Skip to content

GCP.NetworkSecurity reference

Source: src/GCP/NetworkSecurity/AddressGroup.ts

A Network Security address group — a named collection of IP addresses or CIDR ranges used by firewall policies and Cloud Armor.

Changing addressGroupId, location, type, capacity, or purpose replaces the group. Description, labels, and items update in place.

Generated name

const group = yield* GCP.NetworkSecurity.AddressGroup("Allowlist", {
items: ["10.0.0.1"],
});

Named group with labels

const group = yield* GCP.NetworkSecurity.AddressGroup("Allowlist", {
addressGroupId: "app-allowlist",
type: "IPV4",
capacity: 100,
items: ["10.0.0.0/24"],
description: "prod allowlist",
labels: { env: "prod" },
});
const group = yield* GCP.NetworkSecurity.AddressGroup("Allowlist", {
addressGroupId: "app-allowlist",
items: ["10.0.0.0/24", "10.1.0.1"],
description: "prod allowlist v2",
labels: { env: "prod", role: "allowlist" },
});

Source: src/GCP/NetworkSecurity/AuthorizationPolicy.ts

A Network Security authorization policy for Traffic Director / endpoint-config selectors.

Changing authorizationPolicyId or location replaces the policy. Action, rules, description, and labels update in place. Attach the policy to a target HTTPS proxy or endpoint config selector to enforce it.

AuthorizationPolicy: Creating an Authorization Policy

Section titled “AuthorizationPolicy: Creating an Authorization Policy”

Allow all

const policy = yield* GCP.NetworkSecurity.AuthorizationPolicy("Allow", {
action: "ALLOW",
});

Allow specific hosts

const policy = yield* GCP.NetworkSecurity.AuthorizationPolicy("Allow", {
action: "ALLOW",
rules: [
{
destinations: [{ hosts: ["api.example.com"], ports: [443] }],
},
],
labels: { env: "prod" },
});

Source: src/GCP/NetworkSecurity/AuthzPolicy.ts

A Network Security AuthzPolicy for Application Load Balancers, Secure Web Proxy, and Agent Gateway.

Changing authzPolicyId, location, or policyProfile replaces the policy. Action, target, rules, custom provider, description, and labels update in place. target.resources must reference forwarding rules or gateways that share loadBalancingScheme.

const policy = yield* GCP.NetworkSecurity.AuthzPolicy("AllowAdmin", {
location: "us-central1",
action: "ALLOW",
target: {
loadBalancingScheme: "INTERNAL_MANAGED",
resources: [forwardingRule.selfLink],
},
httpRules: [
{
to: {
operations: [
{ methods: ["GET"], paths: [{ prefix: "/admin" }] },
],
},
},
],
});

Source: src/GCP/NetworkSecurity/BackendAuthenticationConfig.ts

A Network Security BackendAuthenticationConfig — how a load balancer authenticates to backends (TrustConfig, public roots, optional mTLS client certificate).

Changing backendAuthenticationConfigId or location replaces the config. TrustConfig, client certificate, well-known roots, description, and labels update in place.

BackendAuthenticationConfig: Creating a Backend Authentication Config

Section titled “BackendAuthenticationConfig: Creating a Backend Authentication Config”

Trust public roots

const config = yield* GCP.NetworkSecurity.BackendAuthenticationConfig(
"BackendTls",
{ wellKnownRoots: "PUBLIC_ROOTS" },
);

TrustConfig plus public roots

const config = yield* GCP.NetworkSecurity.BackendAuthenticationConfig(
"BackendTls",
{
trustConfig: trust.name,
wellKnownRoots: "PUBLIC_ROOTS",
labels: { env: "prod" },
},
);

Source: src/GCP/NetworkSecurity/ClientTlsPolicy.ts

A Network Security ClientTlsPolicy — how a client authenticates connections to backends. The policy has no effect until it is attached to a backend service.

Changing clientTlsPolicyId or location replaces the policy. Description, labels, SNI, server-validation CAs, and the client certificate provider update in place.

