Documentation ¶
Index ¶
- type Binding
- type BindingArgs
- type BindingArray
- type BindingArrayInput
- type BindingArrayOutput
- type BindingInput
- type BindingOutput
- func (o BindingOutput) Condition() ExprPtrOutput
- func (BindingOutput) ElementType() reflect.Type
- func (o BindingOutput) Members() pulumi.StringArrayOutput
- func (o BindingOutput) Role() pulumi.StringPtrOutput
- func (o BindingOutput) ToBindingOutput() BindingOutput
- func (o BindingOutput) ToBindingOutputWithContext(ctx context.Context) BindingOutput
- type BindingResponse
- type BindingResponseArrayOutput
- func (BindingResponseArrayOutput) ElementType() reflect.Type
- func (o BindingResponseArrayOutput) Index(i pulumi.IntInput) BindingResponseOutput
- func (o BindingResponseArrayOutput) ToBindingResponseArrayOutput() BindingResponseArrayOutput
- func (o BindingResponseArrayOutput) ToBindingResponseArrayOutputWithContext(ctx context.Context) BindingResponseArrayOutput
- type BindingResponseOutput
- func (o BindingResponseOutput) Condition() ExprResponseOutput
- func (BindingResponseOutput) ElementType() reflect.Type
- func (o BindingResponseOutput) Members() pulumi.StringArrayOutput
- func (o BindingResponseOutput) Role() pulumi.StringOutput
- func (o BindingResponseOutput) ToBindingResponseOutput() BindingResponseOutput
- func (o BindingResponseOutput) ToBindingResponseOutputWithContext(ctx context.Context) BindingResponseOutput
- type Brand
- type BrandArgs
- type BrandInput
- type BrandOutput
- func (o BrandOutput) ApplicationTitle() pulumi.StringOutput
- func (BrandOutput) ElementType() reflect.Type
- func (o BrandOutput) Name() pulumi.StringOutput
- func (o BrandOutput) OrgInternalOnly() pulumi.BoolOutput
- func (o BrandOutput) Project() pulumi.StringOutput
- func (o BrandOutput) SupportEmail() pulumi.StringOutput
- func (o BrandOutput) ToBrandOutput() BrandOutput
- func (o BrandOutput) ToBrandOutputWithContext(ctx context.Context) BrandOutput
- type BrandState
- type DestGroup
- type DestGroupArgs
- type DestGroupInput
- type DestGroupOutput
- func (o DestGroupOutput) Cidrs() pulumi.StringArrayOutput
- func (DestGroupOutput) ElementType() reflect.Type
- func (o DestGroupOutput) Fqdns() pulumi.StringArrayOutput
- func (o DestGroupOutput) Location() pulumi.StringOutput
- func (o DestGroupOutput) Name() pulumi.StringOutput
- func (o DestGroupOutput) Project() pulumi.StringOutput
- func (o DestGroupOutput) ToDestGroupOutput() DestGroupOutput
- func (o DestGroupOutput) ToDestGroupOutputWithContext(ctx context.Context) DestGroupOutput
- func (o DestGroupOutput) TunnelDestGroupId() pulumi.StringOutput
- type DestGroupState
- type Expr
- type ExprArgs
- type ExprInput
- type ExprOutput
- func (o ExprOutput) Description() pulumi.StringPtrOutput
- func (ExprOutput) ElementType() reflect.Type
- func (o ExprOutput) Expression() pulumi.StringPtrOutput
- func (o ExprOutput) Location() pulumi.StringPtrOutput
- func (o ExprOutput) Title() pulumi.StringPtrOutput
- func (o ExprOutput) ToExprOutput() ExprOutput
- func (o ExprOutput) ToExprOutputWithContext(ctx context.Context) ExprOutput
- func (o ExprOutput) ToExprPtrOutput() ExprPtrOutput
- func (o ExprOutput) ToExprPtrOutputWithContext(ctx context.Context) ExprPtrOutput
- type ExprPtrInput
- type ExprPtrOutput
- func (o ExprPtrOutput) Description() pulumi.StringPtrOutput
- func (o ExprPtrOutput) Elem() ExprOutput
- func (ExprPtrOutput) ElementType() reflect.Type
- func (o ExprPtrOutput) Expression() pulumi.StringPtrOutput
- func (o ExprPtrOutput) Location() pulumi.StringPtrOutput
