GCP.IAP reference
BrandsIdentityAwareProxyClient
Section titled “BrandsIdentityAwareProxyClient”Source:
src/GCP/IAP/BrandsIdentityAwareProxyClient.ts
An Identity-Aware Proxy owned OAuth client.
IAP OAuth clients have no labels field, so Alchemy stamps ownership
into displayName for list / nuke. Brand, client id, and display
name are identity — the API has no patch, so changing any of them
replaces the client. Creating a client requires an existing
internal-only OAuth brand on a Workspace project.
BrandsIdentityAwareProxyClient: Creating an IAP OAuth Client
Section titled “BrandsIdentityAwareProxyClient: Creating an IAP OAuth Client”Named client under an existing brand
const client = yield* GCP.IAP.BrandsIdentityAwareProxyClient("Console", { brand: "projects/my-project/brands/123456", displayName: "Alchemy console",});Generated display name
const client = yield* GCP.IAP.BrandsIdentityAwareProxyClient("Console", { brand: existingBrandName,});IapDestGroup
Section titled “IapDestGroup”Source:
src/GCP/IAP/IapDestGroup.ts
An Identity-Aware Proxy TCP-forwarding tunnel destination group.
Destination groups have no labels field, so Alchemy identifies its
groups by the generated destGroupId: read reports a group with an
explicit destGroupId as unowned (adopt it with --adopt), and nuke
cannot discover groups. destGroupId and location are identity —
changing either replaces the group. CIDRs and FQDNs update in place.
IapDestGroup: Creating a Destination Group
Section titled “IapDestGroup: Creating a Destination Group”Generated name with CIDRs
const group = yield* GCP.IAP.IapDestGroup("SshHosts", { cidrs: ["10.1.0.0/16"],});Named group with FQDNs
const group = yield* GCP.IAP.IapDestGroup("SshHosts", { destGroupId: "prod-ssh", location: "us-central1", fqdns: ["*.internal.example.com"],});IapDestGroup: Updating a Destination Group
Section titled “IapDestGroup: Updating a Destination Group”const group = yield* GCP.IAP.IapDestGroup("SshHosts", { cidrs: ["10.1.0.0/16", "192.168.2.0/24"], fqdns: ["db.internal.example.com"],});