ClientTlsPolicy: Creating a ClientTlsPolicy

Section titled “ClientTlsPolicy: Creating a ClientTlsPolicy”

Generated name

const policy = yield* GCP.NetworkSecurity.ClientTlsPolicy("BackendTls", {
sni: "backend.example.com",
});

Named policy with labels

const policy = yield* GCP.NetworkSecurity.ClientTlsPolicy("BackendTls", {
clientTlsPolicyId: "app-backend-tls",
description: "prod backends",
labels: { env: "prod" },
sni: "backend.example.com",
});
const policy = yield* GCP.NetworkSecurity.ClientTlsPolicy("Mtls", {
sni: "secure.example.com",
clientCertificate: {
certificateProviderInstance: {
pluginInstance: "google_cloud_private_spiffe",
},
},
serverValidationCa: [
{
certificateProviderInstance: {
pluginInstance: "google_cloud_private_spiffe",
},
},
],
});

Source: src/GCP/NetworkSecurity/DnsThreatDetector.ts

A DNS threat detector that sends VPC DNS query logs to Infoblox for analysis. By default every VPC in the project is monitored; pass excludedNetworks to skip specific networks.

A project may have only one detector. Changing dnsThreatDetectorId, location, or provider replaces the resource. Labels and excludedNetworks update in place.

DnsThreatDetector: Creating a DnsThreatDetector

Section titled “DnsThreatDetector: Creating a DnsThreatDetector”

Monitor every VPC

const detector = yield* GCP.NetworkSecurity.DnsThreatDetector("Armor", {
provider: "INFOBLOX",
});

Exclude a network

const detector = yield* GCP.NetworkSecurity.DnsThreatDetector("Armor", {
provider: "INFOBLOX",
excludedNetworks: [
`projects/${project}/global/networks/${vpc.networkName}`,
],
labels: { env: "prod" },
});

Source: src/GCP/NetworkSecurity/FirewallEndpoint.ts

A project-scoped Cloud NGFW firewall endpoint. Endpoints terminate inspected traffic in a zone; associate them with a VPC via FirewallEndpointAssociation.

Changing firewallEndpointId, location, billingProjectId, or jumbo-frame settings replaces the endpoint. Description and labels update in place. Provisioning is asynchronous and can take several minutes.

FirewallEndpoint: Creating a FirewallEndpoint

Section titled “FirewallEndpoint: Creating a FirewallEndpoint”

Generated name

const endpoint = yield* GCP.NetworkSecurity.FirewallEndpoint("Ngfw", {
location: "us-central1-a",
});

Named endpoint with labels

const endpoint = yield* GCP.NetworkSecurity.FirewallEndpoint("Ngfw", {
firewallEndpointId: "app-ngfw",
location: "us-central1-a",
description: "prod inspection",
labels: { env: "prod" },
});

Source: src/GCP/NetworkSecurity/FirewallEndpointAssociation.ts

Associates a Cloud NGFW FirewallEndpoint with a VPC network so matching traffic is intercepted for inspection.

Changing firewallEndpointAssociationId, location, network, or firewallEndpoint replaces the association. Labels, disabled, and tlsInspectionPolicy update in place.

FirewallEndpointAssociation: Creating a FirewallEndpointAssociation

Section titled “FirewallEndpointAssociation: Creating a FirewallEndpointAssociation”

Attach an endpoint to a VPC

const association = yield* GCP.NetworkSecurity.FirewallEndpointAssociation(
"Inspect",
{
location: "us-central1-a",
firewallEndpoint: endpoint.name,
network: `projects/${vpc.project}/global/networks/${vpc.networkName}`,
},
);

Disable interception

const association = yield* GCP.NetworkSecurity.FirewallEndpointAssociation(
"Inspect",
{
location: "us-central1-a",
firewallEndpoint: endpoint.name,
network: `projects/${vpc.project}/global/networks/${vpc.networkName}`,
disabled: true,
},
);

Source: src/GCP/NetworkSecurity/GatewaySecurityPoliciesRule.ts

A GatewaySecurityPolicyRule nested under a GatewaySecurityPolicy. Each rule matches traffic with CEL and applies ALLOW or DENY.