- func (o ExprPtrOutput) Title() pulumi.StringPtrOutput
- func (o ExprPtrOutput) ToExprPtrOutput() ExprPtrOutput
- func (o ExprPtrOutput) ToExprPtrOutputWithContext(ctx context.Context) ExprPtrOutput
- type ExprResponse
- type ExprResponseOutput
- func (o ExprResponseOutput) Description() pulumi.StringOutput
- func (ExprResponseOutput) ElementType() reflect.Type
- func (o ExprResponseOutput) Expression() pulumi.StringOutput
- func (o ExprResponseOutput) Location() pulumi.StringOutput
- func (o ExprResponseOutput) Title() pulumi.StringOutput
- func (o ExprResponseOutput) ToExprResponseOutput() ExprResponseOutput
- func (o ExprResponseOutput) ToExprResponseOutputWithContext(ctx context.Context) ExprResponseOutput
- type IdentityAwareProxyClient
- type IdentityAwareProxyClientArgs
- type IdentityAwareProxyClientInput
- type IdentityAwareProxyClientOutput
- func (o IdentityAwareProxyClientOutput) BrandId() pulumi.StringOutput
- func (o IdentityAwareProxyClientOutput) DisplayName() pulumi.StringOutput
- func (IdentityAwareProxyClientOutput) ElementType() reflect.Type
- func (o IdentityAwareProxyClientOutput) Name() pulumi.StringOutput
- func (o IdentityAwareProxyClientOutput) Project() pulumi.StringOutput
- func (o IdentityAwareProxyClientOutput) Secret() pulumi.StringOutput
- func (o IdentityAwareProxyClientOutput) ToIdentityAwareProxyClientOutput() IdentityAwareProxyClientOutput
- func (o IdentityAwareProxyClientOutput) ToIdentityAwareProxyClientOutputWithContext(ctx context.Context) IdentityAwareProxyClientOutput
- type IdentityAwareProxyClientState
- type LookupBrandArgs
- type LookupBrandOutputArgs
- type LookupBrandResult
- type LookupBrandResultOutput
- func (o LookupBrandResultOutput) ApplicationTitle() pulumi.StringOutput
- func (LookupBrandResultOutput) ElementType() reflect.Type
- func (o LookupBrandResultOutput) Name() pulumi.StringOutput
- func (o LookupBrandResultOutput) OrgInternalOnly() pulumi.BoolOutput
- func (o LookupBrandResultOutput) SupportEmail() pulumi.StringOutput
- func (o LookupBrandResultOutput) ToLookupBrandResultOutput() LookupBrandResultOutput
- func (o LookupBrandResultOutput) ToLookupBrandResultOutputWithContext(ctx context.Context) LookupBrandResultOutput
- type LookupDestGroupArgs
- type LookupDestGroupOutputArgs
- type LookupDestGroupResult
- type LookupDestGroupResultOutput
- func (o LookupDestGroupResultOutput) Cidrs() pulumi.StringArrayOutput
- func (LookupDestGroupResultOutput) ElementType() reflect.Type
- func (o LookupDestGroupResultOutput) Fqdns() pulumi.StringArrayOutput
- func (o LookupDestGroupResultOutput) Name() pulumi.StringOutput
- func (o LookupDestGroupResultOutput) ToLookupDestGroupResultOutput() LookupDestGroupResultOutput
- func (o LookupDestGroupResultOutput) ToLookupDestGroupResultOutputWithContext(ctx context.Context) LookupDestGroupResultOutput
- type LookupIdentityAwareProxyClientArgs
- type LookupIdentityAwareProxyClientOutputArgs
- type LookupIdentityAwareProxyClientResult
- type LookupIdentityAwareProxyClientResultOutput
- func (o LookupIdentityAwareProxyClientResultOutput) DisplayName() pulumi.StringOutput
- func (LookupIdentityAwareProxyClientResultOutput) ElementType() reflect.Type
- func (o LookupIdentityAwareProxyClientResultOutput) Name() pulumi.StringOutput
- func (o LookupIdentityAwareProxyClientResultOutput) Secret() pulumi.StringOutput
- func (o LookupIdentityAwareProxyClientResultOutput) ToLookupIdentityAwareProxyClientResultOutput() LookupIdentityAwareProxyClientResultOutput
