Skip to content

GCP.OrgPolicy reference

Source: src/GCP/OrgPolicy/CustomConstraint.ts

A Google Cloud Organization Policy custom constraint.

Custom constraints can only be created on an organization. Creating one does not enforce anything — attach a GCP.OrgPolicy.Policy that references the constraint id to enforce it.

Custom constraints have no labels. Alchemy stamps ownership into the description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…]) so list / pnpm nuke:gcp can find them.

constraintId, organization, and resourceTypes are immutable — changing them replaces the constraint. methodTypes, condition, actionType, displayName, and description update in place.

CustomConstraint: Creating a Custom Constraint

Section titled “CustomConstraint: Creating a Custom Constraint”

Deny matching Compute instances

const constraint = yield* GCP.OrgPolicy.CustomConstraint("NoTestVms", {
resourceTypes: ["compute.googleapis.com/Instance"],
methodTypes: ["CREATE"],
condition: "resource.name.startsWith('test-')",
actionType: "DENY",
displayName: "Deny test VMs",
});

Named constraint on an explicit organization

const constraint = yield* GCP.OrgPolicy.CustomConstraint("NoTestVms", {
constraintId: "custom.denyTestVms",
organization: "organizations/123456789",
resourceTypes: ["compute.googleapis.com/Instance"],
methodTypes: ["CREATE", "UPDATE"],
condition: "resource.name.startsWith('test-')",
actionType: "DENY",
displayName: "Deny test VMs",
description: "blocks test-prefixed instances",
});

CustomConstraint: Updating a Custom Constraint

Section titled “CustomConstraint: Updating a Custom Constraint”
const constraint = yield* GCP.OrgPolicy.CustomConstraint("NoTestVms", {
constraintId: "custom.denyTestVms",
resourceTypes: ["compute.googleapis.com/Instance"],
methodTypes: ["CREATE", "UPDATE"],
condition: "resource.name.startsWith('tmp-')",
actionType: "DENY",
displayName: "Deny tmp VMs",
});

Source: src/GCP/OrgPolicy/Policy.ts

A Google Cloud Organization Policy on a project, folder, or organization.

Identity is (parent, constraint) — the constraint must already exist (built-in or custom). Organization policies have no labels or description field; Alchemy treats existence at the computed name as ownership, and list returns every policy set on the current project so pnpm nuke:gcp can clean leaks.

constraint and parent are immutable. spec and dryRunSpec update in place.

Enforce a boolean constraint on the current project

const serial = yield* GCP.OrgPolicy.Policy("SerialPort", {
constraint: "compute.disableSerialPortAccess",
spec: {
rules: [{ enforce: true }],
},
});

List constraint that allows every value

const locations = yield* GCP.OrgPolicy.Policy("Locations", {
constraint: "gcp.resourceLocations",
spec: {
inheritFromParent: false,
rules: [{ allowAll: true }],
},
});
const serial = yield* GCP.OrgPolicy.Policy("SerialPort", {
constraint: "compute.disableSerialPortAccess",
spec: {
rules: [{ enforce: true }],
},
dryRunSpec: {
rules: [{ enforce: true }],
},
});
const serial = yield* GCP.OrgPolicy.Policy("SerialPort", {
constraint: "compute.disableSerialPortAccess",
spec: {
rules: [{ enforce: false }],
},
});