GCP.FirebaseRules reference
GetReleaseExecutable
Section titled “GetReleaseExecutable”Source:
src/GCP/FirebaseRules/GetReleaseExecutable.ts
Runtime binding for Firebase Rules releases.getExecutable.
Bind this operation to a Release in a Function/Action init
phase. Provide GetReleaseExecutableHttp.
GetReleaseExecutable: Reading a Release Executable
Section titled “GetReleaseExecutable: Reading a Release Executable”const getExecutable = yield* GCP.FirebaseRules.GetReleaseExecutable( release,);const { rulesetName, executableVersion } = yield* getExecutable();GetReleaseExecutableHttp
Section titled “GetReleaseExecutableHttp”Source:
src/GCP/FirebaseRules/GetReleaseExecutableHttp.tsKind: Layer · Provides:GCP.FirebaseRules.GetReleaseExecutable
HTTP implementation of GetReleaseExecutable.
Grants roles/firebaserules.admin on the project because it is the
narrowest predefined role containing firebaserules.releases.getExecutable, and Firebase
Rules has no resource-level IAM.
Release
Section titled “Release”Source:
src/GCP/FirebaseRules/Release.ts
A named Firebase Security Rules release pointing at a Ruleset.
Releases have no labels field. Generated release ids are prefixed
alc- so list / nuke can find them. releaseId is identity —
changing it replaces the release. rulesetName updates in place.
Release: Creating a Release
Section titled “Release: Creating a Release”Generated id
const ruleset = yield* GCP.FirebaseRules.Ruleset("Firestore", { source: { files: [ { name: "firestore.rules", content: "rules_version = '2'; service cloud.firestore { match /databases/{database}/documents { match /{document=**} { allow read, write: if false; } } }", }, ], },});const release = yield* GCP.FirebaseRules.Release("Live", { rulesetName: ruleset.name,});Named release
const release = yield* GCP.FirebaseRules.Release("Live", { releaseId: "prod", rulesetName: ruleset.name,});Release: Updating a Release
Section titled “Release: Updating a Release”const release = yield* GCP.FirebaseRules.Release("Live", { rulesetName: nextRuleset.name,});Ruleset
Section titled “Ruleset”Source:
src/GCP/FirebaseRules/Ruleset.ts
An immutable Firebase Security Rules ruleset.
Rulesets have no labels field, so Alchemy stamps ownership into a
// [alchemy …] comment on the first source file for list / nuke.
Source and attachmentPoint are identity — changing either replaces
the ruleset. The ruleset id is assigned by the service.
Ruleset: Creating a Ruleset
Section titled “Ruleset: Creating a Ruleset”Firestore rules
const ruleset = yield* GCP.FirebaseRules.Ruleset("Firestore", { source: { files: [{ name: "firestore.rules", content: "rules_version = '2'; service cloud.firestore { match /databases/{database}/documents { match /{document=**} { allow read, write: if false; } } }", }], },});Storage rules with an attachment point
const ruleset = yield* GCP.FirebaseRules.Ruleset("Storage", { attachmentPoint: "firebase.storage.googleapis.com/projects/my-project/buckets/my-bucket", source: { files: [{ name: "storage.rules", content: "rules_version = '2'; service firebase.storage { match /b/{bucket}/o { match /{allPaths=**} { allow read, write: if false; } } }", }], },});Ruleset: Replacing a Ruleset
Section titled “Ruleset: Replacing a Ruleset”const ruleset = yield* GCP.FirebaseRules.Ruleset("Firestore", { source: { files: [{ name: "firestore.rules", content: "rules_version = '2'; service cloud.firestore { match /databases/{database}/documents { match /{document=**} { allow read, write: if request.auth != null; } } }", }], },});TestRuleset
Section titled “TestRuleset”Source:
src/GCP/FirebaseRules/TestRuleset.ts
Runtime binding for Firebase Rules projects.test against a
Ruleset.
Bind this operation to a ruleset in a Function/Action init phase.
Provide TestRulesetHttp. source must be omitted when the
name refers to an existing ruleset.
TestRuleset: Testing a Ruleset
Section titled “TestRuleset: Testing a Ruleset”const testRuleset = yield* GCP.FirebaseRules.TestRuleset(ruleset);const result = yield* testRuleset({ body: { testSuite: { testCases: [{ expectation: "DENY" }], }, },});TestRulesetHttp
Section titled “TestRulesetHttp”Source:
src/GCP/FirebaseRules/TestRulesetHttp.tsKind: Layer · Provides:GCP.FirebaseRules.TestRuleset
HTTP implementation of TestRuleset.
Grants roles/firebaserules.admin on the project because it is the
narrowest predefined role containing firebaserules.rulesets.test, and Firebase
Rules has no resource-level IAM.