- func (o LookupIdentityAwareProxyClientResultOutput) ToLookupIdentityAwareProxyClientResultOutputWithContext(ctx context.Context) LookupIdentityAwareProxyClientResultOutput
- type LookupV1IamPolicyArgs
- type LookupV1IamPolicyOutputArgs
- type LookupV1IamPolicyResult
- type LookupV1IamPolicyResultOutput
- func (o LookupV1IamPolicyResultOutput) Bindings() BindingResponseArrayOutput
- func (LookupV1IamPolicyResultOutput) ElementType() reflect.Type
- func (o LookupV1IamPolicyResultOutput) Etag() pulumi.StringOutput
- func (o LookupV1IamPolicyResultOutput) ToLookupV1IamPolicyResultOutput() LookupV1IamPolicyResultOutput
- func (o LookupV1IamPolicyResultOutput) ToLookupV1IamPolicyResultOutputWithContext(ctx context.Context) LookupV1IamPolicyResultOutput
- func (o LookupV1IamPolicyResultOutput) Version() pulumi.IntOutput
- type V1IamBinding
- type V1IamBindingArgs
- type V1IamBindingInput
- type V1IamBindingOutput
- func (o V1IamBindingOutput) Condition() iam.ConditionPtrOutput
- func (V1IamBindingOutput) ElementType() reflect.Type
- func (o V1IamBindingOutput) Etag() pulumi.StringOutput
- func (o V1IamBindingOutput) Members() pulumi.StringArrayOutput
- func (o V1IamBindingOutput) Name() pulumi.StringOutput
- func (o V1IamBindingOutput) Project() pulumi.StringOutput
- func (o V1IamBindingOutput) Role() pulumi.StringOutput
- func (o V1IamBindingOutput) ToV1IamBindingOutput() V1IamBindingOutput
- func (o V1IamBindingOutput) ToV1IamBindingOutputWithContext(ctx context.Context) V1IamBindingOutput
- type V1IamBindingState
- type V1IamMember
- type V1IamMemberArgs
- type V1IamMemberInput
- type V1IamMemberOutput
- func (o V1IamMemberOutput) Condition() iam.ConditionPtrOutput
- func (V1IamMemberOutput) ElementType() reflect.Type
- func (o V1IamMemberOutput) Etag() pulumi.StringOutput
- func (o V1IamMemberOutput) Member() pulumi.StringOutput
- func (o V1IamMemberOutput) Name() pulumi.StringOutput
- func (o V1IamMemberOutput) Project() pulumi.StringOutput
- func (o V1IamMemberOutput) Role() pulumi.StringOutput
- func (o V1IamMemberOutput) ToV1IamMemberOutput() V1IamMemberOutput
- func (o V1IamMemberOutput) ToV1IamMemberOutputWithContext(ctx context.Context) V1IamMemberOutput
- type V1IamMemberState
- type V1IamPolicy
- type V1IamPolicyArgs
- type V1IamPolicyInput
- type V1IamPolicyOutput
- func (o V1IamPolicyOutput) Bindings() BindingResponseArrayOutput
- func (V1IamPolicyOutput) ElementType() reflect.Type
- func (o V1IamPolicyOutput) Etag() pulumi.StringOutput
- func (o V1IamPolicyOutput) ToV1IamPolicyOutput() V1IamPolicyOutput
- func (o V1IamPolicyOutput) ToV1IamPolicyOutputWithContext(ctx context.Context) V1IamPolicyOutput
- func (o V1IamPolicyOutput) V1Id() pulumi.StringOutput
- func (o V1IamPolicyOutput) Version() pulumi.IntOutput
- type V1IamPolicyState
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Binding ¶
type Binding struct { // The condition that is associated with this binding. If the condition evaluates to `true`, then this binding applies to the current request. If the condition evaluates to `false`, then this binding does not apply to the current request. However, a different role binding might grant the same role to one or more of the principals in this binding. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies). Condition *Expr `pulumi:"condition"` // Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding. Members []string `pulumi:"members"` // Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`. Role *string `pulumi:"role"` }
Associates `members`, or principals, with a `role`.
