GCP.IAM reference
Policy
Section titled “Policy”Source:
src/GCP/IAM/Policy.ts
An IAM v2 deny policy attached to a project, folder, or organization.
This is not GCP.OrgPolicy.Policy (organization policy
constraints). Deny policies use annotations for Alchemy ownership.
Create, update, and delete are long-running operations.
Policy: Creating a Deny Policy
Section titled “Policy: Creating a Deny Policy”const policy = yield* GCP.IAM.Policy("Probe", { displayName: "alchemy-probe", rules: [{ denyRule: { deniedPermissions: ["iam.googleapis.com/roles.list"], deniedPrincipals: [ "principal://goog/subject/alchemy-deny-probe@example.invalid", ], }, }],});