Skip to content

GCP.SecurityPosture reference

Source: src/GCP/SecurityPosture/Posture.ts

An organization-scoped Security Command Center security posture.

A posture groups organization-policy constraints and Security Health Analytics detectors into policy sets that can be deployed to a project, folder, or organization. Postures live under organizations/{organization}/locations/global. They have no labels field — Alchemy stamps ownership into annotations. postureId and organization are identity. Description, policy sets, and state update in place. State cannot be patched in the same request as other fields.

Creating a posture requires the Security Posture API and organization-level Security Command Center Premium or Enterprise.

Generated id with the default detector policy set

const posture = yield* GCP.SecurityPosture.Posture("Baseline", {
description: "staging baseline",
});

Named ACTIVE posture with a Security Health Analytics module

const posture = yield* GCP.SecurityPosture.Posture("Baseline", {
organization: "organizations/123456789",
postureId: "staging-baseline",
state: "ACTIVE",
policySets: [
{
policySetId: "sha",
policies: [
{
policyId: "api-key-exists",
constraint: {
securityHealthAnalyticsModule: {
moduleName: "API_KEY_EXISTS",
moduleEnablementState: "DISABLED",
},
},
},
],
},
],
});

Source: src/GCP/SecurityPosture/PostureDeployment.ts

A Security Command Center posture deployment.

Deployments apply a posture revision to one organization, folder, or project. The parent is always the organization, even when the target is a folder or project. At most one posture can be deployed to each target. Deployments have no labels field — Alchemy stamps ownership into annotations. postureDeploymentId, organization, and targetResource are identity. postureId and postureRevisionId update in place.

The posture must be ACTIVE. Creating a deployment requires the Security Posture API and organization-level Security Command Center Premium or Enterprise.

PostureDeployment: Creating a Posture Deployment

Section titled “PostureDeployment: Creating a Posture Deployment”

Deploy a posture to the stack project

const posture = yield* GCP.SecurityPosture.Posture("Baseline", {
state: "ACTIVE",
});
const deployment = yield* GCP.SecurityPosture.PostureDeployment(
"Staging",
{
postureId: posture.name,
postureRevisionId: posture.revisionId,
},
);

Deploy to an explicit project

const deployment = yield* GCP.SecurityPosture.PostureDeployment(
"Staging",
{
organization: "organizations/123456789",
targetResource: "projects/987654321",
postureId:
"organizations/123456789/locations/global/postures/staging-baseline",
postureRevisionId: "abcdefgh",
description: "staging deployment",
},
);