type BindingArgs ¶
type BindingArgs struct { // The condition that is associated with this binding. If the condition evaluates to `true`, then this binding applies to the current request. If the condition evaluates to `false`, then this binding does not apply to the current request. However, a different role binding might grant the same role to one or more of the principals in this binding. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies). Condition ExprPtrInput `pulumi:"condition"` // Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding. Members pulumi.StringArrayInput `pulumi:"members"` // Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`. Role pulumi.StringPtrInput `pulumi:"role"` }
Associates `members`, or principals, with a `role`.
func (BindingArgs) ElementType ¶
func (BindingArgs) ElementType() reflect.Type
func (BindingArgs) ToBindingOutput ¶
func (i BindingArgs) ToBindingOutput() BindingOutput
func (BindingArgs) ToBindingOutputWithContext ¶
func (i BindingArgs) ToBindingOutputWithContext(ctx context.Context) BindingOutput
type BindingArray ¶
type BindingArray []BindingInput
func (BindingArray) ElementType ¶
func (BindingArray) ElementType() reflect.Type
func (BindingArray) ToBindingArrayOutput ¶
func (i BindingArray) ToBindingArrayOutput() BindingArrayOutput
func (BindingArray) ToBindingArrayOutputWithContext ¶
func (i BindingArray) ToBindingArrayOutputWithContext(ctx context.Context) BindingArrayOutput
type BindingArrayInput ¶
type BindingArrayInput interface { pulumi.Input ToBindingArrayOutput() BindingArrayOutput ToBindingArrayOutputWithContext(context.Context) BindingArrayOutput }
BindingArrayInput is an input type that accepts BindingArray and BindingArrayOutput values. You can construct a concrete instance of `BindingArrayInput` via:
BindingArray{ BindingArgs{...} }
type BindingArrayOutput ¶
type BindingArrayOutput struct{ *pulumi.OutputState }
func (BindingArrayOutput) ElementType ¶
func (BindingArrayOutput) ElementType() reflect.Type
func (BindingArrayOutput) Index ¶
func (o BindingArrayOutput) Index(i pulumi.IntInput) BindingOutput
func (BindingArrayOutput) ToBindingArrayOutput ¶
func (o BindingArrayOutput) ToBindingArrayOutput() BindingArrayOutput
func (BindingArrayOutput) ToBindingArrayOutputWithContext ¶
func (o BindingArrayOutput) ToBindingArrayOutputWithContext(ctx context.Context) BindingArrayOutput
type BindingInput ¶
type BindingInput interface { pulumi.Input ToBindingOutput() BindingOutput ToBindingOutputWithContext(context.Context) BindingOutput }
BindingInput is an input type that accepts BindingArgs and BindingOutput values. You can construct a concrete instance of `BindingInput` via:
BindingArgs{...}
type BindingOutput ¶
type BindingOutput struct{ *pulumi.OutputState }
Associates `members`, or principals, with a `role`.
func (BindingOutput) Condition ¶
func (o BindingOutput) Condition() ExprPtrOutput
The condition that is associated with this binding. If the condition evaluates to `true`, then this binding applies to the current request. If the condition evaluates to `false`, then this binding does not apply to the current request. However, a different role binding might grant the same role to one or more of the principals in this binding. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).
