GCP.NetworkSecurity reference
AddressGroup
Section titled “AddressGroup”Source:
src/GCP/NetworkSecurity/AddressGroup.ts
A Network Security address group — a named collection of IP addresses or CIDR ranges used by firewall policies and Cloud Armor.
Changing addressGroupId, location, type, capacity, or purpose
replaces the group. Description, labels, and items update in place.
AddressGroup: Creating an Address Group
Section titled “AddressGroup: Creating an Address Group”Generated name
const group = yield* GCP.NetworkSecurity.AddressGroup("Allowlist", { items: ["10.0.0.1"],});Named group with labels
const group = yield* GCP.NetworkSecurity.AddressGroup("Allowlist", { addressGroupId: "app-allowlist", type: "IPV4", capacity: 100, items: ["10.0.0.0/24"], description: "prod allowlist", labels: { env: "prod" },});AddressGroup: Updating an Address Group
Section titled “AddressGroup: Updating an Address Group”const group = yield* GCP.NetworkSecurity.AddressGroup("Allowlist", { addressGroupId: "app-allowlist", items: ["10.0.0.0/24", "10.1.0.1"], description: "prod allowlist v2", labels: { env: "prod", role: "allowlist" },});AuthorizationPolicy
Section titled “AuthorizationPolicy”Source:
src/GCP/NetworkSecurity/AuthorizationPolicy.ts
A Network Security authorization policy for Traffic Director / endpoint-config selectors.
Changing authorizationPolicyId or location replaces the policy.
Action, rules, description, and labels update in place. Attach the
policy to a target HTTPS proxy or endpoint config selector to enforce
it.
AuthorizationPolicy: Creating an Authorization Policy
Section titled “AuthorizationPolicy: Creating an Authorization Policy”Allow all
const policy = yield* GCP.NetworkSecurity.AuthorizationPolicy("Allow", { action: "ALLOW",});Allow specific hosts
const policy = yield* GCP.NetworkSecurity.AuthorizationPolicy("Allow", { action: "ALLOW", rules: [ { destinations: [{ hosts: ["api.example.com"], ports: [443] }], }, ], labels: { env: "prod" },});AuthzPolicy
Section titled “AuthzPolicy”Source:
src/GCP/NetworkSecurity/AuthzPolicy.ts
A Network Security AuthzPolicy for Application Load Balancers, Secure Web Proxy, and Agent Gateway.
Changing authzPolicyId, location, or policyProfile replaces the
policy. Action, target, rules, custom provider, description, and
labels update in place. target.resources must reference forwarding
rules or gateways that share loadBalancingScheme.
AuthzPolicy: Creating an Authz Policy
Section titled “AuthzPolicy: Creating an Authz Policy”const policy = yield* GCP.NetworkSecurity.AuthzPolicy("AllowAdmin", { location: "us-central1", action: "ALLOW", target: { loadBalancingScheme: "INTERNAL_MANAGED", resources: [forwardingRule.selfLink], }, httpRules: [ { to: { operations: [ { methods: ["GET"], paths: [{ prefix: "/admin" }] }, ], }, }, ],});BackendAuthenticationConfig
Section titled “BackendAuthenticationConfig”Source:
src/GCP/NetworkSecurity/BackendAuthenticationConfig.ts
A Network Security BackendAuthenticationConfig — how a load balancer authenticates to backends (TrustConfig, public roots, optional mTLS client certificate).
Changing backendAuthenticationConfigId or location replaces the
config. TrustConfig, client certificate, well-known roots,
description, and labels update in place.
BackendAuthenticationConfig: Creating a Backend Authentication Config
Section titled “BackendAuthenticationConfig: Creating a Backend Authentication Config”Trust public roots
const config = yield* GCP.NetworkSecurity.BackendAuthenticationConfig( "BackendTls", { wellKnownRoots: "PUBLIC_ROOTS" },);TrustConfig plus public roots
const config = yield* GCP.NetworkSecurity.BackendAuthenticationConfig( "BackendTls", { trustConfig: trust.name, wellKnownRoots: "PUBLIC_ROOTS", labels: { env: "prod" }, },);ClientTlsPolicy
Section titled “ClientTlsPolicy”Source:
src/GCP/NetworkSecurity/ClientTlsPolicy.ts
A Network Security ClientTlsPolicy — how a client authenticates connections to backends. The policy has no effect until it is attached to a backend service.