The API has no labels field, so Alchemy stamps ownership into the description for list / nuke. Changing the parent policy, rule id, or location replaces the rule. Matchers, priority, profile, enabled flag, TLS inspection, and description update in place.

GatewaySecurityPoliciesRule: Creating a GatewaySecurityPoliciesRule

Section titled “GatewaySecurityPoliciesRule: Creating a GatewaySecurityPoliciesRule”

Allow all sessions

const rule = yield* GCP.NetworkSecurity.GatewaySecurityPoliciesRule("Allow", {
gatewaySecurityPolicy: policy.name,
basicProfile: "ALLOW",
priority: 1000,
sessionMatcher: "true",
});

Deny by host

const rule = yield* GCP.NetworkSecurity.GatewaySecurityPoliciesRule("Block", {
gatewaySecurityPolicy: policy.name,
basicProfile: "DENY",
priority: 100,
enabled: true,
sessionMatcher: "host() == 'blocked.example.com'",
description: "block listed host",
});

Source: src/GCP/NetworkSecurity/GatewaySecurityPolicy.ts

A Gateway Security Policy — a collection of GatewaySecurityPolicyRules used by Secure Web Proxy.

The API has no labels field, so Alchemy stamps ownership into the description for list / nuke. Changing gatewaySecurityPolicyId or location replaces the policy. Description and tlsInspectionPolicy update in place.

GatewaySecurityPolicy: Creating a GatewaySecurityPolicy

Section titled “GatewaySecurityPolicy: Creating a GatewaySecurityPolicy”

Generated name

const policy = yield* GCP.NetworkSecurity.GatewaySecurityPolicy("Swp", {
description: "secure web proxy",
});

Named policy with TLS inspection

const policy = yield* GCP.NetworkSecurity.GatewaySecurityPolicy("Swp", {
gatewaySecurityPolicyId: "app-swp",
location: "us-central1",
tlsInspectionPolicy: inspection.name,
});

Source: src/GCP/NetworkSecurity/InterceptDeployment.ts

A zonal intercept deployment — a GENEVE backend (typically an internal passthrough load balancer) that belongs to a global InterceptDeploymentGroup.

Changing interceptDeploymentId, location, interceptDeploymentGroup, or forwardingRule replaces the deployment. Description and labels update in place.

InterceptDeployment: Creating an InterceptDeployment

Section titled “InterceptDeployment: Creating an InterceptDeployment”
const deployment = yield* GCP.NetworkSecurity.InterceptDeployment(
"ZoneA",
{
location: "us-central1-a",
interceptDeploymentGroup: group.name,
forwardingRule: rule.selfLink,
description: "us-central1-a interceptors",
},
);

Source: src/GCP/NetworkSecurity/InterceptDeploymentGroup.ts

A global intercept deployment group — aggregates zonal intercept backends into a single intercept service that consumers attach via an endpoint group.

Changing interceptDeploymentGroupId, location, or network replaces the group. Description and labels update in place.

InterceptDeploymentGroup: Creating an InterceptDeploymentGroup

Section titled “InterceptDeploymentGroup: Creating an InterceptDeploymentGroup”
const group = yield* GCP.NetworkSecurity.InterceptDeploymentGroup("Inspect", {
network: `projects/${vpc.project}/global/networks/${vpc.networkName}`,
description: "prod intercept",
labels: { env: "prod" },
});

Source: src/GCP/NetworkSecurity/InterceptEndpointGroup.ts

A Network Security Integration intercept endpoint group — the consumer frontend for an intercept deployment group.

Changing interceptEndpointGroupId, location, or interceptDeploymentGroup replaces the group. Description and labels update in place.