func (BindingOutput) ElementType ¶
func (BindingOutput) ElementType() reflect.Type
func (BindingOutput) Members ¶
func (o BindingOutput) Members() pulumi.StringArrayOutput
Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding.
func (BindingOutput) Role ¶
func (o BindingOutput) Role() pulumi.StringPtrOutput
Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`.
func (BindingOutput) ToBindingOutput ¶
func (o BindingOutput) ToBindingOutput() BindingOutput
func (BindingOutput) ToBindingOutputWithContext ¶
func (o BindingOutput) ToBindingOutputWithContext(ctx context.Context) BindingOutput
type BindingResponse ¶
type BindingResponse struct { // The condition that is associated with this binding. If the condition evaluates to `true`, then this binding applies to the current request. If the condition evaluates to `false`, then this binding does not apply to the current request. However, a different role binding might grant the same role to one or more of the principals in this binding. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies). Condition ExprResponse `pulumi:"condition"` // Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding. Members []string `pulumi:"members"` // Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`. Role string `pulumi:"role"` }
Associates `members`, or principals, with a `role`.
type BindingResponseArrayOutput ¶
type BindingResponseArrayOutput struct{ *pulumi.OutputState }
func (BindingResponseArrayOutput) ElementType ¶
func (BindingResponseArrayOutput) ElementType() reflect.Type
func (BindingResponseArrayOutput) Index ¶
func (o BindingResponseArrayOutput) Index(i pulumi.IntInput) BindingResponseOutput
func (BindingResponseArrayOutput) ToBindingResponseArrayOutput ¶
func (o BindingResponseArrayOutput) ToBindingResponseArrayOutput() BindingResponseArrayOutput
func (BindingResponseArrayOutput) ToBindingResponseArrayOutputWithContext ¶
func (o BindingResponseArrayOutput) ToBindingResponseArrayOutputWithContext(ctx context.Context) BindingResponseArrayOutput
type BindingResponseOutput ¶
type BindingResponseOutput struct{ *pulumi.OutputState }
Associates `members`, or principals, with a `role`.
func (BindingResponseOutput) Condition ¶
func (o BindingResponseOutput) Condition() ExprResponseOutput
The condition that is associated with this binding. If the condition evaluates to `true`, then this binding applies to the current request. If the condition evaluates to `false`, then this binding does not apply to the current request. However, a different role binding might grant the same role to one or more of the principals in this binding. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).
func (BindingResponseOutput) ElementType ¶
func (BindingResponseOutput) ElementType() reflect.Type
func (BindingResponseOutput) Members ¶
func (o BindingResponseOutput) Members() pulumi.StringArrayOutput
Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding.
func (BindingResponseOutput) Role ¶
func (o BindingResponseOutput) Role() pulumi.StringOutput
Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`.
func (BindingResponseOutput) ToBindingResponseOutput ¶
func (o BindingResponseOutput) ToBindingResponseOutput() BindingResponseOutput
func (BindingResponseOutput) ToBindingResponseOutputWithContext ¶
func (o BindingResponseOutput) ToBindingResponseOutputWithContext(ctx context.Context) BindingResponseOutput
type Brand ¶
type Brand struct { pulumi.CustomResourceState // Application name displayed on OAuth consent screen. ApplicationTitle pulumi.StringOutput `pulumi:"applicationTitle"` // Identifier of the brand. NOTE: GCP project number achieves the same brand identification purpose as only one brand per project can be created. Name pulumi.StringOutput `pulumi:"name"` // Whether the brand is only intended for usage inside the G Suite organization only. OrgInternalOnly pulumi.BoolOutput `pulumi:"orgInternalOnly"` Project pulumi.StringOutput `pulumi:"project"` // Support email displayed on the OAuth consent screen. SupportEmail pulumi.StringOutput `pulumi:"supportEmail"` }
Constructs a new OAuth brand for the project if one does not exist. The created brand is "internal only", meaning that OAuth clients created under it only accept requests from users who belong to the same Google Workspace organization as the project. The brand is created in an un-reviewed status. NOTE: The "internal only" status can be manually changed in the Google Cloud Console. Requires that a brand does not already exist for the project, and that the specified support email is owned by the caller. Auto-naming is currently not supported for this resource. Note - this resource's API doesn't support deletion. When deleted, the resource will persist on Google Cloud even though it will be deleted from Pulumi state.
