GCP.SecurityPosture reference
Posture
Section titled “Posture”Source:
src/GCP/SecurityPosture/Posture.ts
An organization-scoped Security Command Center security posture.
A posture groups organization-policy constraints and Security Health
Analytics detectors into policy sets that can be deployed to a
project, folder, or organization. Postures live under
organizations/{organization}/locations/global. They have no labels
field — Alchemy stamps ownership into annotations. postureId and
organization are identity. Description, policy sets, and state
update in place. State cannot be patched in the same request as other
fields.
Creating a posture requires the Security Posture API and organization-level Security Command Center Premium or Enterprise.
Posture: Creating a Posture
Section titled “Posture: Creating a Posture”Generated id with the default detector policy set
const posture = yield* GCP.SecurityPosture.Posture("Baseline", { description: "staging baseline",});Named ACTIVE posture with a Security Health Analytics module
const posture = yield* GCP.SecurityPosture.Posture("Baseline", { organization: "organizations/123456789", postureId: "staging-baseline", state: "ACTIVE", policySets: [ { policySetId: "sha", policies: [ { policyId: "api-key-exists", constraint: { securityHealthAnalyticsModule: { moduleName: "API_KEY_EXISTS", moduleEnablementState: "DISABLED", }, }, }, ], }, ],});PostureDeployment
Section titled “PostureDeployment”Source:
src/GCP/SecurityPosture/PostureDeployment.ts
A Security Command Center posture deployment.
Deployments apply a posture revision to one organization, folder, or
project. The parent is always the organization, even when the target
is a folder or project. At most one posture can be deployed to each
target. Deployments have no labels field — Alchemy stamps ownership
into annotations. postureDeploymentId, organization, and
targetResource are identity. postureId and postureRevisionId
update in place.
The posture must be ACTIVE. Creating a deployment requires the
Security Posture API and organization-level Security Command Center
Premium or Enterprise.
PostureDeployment: Creating a Posture Deployment
Section titled “PostureDeployment: Creating a Posture Deployment”Deploy a posture to the stack project
const posture = yield* GCP.SecurityPosture.Posture("Baseline", { state: "ACTIVE",});const deployment = yield* GCP.SecurityPosture.PostureDeployment( "Staging", { postureId: posture.name, postureRevisionId: posture.revisionId, },);Deploy to an explicit project
const deployment = yield* GCP.SecurityPosture.PostureDeployment( "Staging", { organization: "organizations/123456789", targetResource: "projects/987654321", postureId: "organizations/123456789/locations/global/postures/staging-baseline", postureRevisionId: "abcdefgh", description: "staging deployment", },);