InterceptEndpointGroup: Creating an Endpoint Group

Section titled “InterceptEndpointGroup: Creating an Endpoint Group”

Generated name

const endpoints = yield* GCP.NetworkSecurity.InterceptEndpointGroup("Front", {
interceptDeploymentGroup: group.name,
});

Named group with labels

const endpoints = yield* GCP.NetworkSecurity.InterceptEndpointGroup("Front", {
interceptEndpointGroupId: "app-intercept-eg",
interceptDeploymentGroup: group.name,
description: "prod intercept frontend",
labels: { env: "prod" },
});

InterceptEndpointGroup: Updating an Endpoint Group

Section titled “InterceptEndpointGroup: Updating an Endpoint Group”
const endpoints = yield* GCP.NetworkSecurity.InterceptEndpointGroup("Front", {
interceptEndpointGroupId: "app-intercept-eg",
interceptDeploymentGroup: group.name,
description: "prod intercept frontend v2",
labels: { env: "prod", role: "nsi" },
});

Source: src/GCP/NetworkSecurity/InterceptEndpointGroupAssociation.ts

A Network Security Integration intercept endpoint-group association — the link between a VPC and an intercept endpoint group.

Creating an association does not enable intercept by itself; a firewall policy with intercept rules must also target the network. Changing interceptEndpointGroupAssociationId, location, interceptEndpointGroup, or network replaces the association. Labels update in place.

InterceptEndpointGroupAssociation: Creating an Association

Section titled “InterceptEndpointGroupAssociation: Creating an Association”

Generated name

const association = yield* GCP.NetworkSecurity.InterceptEndpointGroupAssociation("Link", {
interceptEndpointGroup: endpoints.name,
network: vpc.selfLink,
});

Named association with labels

const association = yield* GCP.NetworkSecurity.InterceptEndpointGroupAssociation("Link", {
interceptEndpointGroupAssociationId: "app-intercept-ega",
interceptEndpointGroup: endpoints.name,
network: "projects/my-project/global/networks/app-vpc",
labels: { env: "prod" },
});

InterceptEndpointGroupAssociation: Updating an Association

Section titled “InterceptEndpointGroupAssociation: Updating an Association”
const association = yield* GCP.NetworkSecurity.InterceptEndpointGroupAssociation("Link", {
interceptEndpointGroupAssociationId: "app-intercept-ega",
interceptEndpointGroup: endpoints.name,
network: vpc.selfLink,
labels: { env: "prod", role: "nsi" },
});

Source: src/GCP/NetworkSecurity/MirroringDeployment.ts

A Network Security Integration mirroring deployment — a zonal GENEVE collector, typically an internal passthrough load balancer, that belongs to a global mirroring deployment group.

Changing mirroringDeploymentId, location, mirroringDeploymentGroup, or forwardingRule replaces the deployment. Description and labels update in place.

MirroringDeployment: Creating a Deployment

Section titled “MirroringDeployment: Creating a Deployment”

Generated name

const deployment = yield* GCP.NetworkSecurity.MirroringDeployment("Collector", {
location: "us-central1-a",
mirroringDeploymentGroup: group.name,
forwardingRule: rule.selfLink,
});

Named deployment with labels

const deployment = yield* GCP.NetworkSecurity.MirroringDeployment("Collector", {
mirroringDeploymentId: "app-collector-a",
location: "us-central1-a",
mirroringDeploymentGroup: group.name,
forwardingRule: rule.selfLink,
description: "zone a collector",
labels: { env: "prod" },
});

MirroringDeployment: Updating a Deployment

Section titled “MirroringDeployment: Updating a Deployment”
const deployment = yield* GCP.NetworkSecurity.MirroringDeployment("Collector", {
mirroringDeploymentId: "app-collector-a",
location: "us-central1-a",
mirroringDeploymentGroup: group.name,
forwardingRule: rule.selfLink,
description: "zone a collector v2",
labels: { env: "prod", role: "nsi" },
});

Source: src/GCP/NetworkSecurity/MirroringDeploymentGroup.ts

A Network Security Integration mirroring deployment group — the global backend that aggregates zonal mirroring collectors.

Changing mirroringDeploymentGroupId, location, or network replaces the group. Description and labels update in place.