Changing clientTlsPolicyId or location replaces the policy.
Description, labels, SNI, server-validation CAs, and the client
certificate provider update in place.
ClientTlsPolicy: Creating a ClientTlsPolicy
Section titled “ClientTlsPolicy: Creating a ClientTlsPolicy”Generated name
const policy = yield* GCP.NetworkSecurity.ClientTlsPolicy("BackendTls", { sni: "backend.example.com",});Named policy with labels
const policy = yield* GCP.NetworkSecurity.ClientTlsPolicy("BackendTls", { clientTlsPolicyId: "app-backend-tls", description: "prod backends", labels: { env: "prod" }, sni: "backend.example.com",});ClientTlsPolicy: mTLS
Section titled “ClientTlsPolicy: mTLS”const policy = yield* GCP.NetworkSecurity.ClientTlsPolicy("Mtls", { sni: "secure.example.com", clientCertificate: { certificateProviderInstance: { pluginInstance: "google_cloud_private_spiffe", }, }, serverValidationCa: [ { certificateProviderInstance: { pluginInstance: "google_cloud_private_spiffe", }, }, ],});DnsThreatDetector
Section titled “DnsThreatDetector”Source:
src/GCP/NetworkSecurity/DnsThreatDetector.ts
A DNS threat detector that sends VPC DNS query logs to Infoblox for
analysis. By default every VPC in the project is monitored; pass
excludedNetworks to skip specific networks.
A project may have only one detector. Changing dnsThreatDetectorId,
location, or provider replaces the resource. Labels and
excludedNetworks update in place.
DnsThreatDetector: Creating a DnsThreatDetector
Section titled “DnsThreatDetector: Creating a DnsThreatDetector”Monitor every VPC
const detector = yield* GCP.NetworkSecurity.DnsThreatDetector("Armor", { provider: "INFOBLOX",});Exclude a network
const detector = yield* GCP.NetworkSecurity.DnsThreatDetector("Armor", { provider: "INFOBLOX", excludedNetworks: [ `projects/${project}/global/networks/${vpc.networkName}`, ], labels: { env: "prod" },});FirewallEndpoint
Section titled “FirewallEndpoint”Source:
src/GCP/NetworkSecurity/FirewallEndpoint.ts
A project-scoped Cloud NGFW firewall endpoint. Endpoints terminate inspected traffic in a zone; associate them with a VPC via FirewallEndpointAssociation.
Changing firewallEndpointId, location, billingProjectId, or
jumbo-frame settings replaces the endpoint. Description and labels
update in place. Provisioning is asynchronous and can take several
minutes.
FirewallEndpoint: Creating a FirewallEndpoint
Section titled “FirewallEndpoint: Creating a FirewallEndpoint”Generated name
const endpoint = yield* GCP.NetworkSecurity.FirewallEndpoint("Ngfw", { location: "us-central1-a",});Named endpoint with labels
const endpoint = yield* GCP.NetworkSecurity.FirewallEndpoint("Ngfw", { firewallEndpointId: "app-ngfw", location: "us-central1-a", description: "prod inspection", labels: { env: "prod" },});FirewallEndpointAssociation
Section titled “FirewallEndpointAssociation”Source:
src/GCP/NetworkSecurity/FirewallEndpointAssociation.ts
Associates a Cloud NGFW FirewallEndpoint with a VPC network so matching traffic is intercepted for inspection.
Changing firewallEndpointAssociationId, location, network, or
firewallEndpoint replaces the association. Labels, disabled, and
tlsInspectionPolicy update in place.
FirewallEndpointAssociation: Creating a FirewallEndpointAssociation
Section titled “FirewallEndpointAssociation: Creating a FirewallEndpointAssociation”Attach an endpoint to a VPC
const association = yield* GCP.NetworkSecurity.FirewallEndpointAssociation( "Inspect", { location: "us-central1-a", firewallEndpoint: endpoint.name, network: `projects/${vpc.project}/global/networks/${vpc.networkName}`, },);Disable interception
const association = yield* GCP.NetworkSecurity.FirewallEndpointAssociation( "Inspect", { location: "us-central1-a", firewallEndpoint: endpoint.name, network: `projects/${vpc.project}/global/networks/${vpc.networkName}`, disabled: true, },);GatewaySecurityPoliciesRule
Section titled “GatewaySecurityPoliciesRule”Source:
src/GCP/NetworkSecurity/GatewaySecurityPoliciesRule.ts
A GatewaySecurityPolicyRule nested under a GatewaySecurityPolicy. Each rule matches traffic with CEL and applies ALLOW or DENY.
