ids",
description: "badge numbers",
regex: { pattern: "EMP[0-9]{6}" },
});

OrganizationStoredInfoType: Updating a Stored Info Type

Section titled “OrganizationStoredInfoType: Updating a Stored Info Type”
const infoType = yield* GCP.DLP.OrganizationStoredInfoType("EmployeeId", {
displayName: "employee ids",
description: "badge numbers v2",
regex: { pattern: "EMP[0-9]{8}" },
});

Source: src/GCP/DLP/StoredInfoType.ts

A project-scoped Cloud DLP stored info type (projects.storedInfoTypes, global processing location).

Stored info types have no labels field, so Alchemy stamps ownership into the config description for list / nuke. Id is identity — changing it replaces the resource. Display name, description, and detector config update in place (a new version).

StoredInfoType: Creating a Stored Info Type

Section titled “StoredInfoType: Creating a Stored Info Type”
const infoType = yield* GCP.DLP.StoredInfoType("Account", {
displayName: "account ids",
description: "internal account numbers",
regex: { pattern: "ACCT[0-9]{8}" },
});

StoredInfoType: Updating a Stored Info Type

Section titled “StoredInfoType: Updating a Stored Info Type”
const infoType = yield* GCP.DLP.StoredInfoType("Account", {
displayName: "account ids",
description: "internal account numbers v2",
regex: { pattern: "ACCT[0-9]{10}" },
});