func GetBrand ¶
func GetBrand(ctx *pulumi.Context, name string, id pulumi.IDInput, state *BrandState, opts ...pulumi.ResourceOption) (*Brand, error)
GetBrand gets an existing Brand resource's state with the given name, ID, and optional state properties that are used to uniquely qualify the lookup (nil if not required).
func NewBrand ¶
func NewBrand(ctx *pulumi.Context, name string, args *BrandArgs, opts ...pulumi.ResourceOption) (*Brand, error)
NewBrand registers a new resource with the given unique name, arguments, and options.
func (*Brand) ElementType ¶
func (*Brand) ToBrandOutput ¶
func (i *Brand) ToBrandOutput() BrandOutput
func (*Brand) ToBrandOutputWithContext ¶
func (i *Brand) ToBrandOutputWithContext(ctx context.Context) BrandOutput
type BrandArgs ¶
type BrandArgs struct { // Application name displayed on OAuth consent screen. ApplicationTitle pulumi.StringPtrInput Project pulumi.StringPtrInput // Support email displayed on the OAuth consent screen. SupportEmail pulumi.StringPtrInput }
The set of arguments for constructing a Brand resource.
func (BrandArgs) ElementType ¶
type BrandInput ¶
type BrandInput interface { pulumi.Input ToBrandOutput() BrandOutput ToBrandOutputWithContext(ctx context.Context) BrandOutput }
type BrandOutput ¶
type BrandOutput struct{ *pulumi.OutputState }
func (BrandOutput) ApplicationTitle ¶ added in v0.19.0
func (o BrandOutput) ApplicationTitle() pulumi.StringOutput
Application name displayed on OAuth consent screen.
func (BrandOutput) ElementType ¶
func (BrandOutput) ElementType() reflect.Type
func (BrandOutput) Name ¶ added in v0.19.0
func (o BrandOutput) Name() pulumi.StringOutput
Identifier of the brand. NOTE: GCP project number achieves the same brand identification purpose as only one brand per project can be created.
func (BrandOutput) OrgInternalOnly ¶ added in v0.19.0
func (o BrandOutput) OrgInternalOnly() pulumi.BoolOutput
Whether the brand is only intended for usage inside the G Suite organization only.
func (BrandOutput) Project ¶ added in v0.21.0
func (o BrandOutput) Project() pulumi.StringOutput
func (BrandOutput) SupportEmail ¶ added in v0.19.0
func (o BrandOutput) SupportEmail() pulumi.StringOutput
Support email displayed on the OAuth consent screen.
func (BrandOutput) ToBrandOutput ¶
func (o BrandOutput) ToBrandOutput() BrandOutput
func (BrandOutput) ToBrandOutputWithContext ¶
func (o BrandOutput) ToBrandOutputWithContext(ctx context.Context) BrandOutput
type BrandState ¶
type BrandState struct { }
func (BrandState) ElementType ¶
func (BrandState) ElementType() reflect.Type
type DestGroup ¶ added in v0.18.0
type DestGroup struct { pulumi.CustomResourceState // Unordered list. List of CIDRs that this group applies to. Cidrs pulumi.StringArrayOutput `pulumi:"cidrs"` // Unordered list. List of FQDNs that this group applies to. Fqdns pulumi.StringArrayOutput `pulumi:"fqdns"` Location pulumi.StringOutput `pulumi:"location"` // Immutable. Identifier for the TunnelDestGroup. Must be unique within the project and contain only lower case letters (a-z) and dashes (-). Name pulumi.StringOutput `pulumi:"name"` Project pulumi.StringOutput `pulumi:"project"` // Required. The ID to use for the TunnelDestGroup, which becomes the final component of the resource name. This value must be 4-63 characters, and valid characters are `[a-z]-`. TunnelDestGroupId pulumi.StringOutput `pulumi:"tunnelDestGroupId"` }
Creates a new TunnelDestGroup.