The API has no labels field, so Alchemy stamps ownership into the
description for list / nuke. Changing the parent policy, rule id,
or location replaces the rule. Matchers, priority, profile, enabled
flag, TLS inspection, and description update in place.
GatewaySecurityPoliciesRule: Creating a GatewaySecurityPoliciesRule
Section titled “GatewaySecurityPoliciesRule: Creating a GatewaySecurityPoliciesRule”Allow all sessions
const rule = yield* GCP.NetworkSecurity.GatewaySecurityPoliciesRule("Allow", { gatewaySecurityPolicy: policy.name, basicProfile: "ALLOW", priority: 1000, sessionMatcher: "true",});Deny by host
const rule = yield* GCP.NetworkSecurity.GatewaySecurityPoliciesRule("Block", { gatewaySecurityPolicy: policy.name, basicProfile: "DENY", priority: 100, enabled: true, sessionMatcher: "host() == 'blocked.example.com'", description: "block listed host",});GatewaySecurityPolicy
Section titled “GatewaySecurityPolicy”Source:
src/GCP/NetworkSecurity/GatewaySecurityPolicy.ts
A Gateway Security Policy — a collection of GatewaySecurityPolicyRules used by Secure Web Proxy.
The API has no labels field, so Alchemy stamps ownership into the
description for list / nuke. Changing gatewaySecurityPolicyId or
location replaces the policy. Description and tlsInspectionPolicy
update in place.
GatewaySecurityPolicy: Creating a GatewaySecurityPolicy
Section titled “GatewaySecurityPolicy: Creating a GatewaySecurityPolicy”Generated name
const policy = yield* GCP.NetworkSecurity.GatewaySecurityPolicy("Swp", { description: "secure web proxy",});Named policy with TLS inspection
const policy = yield* GCP.NetworkSecurity.GatewaySecurityPolicy("Swp", { gatewaySecurityPolicyId: "app-swp", location: "us-central1", tlsInspectionPolicy: inspection.name,});InterceptDeployment
Section titled “InterceptDeployment”Source:
src/GCP/NetworkSecurity/InterceptDeployment.ts
A zonal intercept deployment — a GENEVE backend (typically an internal passthrough load balancer) that belongs to a global InterceptDeploymentGroup.
Changing interceptDeploymentId, location, interceptDeploymentGroup,
or forwardingRule replaces the deployment. Description and labels
update in place.
InterceptDeployment: Creating an InterceptDeployment
Section titled “InterceptDeployment: Creating an InterceptDeployment”const deployment = yield* GCP.NetworkSecurity.InterceptDeployment( "ZoneA", { location: "us-central1-a", interceptDeploymentGroup: group.name, forwardingRule: rule.selfLink, description: "us-central1-a interceptors", },);InterceptDeploymentGroup
Section titled “InterceptDeploymentGroup”Source:
src/GCP/NetworkSecurity/InterceptDeploymentGroup.ts
A global intercept deployment group — aggregates zonal intercept backends into a single intercept service that consumers attach via an endpoint group.
Changing interceptDeploymentGroupId, location, or network
replaces the group. Description and labels update in place.
InterceptDeploymentGroup: Creating an InterceptDeploymentGroup
Section titled “InterceptDeploymentGroup: Creating an InterceptDeploymentGroup”const group = yield* GCP.NetworkSecurity.InterceptDeploymentGroup("Inspect", { network: `projects/${vpc.project}/global/networks/${vpc.networkName}`, description: "prod intercept", labels: { env: "prod" },});InterceptEndpointGroup
Section titled “InterceptEndpointGroup”Source:
src/GCP/NetworkSecurity/InterceptEndpointGroup.ts
A Network Security Integration intercept endpoint group — the consumer frontend for an intercept deployment group.
Changing interceptEndpointGroupId, location, or
interceptDeploymentGroup replaces the group. Description and labels
update in place.