MirroringDeploymentGroup: Creating a Deployment Group

Section titled “MirroringDeploymentGroup: Creating a Deployment Group”

Generated name

const group = yield* GCP.NetworkSecurity.MirroringDeploymentGroup("Collectors", {
network: vpc.selfLink,
});

Named group with labels

const group = yield* GCP.NetworkSecurity.MirroringDeploymentGroup("Collectors", {
mirroringDeploymentGroupId: "app-collectors",
network: "projects/my-project/global/networks/app-vpc",
description: "prod mirroring backends",
labels: { env: "prod" },
});

MirroringDeploymentGroup: Updating a Deployment Group

Section titled “MirroringDeploymentGroup: Updating a Deployment Group”
const group = yield* GCP.NetworkSecurity.MirroringDeploymentGroup("Collectors", {
mirroringDeploymentGroupId: "app-collectors",
network: vpc.selfLink,
description: "prod mirroring backends v2",
labels: { env: "prod", role: "nsi" },
});

Source: src/GCP/NetworkSecurity/MirroringEndpointGroup.ts

A Network Security Integration mirroring endpoint group — the consumer frontend for a mirroring deployment group.

Changing mirroringEndpointGroupId, location, type, or mirroringDeploymentGroup replaces the group. Description and labels update in place.

MirroringEndpointGroup: Creating an Endpoint Group

Section titled “MirroringEndpointGroup: Creating an Endpoint Group”

Generated name

const endpoints = yield* GCP.NetworkSecurity.MirroringEndpointGroup("Front", {
mirroringDeploymentGroup: group.name,
});

Named group with labels

const endpoints = yield* GCP.NetworkSecurity.MirroringEndpointGroup("Front", {
mirroringEndpointGroupId: "app-mirroring-eg",
mirroringDeploymentGroup: group.name,
description: "prod mirroring frontend",
labels: { env: "prod" },
});

MirroringEndpointGroup: Updating an Endpoint Group

Section titled “MirroringEndpointGroup: Updating an Endpoint Group”
const endpoints = yield* GCP.NetworkSecurity.MirroringEndpointGroup("Front", {
mirroringEndpointGroupId: "app-mirroring-eg",
mirroringDeploymentGroup: group.name,
description: "prod mirroring frontend v2",
labels: { env: "prod", role: "nsi" },
});

Source: src/GCP/NetworkSecurity/MirroringEndpointGroupAssociation.ts

A Network Security Integration mirroring endpoint-group association — the link between a VPC and a mirroring endpoint group.

Creating an association does not enable mirroring by itself; a firewall policy with mirroring rules must also target the network. Changing mirroringEndpointGroupAssociationId, location, mirroringEndpointGroup, or network replaces the association. Labels update in place.

MirroringEndpointGroupAssociation: Creating an Association

Section titled “MirroringEndpointGroupAssociation: Creating an Association”

Generated name

const association = yield* GCP.NetworkSecurity.MirroringEndpointGroupAssociation("Link", {
mirroringEndpointGroup: endpoints.name,
network: vpc.selfLink,
});

Named association with labels

const association = yield* GCP.NetworkSecurity.MirroringEndpointGroupAssociation("Link", {
mirroringEndpointGroupAssociationId: "app-mirroring-ega",
mirroringEndpointGroup: endpoints.name,
network: "projects/my-project/global/networks/app-vpc",
labels: { env: "prod" },
});

MirroringEndpointGroupAssociation: Updating an Association

Section titled “MirroringEndpointGroupAssociation: Updating an Association”
const association = yield* GCP.NetworkSecurity.MirroringEndpointGroupAssociation("Link", {
mirroringEndpointGroupAssociationId: "app-mirroring-ega",
mirroringEndpointGroup: endpoints.name,
network: vpc.selfLink,
labels: { env: "prod", role: "nsi" },
});

Source: src/GCP/NetworkSecurity/OrganizationsAddressGroup.ts

An organization-scoped Network Security address group.

Changing addressGroupId, organization, location, type, capacity, or purpose replaces the group. Description, labels, and items update in place.