func GetDestGroup ¶ added in v0.18.0
func GetDestGroup(ctx *pulumi.Context, name string, id pulumi.IDInput, state *DestGroupState, opts ...pulumi.ResourceOption) (*DestGroup, error)
GetDestGroup gets an existing DestGroup resource's state with the given name, ID, and optional state properties that are used to uniquely qualify the lookup (nil if not required).
func NewDestGroup ¶ added in v0.18.0
func NewDestGroup(ctx *pulumi.Context, name string, args *DestGroupArgs, opts ...pulumi.ResourceOption) (*DestGroup, error)
NewDestGroup registers a new resource with the given unique name, arguments, and options.
func (*DestGroup) ElementType ¶ added in v0.18.0
func (*DestGroup) ToDestGroupOutput ¶ added in v0.18.0
func (i *DestGroup) ToDestGroupOutput() DestGroupOutput
func (*DestGroup) ToDestGroupOutputWithContext ¶ added in v0.18.0
func (i *DestGroup) ToDestGroupOutputWithContext(ctx context.Context) DestGroupOutput
type DestGroupArgs ¶ added in v0.18.0
type DestGroupArgs struct { // Unordered list. List of CIDRs that this group applies to. Cidrs pulumi.StringArrayInput // Unordered list. List of FQDNs that this group applies to. Fqdns pulumi.StringArrayInput Location pulumi.StringPtrInput // Immutable. Identifier for the TunnelDestGroup. Must be unique within the project and contain only lower case letters (a-z) and dashes (-). Name pulumi.StringPtrInput Project pulumi.StringPtrInput // Required. The ID to use for the TunnelDestGroup, which becomes the final component of the resource name. This value must be 4-63 characters, and valid characters are `[a-z]-`. TunnelDestGroupId pulumi.StringInput }
The set of arguments for constructing a DestGroup resource.
func (DestGroupArgs) ElementType ¶ added in v0.18.0
func (DestGroupArgs) ElementType() reflect.Type
type DestGroupInput ¶ added in v0.18.0
type DestGroupInput interface { pulumi.Input ToDestGroupOutput() DestGroupOutput ToDestGroupOutputWithContext(ctx context.Context) DestGroupOutput }
type DestGroupOutput ¶ added in v0.18.0
type DestGroupOutput struct{ *pulumi.OutputState }
func (DestGroupOutput) Cidrs ¶ added in v0.19.0
func (o DestGroupOutput) Cidrs() pulumi.StringArrayOutput
Unordered list. List of CIDRs that this group applies to.
func (DestGroupOutput) ElementType ¶ added in v0.18.0
func (DestGroupOutput) ElementType() reflect.Type
func (DestGroupOutput) Fqdns ¶ added in v0.19.0
func (o DestGroupOutput) Fqdns() pulumi.StringArrayOutput
Unordered list. List of FQDNs that this group applies to.
func (DestGroupOutput) Location ¶ added in v0.21.0
func (o DestGroupOutput) Location() pulumi.StringOutput
func (DestGroupOutput) Name ¶ added in v0.19.0
func (o DestGroupOutput) Name() pulumi.StringOutput
Immutable. Identifier for the TunnelDestGroup. Must be unique within the project and contain only lower case letters (a-z) and dashes (-).