InterceptEndpointGroup: Creating an Endpoint Group
Section titled “InterceptEndpointGroup: Creating an Endpoint Group”Generated name
const endpoints = yield* GCP.NetworkSecurity.InterceptEndpointGroup("Front", { interceptDeploymentGroup: group.name,});Named group with labels
const endpoints = yield* GCP.NetworkSecurity.InterceptEndpointGroup("Front", { interceptEndpointGroupId: "app-intercept-eg", interceptDeploymentGroup: group.name, description: "prod intercept frontend", labels: { env: "prod" },});InterceptEndpointGroup: Updating an Endpoint Group
Section titled “InterceptEndpointGroup: Updating an Endpoint Group”const endpoints = yield* GCP.NetworkSecurity.InterceptEndpointGroup("Front", { interceptEndpointGroupId: "app-intercept-eg", interceptDeploymentGroup: group.name, description: "prod intercept frontend v2", labels: { env: "prod", role: "nsi" },});InterceptEndpointGroupAssociation
Section titled “InterceptEndpointGroupAssociation”Source:
src/GCP/NetworkSecurity/InterceptEndpointGroupAssociation.ts
A Network Security Integration intercept endpoint-group association — the link between a VPC and an intercept endpoint group.
Creating an association does not enable intercept by itself; a firewall
policy with intercept rules must also target the network. Changing
interceptEndpointGroupAssociationId, location,
interceptEndpointGroup, or network replaces the association. Labels
update in place.
InterceptEndpointGroupAssociation: Creating an Association
Section titled “InterceptEndpointGroupAssociation: Creating an Association”Generated name
const association = yield* GCP.NetworkSecurity.InterceptEndpointGroupAssociation("Link", { interceptEndpointGroup: endpoints.name, network: vpc.selfLink,});Named association with labels
const association = yield* GCP.NetworkSecurity.InterceptEndpointGroupAssociation("Link", { interceptEndpointGroupAssociationId: "app-intercept-ega", interceptEndpointGroup: endpoints.name, network: "projects/my-project/global/networks/app-vpc", labels: { env: "prod" },});InterceptEndpointGroupAssociation: Updating an Association
Section titled “InterceptEndpointGroupAssociation: Updating an Association”const association = yield* GCP.NetworkSecurity.InterceptEndpointGroupAssociation("Link", { interceptEndpointGroupAssociationId: "app-intercept-ega", interceptEndpointGroup: endpoints.name, network: vpc.selfLink, labels: { env: "prod", role: "nsi" },});MirroringDeployment
Section titled “MirroringDeployment”Source:
src/GCP/NetworkSecurity/MirroringDeployment.ts
A Network Security Integration mirroring deployment — a zonal GENEVE collector, typically an internal passthrough load balancer, that belongs to a global mirroring deployment group.
Changing mirroringDeploymentId, location, mirroringDeploymentGroup,
or forwardingRule replaces the deployment. Description and labels
update in place.
MirroringDeployment: Creating a Deployment
Section titled “MirroringDeployment: Creating a Deployment”Generated name
const deployment = yield* GCP.NetworkSecurity.MirroringDeployment("Collector", { location: "us-central1-a", mirroringDeploymentGroup: group.name, forwardingRule: rule.selfLink,});Named deployment with labels
const deployment = yield* GCP.NetworkSecurity.MirroringDeployment("Collector", { mirroringDeploymentId: "app-collector-a", location: "us-central1-a", mirroringDeploymentGroup: group.name, forwardingRule: rule.selfLink, description: "zone a collector", labels: { env: "prod" },});MirroringDeployment: Updating a Deployment
Section titled “MirroringDeployment: Updating a Deployment”const deployment = yield* GCP.NetworkSecurity.MirroringDeployment("Collector", { mirroringDeploymentId: "app-collector-a", location: "us-central1-a", mirroringDeploymentGroup: group.name, forwardingRule: rule.selfLink, description: "zone a collector v2", labels: { env: "prod", role: "nsi" },});MirroringDeploymentGroup
Section titled “MirroringDeploymentGroup”Source:
src/GCP/NetworkSecurity/MirroringDeploymentGroup.ts
A Network Security Integration mirroring deployment group — the global backend that aggregates zonal mirroring collectors.
Changing mirroringDeploymentGroupId, location, or network replaces
the group. Description and labels update in place.