OrganizationsAddressGroup: Creating an Organization Address Group

Section titled “OrganizationsAddressGroup: Creating an Organization Address Group”

Generated name

const group = yield* GCP.NetworkSecurity.OrganizationsAddressGroup(
"OrgAllowlist",
{ items: ["10.0.0.1"] },
);

Named group

const group = yield* GCP.NetworkSecurity.OrganizationsAddressGroup(
"OrgAllowlist",
{
addressGroupId: "org-allowlist",
organization: "123456789",
type: "IPV4",
items: ["10.0.0.0/24"],
labels: { env: "prod" },
},
);

Source: src/GCP/NetworkSecurity/OrganizationsFirewallEndpoint.ts

An organization-scoped Cloud NGFW firewall endpoint.

Endpoints are zonal and bill to billingProjectId. Changing firewallEndpointId, organization, location, billingProjectId, or jumbo-frame settings replaces the endpoint. Description and labels update in place. Provisioning is slow — tests skip when FAST is set.

OrganizationsFirewallEndpoint: Creating a Firewall Endpoint

Section titled “OrganizationsFirewallEndpoint: Creating a Firewall Endpoint”

Generated name

const endpoint = yield* GCP.NetworkSecurity.OrganizationsFirewallEndpoint(
"Ngfw",
{ location: "us-central1-a" },
);

Named endpoint

const endpoint = yield* GCP.NetworkSecurity.OrganizationsFirewallEndpoint(
"Ngfw",
{
firewallEndpointId: "app-ngfw",
organization: "123456789",
location: "us-central1-a",
billingProjectId: "my-project",
description: "prod NGFW",
labels: { env: "prod" },
},
);

Source: src/GCP/NetworkSecurity/OrganizationsSecurityProfile.ts

An organization-scoped Network Security profile (threat prevention, URL filtering, custom mirroring, or custom intercept).

Changing securityProfileId, organization, location, type, or the immutable nested mirroring/intercept targets replaces the profile. Description, labels, and threat-prevention or URL-filter config update in place.

OrganizationsSecurityProfile: Creating a Security Profile

Section titled “OrganizationsSecurityProfile: Creating a Security Profile”
const profile = yield* GCP.NetworkSecurity.OrganizationsSecurityProfile(
"Threats",
{
type: "THREAT_PREVENTION",
threatPreventionProfile: {
severityOverrides: [{ severity: "INFORMATIONAL", action: "ALERT" }],
},
},
);

Source: src/GCP/NetworkSecurity/OrganizationsSecurityProfileGroup.ts

An organization-scoped group of Network Security profiles.

Changing securityProfileGroupId, organization, or location replaces the group. Profile references, description, and labels update in place.

OrganizationsSecurityProfileGroup: Creating a Security Profile Group

Section titled “OrganizationsSecurityProfileGroup: Creating a Security Profile Group”

Empty group

const group = yield* GCP.NetworkSecurity.OrganizationsSecurityProfileGroup(
"Profiles",
{},
);

Attach a threat-prevention profile

const group = yield* GCP.NetworkSecurity.OrganizationsSecurityProfileGroup(
"Profiles",
{
threatPreventionProfile: profile.name,
labels: { env: "prod" },
},
);

Source: src/GCP/NetworkSecurity/SacAttachment.ts

A Secure Access Connect (SAC) attachment — binds an NCC Gateway to a SAC realm so SSE traffic can be processed.

The realm must first be paired with the SSE partner’s realm (Palo Alto Prisma Access / Symantec) on the partner side; an unpaired realm is rejected with SacRealmNotPaired.

The create API has no patch; changing sacAttachmentId, location, sacRealm, nccGateway, or labels replaces the attachment.

Generated name

const attachment = yield* GCP.NetworkSecurity.SacAttachment("PrismaLink", {
sacRealm: realm.name,
nccGateway: gateway.name,
});

Named attachment with labels

const attachment = yield* GCP.NetworkSecurity.SacAttachment("PrismaLink", {
sacAttachmentId: "app-prisma-link",
location: "us-central1",
sacRealm: realm.name,
nccGateway: gateway.name,
labels: { env: "prod" },
});

Source: src/GCP/NetworkSecurity/SacRealm.ts

A Secure Access Connect (SAC) realm — the handshake between a Google Cloud project and an SSE partner such as Palo Alto Prisma Access.

