GCP.OrgPolicy reference
CustomConstraint
Section titled “CustomConstraint”Source:
src/GCP/OrgPolicy/CustomConstraint.ts
A Google Cloud Organization Policy custom constraint.
Custom constraints can only be created on an organization. Creating one
does not enforce anything — attach a GCP.OrgPolicy.Policy that
references the constraint id to enforce it.
Custom constraints have no labels. Alchemy stamps ownership into the
description ([alchemy alchemy-stack=… alchemy-stage=… alchemy-id=…])
so list / pnpm nuke:gcp can find them.
constraintId, organization, and resourceTypes are immutable —
changing them replaces the constraint. methodTypes, condition,
actionType, displayName, and description update in place.
CustomConstraint: Creating a Custom Constraint
Section titled “CustomConstraint: Creating a Custom Constraint”Deny matching Compute instances
const constraint = yield* GCP.OrgPolicy.CustomConstraint("NoTestVms", { resourceTypes: ["compute.googleapis.com/Instance"], methodTypes: ["CREATE"], condition: "resource.name.startsWith('test-')", actionType: "DENY", displayName: "Deny test VMs",});Named constraint on an explicit organization
const constraint = yield* GCP.OrgPolicy.CustomConstraint("NoTestVms", { constraintId: "custom.denyTestVms", organization: "organizations/123456789", resourceTypes: ["compute.googleapis.com/Instance"], methodTypes: ["CREATE", "UPDATE"], condition: "resource.name.startsWith('test-')", actionType: "DENY", displayName: "Deny test VMs", description: "blocks test-prefixed instances",});CustomConstraint: Updating a Custom Constraint
Section titled “CustomConstraint: Updating a Custom Constraint”const constraint = yield* GCP.OrgPolicy.CustomConstraint("NoTestVms", { constraintId: "custom.denyTestVms", resourceTypes: ["compute.googleapis.com/Instance"], methodTypes: ["CREATE", "UPDATE"], condition: "resource.name.startsWith('tmp-')", actionType: "DENY", displayName: "Deny tmp VMs",});Policy
Section titled “Policy”Source:
src/GCP/OrgPolicy/Policy.ts
A Google Cloud Organization Policy on a project, folder, or organization.
Identity is (parent, constraint) — the constraint must already exist
(built-in or custom). Organization policies have no labels or description
field; Alchemy treats existence at the computed name as ownership, and
list returns every policy set on the current project so pnpm nuke:gcp
can clean leaks.
constraint and parent are immutable. spec and dryRunSpec update
in place.
Policy: Creating a Policy
Section titled “Policy: Creating a Policy”Enforce a boolean constraint on the current project
const serial = yield* GCP.OrgPolicy.Policy("SerialPort", { constraint: "compute.disableSerialPortAccess", spec: { rules: [{ enforce: true }], },});List constraint that allows every value
const locations = yield* GCP.OrgPolicy.Policy("Locations", { constraint: "gcp.resourceLocations", spec: { inheritFromParent: false, rules: [{ allowAll: true }], },});Policy: Dry-run
Section titled “Policy: Dry-run”const serial = yield* GCP.OrgPolicy.Policy("SerialPort", { constraint: "compute.disableSerialPortAccess", spec: { rules: [{ enforce: true }], }, dryRunSpec: { rules: [{ enforce: true }], },});Policy: Updating a Policy
Section titled “Policy: Updating a Policy”const serial = yield* GCP.OrgPolicy.Policy("SerialPort", { constraint: "compute.disableSerialPortAccess", spec: { rules: [{ enforce: false }], },});