MirroringDeploymentGroup: Creating a Deployment Group
Section titled “MirroringDeploymentGroup: Creating a Deployment Group”Generated name
const group = yield* GCP.NetworkSecurity.MirroringDeploymentGroup("Collectors", { network: vpc.selfLink,});Named group with labels
const group = yield* GCP.NetworkSecurity.MirroringDeploymentGroup("Collectors", { mirroringDeploymentGroupId: "app-collectors", network: "projects/my-project/global/networks/app-vpc", description: "prod mirroring backends", labels: { env: "prod" },});MirroringDeploymentGroup: Updating a Deployment Group
Section titled “MirroringDeploymentGroup: Updating a Deployment Group”const group = yield* GCP.NetworkSecurity.MirroringDeploymentGroup("Collectors", { mirroringDeploymentGroupId: "app-collectors", network: vpc.selfLink, description: "prod mirroring backends v2", labels: { env: "prod", role: "nsi" },});MirroringEndpointGroup
Section titled “MirroringEndpointGroup”Source:
src/GCP/NetworkSecurity/MirroringEndpointGroup.ts
A Network Security Integration mirroring endpoint group — the consumer frontend for a mirroring deployment group.
Changing mirroringEndpointGroupId, location, type, or
mirroringDeploymentGroup replaces the group. Description and labels
update in place.
MirroringEndpointGroup: Creating an Endpoint Group
Section titled “MirroringEndpointGroup: Creating an Endpoint Group”Generated name
const endpoints = yield* GCP.NetworkSecurity.MirroringEndpointGroup("Front", { mirroringDeploymentGroup: group.name,});Named group with labels
const endpoints = yield* GCP.NetworkSecurity.MirroringEndpointGroup("Front", { mirroringEndpointGroupId: "app-mirroring-eg", mirroringDeploymentGroup: group.name, description: "prod mirroring frontend", labels: { env: "prod" },});MirroringEndpointGroup: Updating an Endpoint Group
Section titled “MirroringEndpointGroup: Updating an Endpoint Group”const endpoints = yield* GCP.NetworkSecurity.MirroringEndpointGroup("Front", { mirroringEndpointGroupId: "app-mirroring-eg", mirroringDeploymentGroup: group.name, description: "prod mirroring frontend v2", labels: { env: "prod", role: "nsi" },});MirroringEndpointGroupAssociation
Section titled “MirroringEndpointGroupAssociation”Source:
src/GCP/NetworkSecurity/MirroringEndpointGroupAssociation.ts
A Network Security Integration mirroring endpoint-group association — the link between a VPC and a mirroring endpoint group.
Creating an association does not enable mirroring by itself; a firewall
policy with mirroring rules must also target the network. Changing
mirroringEndpointGroupAssociationId, location,
mirroringEndpointGroup, or network replaces the association. Labels
update in place.
MirroringEndpointGroupAssociation: Creating an Association
Section titled “MirroringEndpointGroupAssociation: Creating an Association”Generated name
const association = yield* GCP.NetworkSecurity.MirroringEndpointGroupAssociation("Link", { mirroringEndpointGroup: endpoints.name, network: vpc.selfLink,});Named association with labels
const association = yield* GCP.NetworkSecurity.MirroringEndpointGroupAssociation("Link", { mirroringEndpointGroupAssociationId: "app-mirroring-ega", mirroringEndpointGroup: endpoints.name, network: "projects/my-project/global/networks/app-vpc", labels: { env: "prod" },});MirroringEndpointGroupAssociation: Updating an Association
Section titled “MirroringEndpointGroupAssociation: Updating an Association”const association = yield* GCP.NetworkSecurity.MirroringEndpointGroupAssociation("Link", { mirroringEndpointGroupAssociationId: "app-mirroring-ega", mirroringEndpointGroup: endpoints.name, network: vpc.selfLink, labels: { env: "prod", role: "nsi" },});OrganizationsAddressGroup
Section titled “OrganizationsAddressGroup”Source:
src/GCP/NetworkSecurity/OrganizationsAddressGroup.ts
An organization-scoped Network Security address group.
Changing addressGroupId, organization, location, type,
capacity, or purpose replaces the group. Description, labels, and
items update in place.