The create API has no patch; changing sacRealmId, location, securityService, or labels replaces the realm.

Generated name

const realm = yield* GCP.NetworkSecurity.SacRealm("Prisma", {});

Named realm with labels

const realm = yield* GCP.NetworkSecurity.SacRealm("Prisma", {
sacRealmId: "app-prisma",
securityService: "PALO_ALTO_PRISMA_ACCESS",
labels: { env: "prod" },
});

Source: src/GCP/NetworkSecurity/SecurityProfile.ts

A Network Security SecurityProfile — the behavior for one ProfileType (threat prevention, URL filtering, custom mirroring, or custom intercept).

Changing securityProfileId, location, type, or an immutable nested target (mirroringEndpointGroup / interceptEndpointGroup) replaces the profile. Description, labels, and the mutable nested profile configuration update in place.

SecurityProfile: Creating a SecurityProfile

Section titled “SecurityProfile: Creating a SecurityProfile”

Threat prevention with a severity override

const profile = yield* GCP.NetworkSecurity.SecurityProfile("Threat", {
type: "THREAT_PREVENTION",
threatPreventionProfile: {
severityOverrides: [{ severity: "HIGH", action: "ALERT" }],
},
});

Named profile with labels

const profile = yield* GCP.NetworkSecurity.SecurityProfile("Threat", {
securityProfileId: "app-threat",
description: "prod threat prevention",
labels: { env: "prod" },
type: "THREAT_PREVENTION",
});

SecurityProfile: Updating a SecurityProfile

Section titled “SecurityProfile: Updating a SecurityProfile”
const profile = yield* GCP.NetworkSecurity.SecurityProfile("Threat", {
securityProfileId: "app-threat",
type: "THREAT_PREVENTION",
description: "prod threat prevention v2",
labels: { env: "prod", role: "ngfw" },
threatPreventionProfile: {
severityOverrides: [{ severity: "CRITICAL", action: "DENY" }],
},
});

Source: src/GCP/NetworkSecurity/SecurityProfileGroup.ts

A Network Security SecurityProfileGroup — a named bundle of SecurityProfile references applied together by firewall policy rules.

Changing securityProfileGroupId or location replaces the group. Description, labels, and profile references update in place.

SecurityProfileGroup: Creating a SecurityProfileGroup

Section titled “SecurityProfileGroup: Creating a SecurityProfileGroup”

Empty group

const group = yield* GCP.NetworkSecurity.SecurityProfileGroup("Ngfw", {});

Group bound to a threat-prevention profile

const profile = yield* GCP.NetworkSecurity.SecurityProfile("Threat", {
type: "THREAT_PREVENTION",
});
const group = yield* GCP.NetworkSecurity.SecurityProfileGroup("Ngfw", {
securityProfileGroupId: "app-ngfw",
description: "prod ngfw",
labels: { env: "prod" },
threatPreventionProfile: profile.name,
});

SecurityProfileGroup: Updating a SecurityProfileGroup

Section titled “SecurityProfileGroup: Updating a SecurityProfileGroup”
const group = yield* GCP.NetworkSecurity.SecurityProfileGroup("Ngfw", {
securityProfileGroupId: "app-ngfw",
description: "prod ngfw v2",
labels: { env: "prod", role: "ngfw" },
threatPreventionProfile: profile.name,
});

Source: src/GCP/NetworkSecurity/ServerTlsPolicy.ts

A Network Security ServerTlsPolicy — how a server authenticates incoming requests. Attach it to a TargetHttpsProxy or EndpointPolicy; the policy itself does not serve traffic.

Changing serverTlsPolicyId or location replaces the policy. Application Load Balancer policies (mtlsPolicy.clientValidationMode set) cannot be updated in place — any other change replaces them. Traffic Director policies update description, labels, allowOpen, serverCertificate, and mtlsPolicy in place.

