GCP.ResourceManager reference
Folder
Section titled “Folder”Source:
src/GCP/ResourceManager/Folder.ts
A Cloud Resource Manager folder — a node in an organization’s resource hierarchy used to group projects and other folders.
Folders have no labels, so a folder found without prior state is
reported as unowned and only taken over with --adopt. displayName
updates in place; changing parent moves the folder. Delete is a 30-day
soft-delete (DELETE_REQUESTED).
Folder: Creating a Folder
Section titled “Folder: Creating a Folder”Generated display name under the current project’s parent
const folder = yield* GCP.ResourceManager.Folder("Team", {});Explicit display name and parent
const folder = yield* GCP.ResourceManager.Folder("Team", { displayName: "platform", parent: "organizations/123456789",});Folder: Updating a Folder
Section titled “Folder: Updating a Folder”const folder = yield* GCP.ResourceManager.Folder("Team", { displayName: "platform-prod",});Source:
src/GCP/ResourceManager/Lien.ts
A Cloud Resource Manager lien — an encumbrance that blocks selected operations on a project (most commonly project deletion).
Liens have no update API, id, or labels: the lien on parent with the
same origin, reason, and restrictions is the managed one, and list /
pnpm nuke:gcp return liens whose origin is alchemy.effect. Changing parent,
origin, reason, or restrictions replaces the lien (delete-first).
Lien: Creating a Lien
Section titled “Lien: Creating a Lien”Block deletion of the current project
const lien = yield* GCP.ResourceManager.Lien("Hold", { reason: "production API key",});Explicit parent and restrictions
const lien = yield* GCP.ResourceManager.Lien("Hold", { parent: "projects/123456789", origin: "alchemy.effect", reason: "holds billing export", restrictions: ["resourcemanager.projects.delete"],});Project
Section titled “Project”Source:
src/GCP/ResourceManager/Project.ts
A Google Cloud project — the container for APIs, IAM, billing, and other resources.
projectId is globally unique and immutable; changing it replaces
the project. parent is moved in place. displayName and labels
update in place. Delete is a 30-day soft-delete (DELETE_REQUESTED).
Alchemy ownership labels are applied so list / pnpm nuke:gcp can
find leftover projects.
Project: Creating a Project
Section titled “Project: Creating a Project”Generated project id under the current project’s parent
const project = yield* GCP.ResourceManager.Project("Sandbox", {});Explicit id, parent, and labels
const project = yield* GCP.ResourceManager.Project("Sandbox", { projectId: "my-app-sandbox", parent: "folders/123456789", displayName: "Sandbox", labels: { env: "test" },});Project: Updating a Project
Section titled “Project: Updating a Project”const project = yield* GCP.ResourceManager.Project("Sandbox", { projectId: "my-app-sandbox", displayName: "Sandbox prod", labels: { env: "prod" },});TagBinding
Section titled “TagBinding”Source:
src/GCP/ResourceManager/TagBinding.ts
A Resource Manager TagBinding — a connection between a TagValue and a Google Cloud resource (project, folder, or organization). Creating the binding applies the TagValue to the resource and its descendants.
TagBindings have no labels and no update API. Identity is
(parent, tagValue); changing either replaces the binding
(delete-first, because a resource may only hold one value per TagKey).
A binding found without prior state is reported as unowned and only
taken over with --adopt.
TagBinding: Creating a Tag Binding
Section titled “TagBinding: Creating a Tag Binding”Bind a TagValue to the current project
const binding = yield* GCP.ResourceManager.TagBinding("Env", { tagValue: "tagValues/456",});Explicit parent and namespaced TagValue
const binding = yield* GCP.ResourceManager.TagBinding("Env", { parent: "//cloudresourcemanager.googleapis.com/projects/123456789", tagValue: "my-project/environment/prod",});TagKey
Section titled “TagKey”Source:
src/GCP/ResourceManager/TagKey.ts
A Resource Manager TagKey — a namespace for TagValues used to annotate Google Cloud resources.
Without labels, ownership rests on the deterministic id: read reports a
resource it finds without prior state as unowned (adopt it with --adopt).
TagKeys have no labels.
shortName, parent, purpose, purposeData, and allowedValuesRegex
are immutable — changing them replaces the key. description is the only
updatable field.
TagKey: Creating a TagKey
Section titled “TagKey: Creating a TagKey”Generated short name
const env = yield* GCP.ResourceManager.TagKey("Environment", {});Explicit short name and description
const env = yield* GCP.ResourceManager.TagKey("Environment", { shortName: "environment", description: "deployment environment", parent: "projects/my-project",});TagKey: Updating a TagKey
Section titled “TagKey: Updating a TagKey”const env = yield* GCP.ResourceManager.TagKey("Environment", { shortName: "environment", description: "prod vs staging",});TagValue
Section titled “TagValue”Source:
src/GCP/ResourceManager/TagValue.ts
A Cloud Resource Manager TagValue — a child of a TagKey used to group resources for policy.
Without labels, ownership rests on the deterministic id: read reports a
resource it finds without prior state as unowned (adopt it with --adopt).
parent and shortName are identity — changing either replaces the value.
Description updates in place. Create, update, and delete are long-running
operations polled via getOperations.
TagValue: Creating a TagValue
Section titled “TagValue: Creating a TagValue”Generated short name under a TagKey
const key = yield* GCP.ResourceManager.TagKey("Environment", {});const value = yield* GCP.ResourceManager.TagValue("Prod", { parent: key.name, description: "production",});Explicit short name
const value = yield* GCP.ResourceManager.TagValue("Prod", { parent: "tagKeys/123456789012", shortName: "prod", description: "production",});TagValue: Updating a TagValue
Section titled “TagValue: Updating a TagValue”const value = yield* GCP.ResourceManager.TagValue("Prod", { parent: "tagKeys/123456789012", shortName: "prod", description: "production workloads",});