OrganizationsAddressGroup: Creating an Organization Address Group
Section titled “OrganizationsAddressGroup: Creating an Organization Address Group”Generated name
const group = yield* GCP.NetworkSecurity.OrganizationsAddressGroup( "OrgAllowlist", { items: ["10.0.0.1"] },);Named group
const group = yield* GCP.NetworkSecurity.OrganizationsAddressGroup( "OrgAllowlist", { addressGroupId: "org-allowlist", organization: "123456789", type: "IPV4", items: ["10.0.0.0/24"], labels: { env: "prod" }, },);OrganizationsFirewallEndpoint
Section titled “OrganizationsFirewallEndpoint”Source:
src/GCP/NetworkSecurity/OrganizationsFirewallEndpoint.ts
An organization-scoped Cloud NGFW firewall endpoint.
Endpoints are zonal and bill to billingProjectId. Changing
firewallEndpointId, organization, location, billingProjectId,
or jumbo-frame settings replaces the endpoint. Description and labels
update in place. Provisioning is slow — tests skip when FAST is set.
OrganizationsFirewallEndpoint: Creating a Firewall Endpoint
Section titled “OrganizationsFirewallEndpoint: Creating a Firewall Endpoint”Generated name
const endpoint = yield* GCP.NetworkSecurity.OrganizationsFirewallEndpoint( "Ngfw", { location: "us-central1-a" },);Named endpoint
const endpoint = yield* GCP.NetworkSecurity.OrganizationsFirewallEndpoint( "Ngfw", { firewallEndpointId: "app-ngfw", organization: "123456789", location: "us-central1-a", billingProjectId: "my-project", description: "prod NGFW", labels: { env: "prod" }, },);OrganizationsSecurityProfile
Section titled “OrganizationsSecurityProfile”Source:
src/GCP/NetworkSecurity/OrganizationsSecurityProfile.ts
An organization-scoped Network Security profile (threat prevention, URL filtering, custom mirroring, or custom intercept).
Changing securityProfileId, organization, location, type, or
the immutable nested mirroring/intercept targets replaces the profile.
Description, labels, and threat-prevention or URL-filter config update
in place.
OrganizationsSecurityProfile: Creating a Security Profile
Section titled “OrganizationsSecurityProfile: Creating a Security Profile”const profile = yield* GCP.NetworkSecurity.OrganizationsSecurityProfile( "Threats", { type: "THREAT_PREVENTION", threatPreventionProfile: { severityOverrides: [{ severity: "INFORMATIONAL", action: "ALERT" }], }, },);OrganizationsSecurityProfileGroup
Section titled “OrganizationsSecurityProfileGroup”Source:
src/GCP/NetworkSecurity/OrganizationsSecurityProfileGroup.ts
An organization-scoped group of Network Security profiles.
Changing securityProfileGroupId, organization, or location
replaces the group. Profile references, description, and labels update
in place.
OrganizationsSecurityProfileGroup: Creating a Security Profile Group
Section titled “OrganizationsSecurityProfileGroup: Creating a Security Profile Group”Empty group
const group = yield* GCP.NetworkSecurity.OrganizationsSecurityProfileGroup( "Profiles", {},);Attach a threat-prevention profile
const group = yield* GCP.NetworkSecurity.OrganizationsSecurityProfileGroup( "Profiles", { threatPreventionProfile: profile.name, labels: { env: "prod" }, },);SacAttachment
Section titled “SacAttachment”Source:
src/GCP/NetworkSecurity/SacAttachment.ts
A Secure Access Connect (SAC) attachment — binds an NCC Gateway to a SAC realm so SSE traffic can be processed.
The realm must first be paired with the SSE partner’s realm (Palo Alto
Prisma Access / Symantec) on the partner side; an unpaired realm is
rejected with SacRealmNotPaired.
The create API has no patch; changing sacAttachmentId, location,
sacRealm, nccGateway, or labels replaces the attachment.
SacAttachment: Creating an Attachment
Section titled “SacAttachment: Creating an Attachment”Generated name
const attachment = yield* GCP.NetworkSecurity.SacAttachment("PrismaLink", { sacRealm: realm.name, nccGateway: gateway.name,});Named attachment with labels
const attachment = yield* GCP.NetworkSecurity.SacAttachment("PrismaLink", { sacAttachmentId: "app-prisma-link", location: "us-central1", sacRealm: realm.name, nccGateway: gateway.name, labels: { env: "prod" },});SacRealm
Section titled “SacRealm”Source:
src/GCP/NetworkSecurity/SacRealm.ts
A Secure Access Connect (SAC) realm — the handshake between a Google Cloud project and an SSE partner such as Palo Alto Prisma Access.