ServerTlsPolicy: Creating a ServerTlsPolicy

Section titled “ServerTlsPolicy: Creating a ServerTlsPolicy”

Application Load Balancer mTLS

const policy = yield* GCP.NetworkSecurity.ServerTlsPolicy("FrontendTls", {
description: "alb mtls",
mtlsPolicy: {
clientValidationMode: "ALLOW_INVALID_OR_MISSING_CLIENT_CERT",
},
});

Named policy with labels

const policy = yield* GCP.NetworkSecurity.ServerTlsPolicy("FrontendTls", {
serverTlsPolicyId: "app-frontend-tls",
location: "global",
description: "prod frontend",
labels: { env: "prod" },
mtlsPolicy: {
clientValidationMode: "ALLOW_INVALID_OR_MISSING_CLIENT_CERT",
},
});

ServerTlsPolicy: Updating a ServerTlsPolicy

Section titled “ServerTlsPolicy: Updating a ServerTlsPolicy”
const policy = yield* GCP.NetworkSecurity.ServerTlsPolicy("FrontendTls", {
serverTlsPolicyId: "app-frontend-tls",
location: "global",
description: "prod frontend v2",
labels: { env: "prod", role: "tls" },
mtlsPolicy: {
clientValidationMode: "ALLOW_INVALID_OR_MISSING_CLIENT_CERT",
},
});

Source: src/GCP/NetworkSecurity/TlsInspectionPolicy.ts

A Network Security TlsInspectionPolicy — CA pool and TLS settings used to intercept TLS for Secure Web Proxy and Cloud NGFW.

TlsInspectionPolicy has no labels field, so Alchemy stamps ownership into the description for list / nuke. Changing tlsInspectionPolicyId or location replaces the policy. caPool, description, TLS feature profile, min version, custom features, excludePublicCaSet, and trustConfig update in place.

TlsInspectionPolicy: Creating a TlsInspectionPolicy

Section titled “TlsInspectionPolicy: Creating a TlsInspectionPolicy”

Intercept with a CaPool

const pool = yield* GCP.PrivateCA.CaPool("Intercept", {
location: "us-central1",
tier: "DEVOPS",
});
const policy = yield* GCP.NetworkSecurity.TlsInspectionPolicy("Inspect", {
caPool: pool.name,
});

Named policy with TLS constraints

const policy = yield* GCP.NetworkSecurity.TlsInspectionPolicy("Inspect", {
tlsInspectionPolicyId: "app-inspect",
location: "us-central1",
caPool: pool.name,
description: "prod intercept",
excludePublicCaSet: true,
minTlsVersion: "TLS_1_2",
tlsFeatureProfile: "PROFILE_MODERN",
});

TlsInspectionPolicy: Updating a TlsInspectionPolicy

Section titled “TlsInspectionPolicy: Updating a TlsInspectionPolicy”
const policy = yield* GCP.NetworkSecurity.TlsInspectionPolicy("Inspect", {
tlsInspectionPolicyId: "app-inspect",
location: "us-central1",
caPool: pool.name,
description: "prod intercept v2",
excludePublicCaSet: true,
minTlsVersion: "TLS_1_2",
});

Source: src/GCP/NetworkSecurity/UrlList.ts

A reusable list of hosts, host patterns, URLs, and URL patterns used by Secure Web Proxy URL filtering.

UrlList has no labels field, so Alchemy stamps ownership into the description for list / nuke. Changing urlListId or location replaces the list. values and description update in place.

Generated name

const blocked = yield* GCP.NetworkSecurity.UrlList("Blocked", {
values: ["malware.example.com", "phishing.example.net"],
});

Named list with a description

const blocked = yield* GCP.NetworkSecurity.UrlList("Blocked", {
urlListId: "app-blocked-hosts",
location: "us-central1",
description: "denied destinations",
values: ["malware.example.com"],
});
const blocked = yield* GCP.NetworkSecurity.UrlList("Blocked", {
urlListId: "app-blocked-hosts",
location: "us-central1",
description: "denied destinations v2",
values: ["malware.example.com", "c2.example.net"],
});