Skip to content

GCP.IAP reference

Source: src/GCP/IAP/BrandsIdentityAwareProxyClient.ts

An Identity-Aware Proxy owned OAuth client.

IAP OAuth clients have no labels field, so Alchemy stamps ownership into displayName for list / nuke. Brand, client id, and display name are identity — the API has no patch, so changing any of them replaces the client. Creating a client requires an existing internal-only OAuth brand on a Workspace project.

BrandsIdentityAwareProxyClient: Creating an IAP OAuth Client

Section titled “BrandsIdentityAwareProxyClient: Creating an IAP OAuth Client”

Named client under an existing brand

const client = yield* GCP.IAP.BrandsIdentityAwareProxyClient("Console", {
brand: "projects/my-project/brands/123456",
displayName: "Alchemy console",
});

Generated display name

const client = yield* GCP.IAP.BrandsIdentityAwareProxyClient("Console", {
brand: existingBrandName,
});

Source: src/GCP/IAP/IapDestGroup.ts

An Identity-Aware Proxy TCP-forwarding tunnel destination group.

Destination groups have no labels field, so Alchemy identifies its groups by the generated destGroupId: read reports a group with an explicit destGroupId as unowned (adopt it with --adopt), and nuke cannot discover groups. destGroupId and location are identity — changing either replaces the group. CIDRs and FQDNs update in place.

IapDestGroup: Creating a Destination Group

Section titled “IapDestGroup: Creating a Destination Group”

Generated name with CIDRs

const group = yield* GCP.IAP.IapDestGroup("SshHosts", {
cidrs: ["10.1.0.0/16"],
});

Named group with FQDNs

const group = yield* GCP.IAP.IapDestGroup("SshHosts", {
destGroupId: "prod-ssh",
location: "us-central1",
fqdns: ["*.internal.example.com"],
});

IapDestGroup: Updating a Destination Group

Section titled “IapDestGroup: Updating a Destination Group”
const group = yield* GCP.IAP.IapDestGroup("SshHosts", {
cidrs: ["10.1.0.0/16", "192.168.2.0/24"],
fqdns: ["db.internal.example.com"],
});