The create API has no patch; changing sacRealmId, location,
securityService, or labels replaces the realm.
SacRealm: Creating a Realm
Section titled “SacRealm: Creating a Realm”Generated name
const realm = yield* GCP.NetworkSecurity.SacRealm("Prisma", {});Named realm with labels
const realm = yield* GCP.NetworkSecurity.SacRealm("Prisma", { sacRealmId: "app-prisma", securityService: "PALO_ALTO_PRISMA_ACCESS", labels: { env: "prod" },});SecurityProfile
Section titled “SecurityProfile”Source:
src/GCP/NetworkSecurity/SecurityProfile.ts
A Network Security SecurityProfile — the behavior for one ProfileType (threat prevention, URL filtering, custom mirroring, or custom intercept).
Changing securityProfileId, location, type, or an immutable
nested target (mirroringEndpointGroup / interceptEndpointGroup)
replaces the profile. Description, labels, and the mutable nested
profile configuration update in place.
SecurityProfile: Creating a SecurityProfile
Section titled “SecurityProfile: Creating a SecurityProfile”Threat prevention with a severity override
const profile = yield* GCP.NetworkSecurity.SecurityProfile("Threat", { type: "THREAT_PREVENTION", threatPreventionProfile: { severityOverrides: [{ severity: "HIGH", action: "ALERT" }], },});Named profile with labels
const profile = yield* GCP.NetworkSecurity.SecurityProfile("Threat", { securityProfileId: "app-threat", description: "prod threat prevention", labels: { env: "prod" }, type: "THREAT_PREVENTION",});SecurityProfile: Updating a SecurityProfile
Section titled “SecurityProfile: Updating a SecurityProfile”const profile = yield* GCP.NetworkSecurity.SecurityProfile("Threat", { securityProfileId: "app-threat", type: "THREAT_PREVENTION", description: "prod threat prevention v2", labels: { env: "prod", role: "ngfw" }, threatPreventionProfile: { severityOverrides: [{ severity: "CRITICAL", action: "DENY" }], },});SecurityProfileGroup
Section titled “SecurityProfileGroup”Source:
src/GCP/NetworkSecurity/SecurityProfileGroup.ts
A Network Security SecurityProfileGroup — a named bundle of SecurityProfile references applied together by firewall policy rules.
Changing securityProfileGroupId or location replaces the group.
Description, labels, and profile references update in place.
SecurityProfileGroup: Creating a SecurityProfileGroup
Section titled “SecurityProfileGroup: Creating a SecurityProfileGroup”Empty group
const group = yield* GCP.NetworkSecurity.SecurityProfileGroup("Ngfw", {});Group bound to a threat-prevention profile
const profile = yield* GCP.NetworkSecurity.SecurityProfile("Threat", { type: "THREAT_PREVENTION",});const group = yield* GCP.NetworkSecurity.SecurityProfileGroup("Ngfw", { securityProfileGroupId: "app-ngfw", description: "prod ngfw", labels: { env: "prod" }, threatPreventionProfile: profile.name,});SecurityProfileGroup: Updating a SecurityProfileGroup
Section titled “SecurityProfileGroup: Updating a SecurityProfileGroup”const group = yield* GCP.NetworkSecurity.SecurityProfileGroup("Ngfw", { securityProfileGroupId: "app-ngfw", description: "prod ngfw v2", labels: { env: "prod", role: "ngfw" }, threatPreventionProfile: profile.name,});ServerTlsPolicy
Section titled “ServerTlsPolicy”Source:
src/GCP/NetworkSecurity/ServerTlsPolicy.ts
A Network Security ServerTlsPolicy — how a server authenticates incoming requests. Attach it to a TargetHttpsProxy or EndpointPolicy; the policy itself does not serve traffic.
Changing serverTlsPolicyId or location replaces the policy.
Application Load Balancer policies (mtlsPolicy.clientValidationMode
set) cannot be updated in place — any other change replaces them.
