Skip to content

GCP.ManagedIdentities reference

Source: src/GCP/ManagedIdentities/Domain.ts

A Managed Microsoft Active Directory domain.

Changing domainName, reservedIpRange, or admin replaces the domain. locations, authorizedNetworks, auditLogsEnabled, and labels update in place. Provisioning typically takes 20-60 minutes.

Generated FQDN

const domain = yield* GCP.ManagedIdentities.Domain("Corp", {
reservedIpRange: "172.16.0.0/24",
locations: ["us-central1"],
});

Explicit FQDN, networks, and labels

const domain = yield* GCP.ManagedIdentities.Domain("Corp", {
domainName: "corp.example.com",
reservedIpRange: "172.16.0.0/24",
locations: ["us-central1"],
authorizedNetworks: ["default"],
auditLogsEnabled: true,
labels: { env: "prod" },
});

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const domain = yield* GCP.ManagedIdentities.Domain("Corp", {
domainName: "corp.example.com",
reservedIpRange: "172.16.0.0/24",
locations: ["us-central1"],
auditLogsEnabled: true,
labels: { env: "prod", team: "identity" },
});

Source: src/GCP/ManagedIdentities/DomainsBackup.ts

An on-demand backup of a Managed Microsoft AD domain.

Changing backupId or domain replaces the backup. Labels update in place. Create is on-demand; scheduled backups are produced by the domain and are not managed here.

Generated name

const backup = yield* GCP.ManagedIdentities.DomainsBackup("Nightly", {
domain: domain.name,
});

Explicit id and labels

const backup = yield* GCP.ManagedIdentities.DomainsBackup("Nightly", {
domain: domain.name,
backupId: "app-nightly",
labels: { env: "prod" },
});

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const backup = yield* GCP.ManagedIdentities.DomainsBackup("Nightly", {
domain: domain.name,
labels: { env: "prod", team: "identity" },
});

Source: src/GCP/ManagedIdentities/Peering.ts

A Managed Microsoft AD domain peering — attaches a VPC in this project to a Managed AD domain that lives in a different project so VMs on that network can join the domain. Same-project access uses Domain.authorizedNetworks instead; creating a peering when domain and network share a project is rejected with BadRequest.

Changing peeringId, domainResource, or authorizedNetwork replaces the peering. Labels update in place.

Generated name

const peering = yield* GCP.ManagedIdentities.Peering("Spoke", {
domainResource: domain.name,
authorizedNetwork: "default",
});

Explicit id and labels

const peering = yield* GCP.ManagedIdentities.Peering("Spoke", {
peeringId: "app-spoke",
domainResource: domain.name,
authorizedNetwork: "projects/my-project/global/networks/default",
labels: { env: "prod" },
});

Re-declare the same logical id with changed props; the engine keeps the physical resource and updates it in place.

const peering = yield* GCP.ManagedIdentities.Peering("Spoke", {
domainResource: domain.name,
authorizedNetwork: "default",
labels: { env: "prod", team: "identity" },
});