Traffic Director policies update description, labels, allowOpen,
serverCertificate, and mtlsPolicy in place.
ServerTlsPolicy: Creating a ServerTlsPolicy
Section titled “ServerTlsPolicy: Creating a ServerTlsPolicy”Application Load Balancer mTLS
const policy = yield* GCP.NetworkSecurity.ServerTlsPolicy("FrontendTls", { description: "alb mtls", mtlsPolicy: { clientValidationMode: "ALLOW_INVALID_OR_MISSING_CLIENT_CERT", },});Named policy with labels
const policy = yield* GCP.NetworkSecurity.ServerTlsPolicy("FrontendTls", { serverTlsPolicyId: "app-frontend-tls", location: "global", description: "prod frontend", labels: { env: "prod" }, mtlsPolicy: { clientValidationMode: "ALLOW_INVALID_OR_MISSING_CLIENT_CERT", },});ServerTlsPolicy: Updating a ServerTlsPolicy
Section titled “ServerTlsPolicy: Updating a ServerTlsPolicy”const policy = yield* GCP.NetworkSecurity.ServerTlsPolicy("FrontendTls", { serverTlsPolicyId: "app-frontend-tls", location: "global", description: "prod frontend v2", labels: { env: "prod", role: "tls" }, mtlsPolicy: { clientValidationMode: "ALLOW_INVALID_OR_MISSING_CLIENT_CERT", },});TlsInspectionPolicy
Section titled “TlsInspectionPolicy”Source:
src/GCP/NetworkSecurity/TlsInspectionPolicy.ts
A Network Security TlsInspectionPolicy — CA pool and TLS settings used to intercept TLS for Secure Web Proxy and Cloud NGFW.
TlsInspectionPolicy has no labels field, so Alchemy stamps ownership
into the description for list / nuke. Changing tlsInspectionPolicyId
or location replaces the policy. caPool, description, TLS feature
profile, min version, custom features, excludePublicCaSet, and
trustConfig update in place.
TlsInspectionPolicy: Creating a TlsInspectionPolicy
Section titled “TlsInspectionPolicy: Creating a TlsInspectionPolicy”Intercept with a CaPool
const pool = yield* GCP.PrivateCA.CaPool("Intercept", { location: "us-central1", tier: "DEVOPS",});const policy = yield* GCP.NetworkSecurity.TlsInspectionPolicy("Inspect", { caPool: pool.name,});Named policy with TLS constraints
const policy = yield* GCP.NetworkSecurity.TlsInspectionPolicy("Inspect", { tlsInspectionPolicyId: "app-inspect", location: "us-central1", caPool: pool.name, description: "prod intercept", excludePublicCaSet: true, minTlsVersion: "TLS_1_2", tlsFeatureProfile: "PROFILE_MODERN",});TlsInspectionPolicy: Updating a TlsInspectionPolicy
Section titled “TlsInspectionPolicy: Updating a TlsInspectionPolicy”const policy = yield* GCP.NetworkSecurity.TlsInspectionPolicy("Inspect", { tlsInspectionPolicyId: "app-inspect", location: "us-central1", caPool: pool.name, description: "prod intercept v2", excludePublicCaSet: true, minTlsVersion: "TLS_1_2",});UrlList
Section titled “UrlList”Source:
src/GCP/NetworkSecurity/UrlList.ts
A reusable list of hosts, host patterns, URLs, and URL patterns used by Secure Web Proxy URL filtering.
UrlList has no labels field, so Alchemy stamps ownership into the
description for list / nuke. Changing urlListId or location
replaces the list. values and description update in place.
UrlList: Creating a UrlList
Section titled “UrlList: Creating a UrlList”Generated name
const blocked = yield* GCP.NetworkSecurity.UrlList("Blocked", { values: ["malware.example.com", "phishing.example.net"],});Named list with a description
const blocked = yield* GCP.NetworkSecurity.UrlList("Blocked", { urlListId: "app-blocked-hosts", location: "us-central1", description: "denied destinations", values: ["malware.example.com"],});UrlList: Updating a UrlList
Section titled “UrlList: Updating a UrlList”const blocked = yield* GCP.NetworkSecurity.UrlList("Blocked", { urlListId: "app-blocked-hosts", location: "us-central1", description: "denied destinations v2", values: ["malware.example.com", "c2.example.net"],});