func (DestGroupOutput) Project ¶ added in v0.21.0
func (o DestGroupOutput) Project() pulumi.StringOutput
func (DestGroupOutput) ToDestGroupOutput ¶ added in v0.18.0
func (o DestGroupOutput) ToDestGroupOutput() DestGroupOutput
func (DestGroupOutput) ToDestGroupOutputWithContext ¶ added in v0.18.0
func (o DestGroupOutput) ToDestGroupOutputWithContext(ctx context.Context) DestGroupOutput
func (DestGroupOutput) TunnelDestGroupId ¶ added in v0.21.0
func (o DestGroupOutput) TunnelDestGroupId() pulumi.StringOutput
Required. The ID to use for the TunnelDestGroup, which becomes the final component of the resource name. This value must be 4-63 characters, and valid characters are `[a-z]-`.
type DestGroupState ¶ added in v0.18.0
type DestGroupState struct { }
func (DestGroupState) ElementType ¶ added in v0.18.0
func (DestGroupState) ElementType() reflect.Type
type Expr ¶
type Expr struct { // Optional. Description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI. Description *string `pulumi:"description"` // Textual representation of an expression in Common Expression Language syntax. Expression *string `pulumi:"expression"` // Optional. String indicating the location of the expression for error reporting, e.g. a file name and a position in the file. Location *string `pulumi:"location"` // Optional. Title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression. Title *string `pulumi:"title"` }
Represents a textual expression in the Common Expression Language (CEL) syntax. CEL is a C-like expression language. The syntax and semantics of CEL are documented at https://github.com/google/cel-spec. Example (Comparison): title: "Summary size limit" description: "Determines if a summary is less than 100 chars" expression: "document.summary.size() < 100" Example (Equality): title: "Requestor is owner" description: "Determines if requestor is the document owner" expression: "document.owner == request.auth.claims.email" Example (Logic): title: "Public documents" description: "Determine whether the document should be publicly visible" expression: "document.type != 'private' && document.type != 'internal'" Example (Data Manipulation): title: "Notification string" description: "Create a notification string with a timestamp." expression: "'New message received at ' + string(document.create_time)" The exact variables and functions that may be referenced within an expression are determined by the service that evaluates it. See the service documentation for additional information.
type ExprArgs ¶
type ExprArgs struct { // Optional. Description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI. Description pulumi.StringPtrInput `pulumi:"description"` // Textual representation of an expression in Common Expression Language syntax. Expression pulumi.StringPtrInput `pulumi:"expression"` // Optional. String indicating the location of the expression for error reporting, e.g. a file name and a position in the file. Location pulumi.StringPtrInput `pulumi:"location"` // Optional. Title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression. Title pulumi.StringPtrInput `pulumi:"title"` }
Represents a textual expression in the Common Expression Language (CEL) syntax. CEL is a C-like expression language. The syntax and semantics of CEL are documented at https://github.com/google/cel-spec. Example (Comparison): title: "Summary size limit" description: "Determines if a summary is less than 100 chars" expression: "document.summary.size() < 100" Example (Equality): title: "Requestor is owner" description: "Determines if requestor is the document owner" expression: "document.owner == request.auth.claims.email" Example (Logic): title: "Public documents" description: "Determine whether the document should be publicly visible" expression: "document.type != 'private' && document.type != 'internal'" Example (Data Manipulation): title: "Notification string" description: "Create a notification string with a timestamp." expression: "'New message received at ' + string(document.create_time)" The exact variables and functions that may be referenced within an expression are determined by the service that evaluates it. See the service documentation for additional information.
func (ExprArgs) ElementType ¶
func (ExprArgs) ToExprOutput ¶
func (i ExprArgs) ToExprOutput() ExprOutput
func (ExprArgs) ToExprOutputWithContext ¶
func (i ExprArgs) ToExprOutputWithContext(ctx context.Context) ExprOutput
func (ExprArgs) ToExprPtrOutput ¶
func (i ExprArgs) ToExprPtrOutput() ExprPtrOutput
func (ExprArgs) ToExprPtrOutputWithContext ¶
func (i ExprArgs) ToExprPtrOutputWithContext(ctx context.Context) ExprPtrOutput
type ExprInput ¶
type ExprInput interface { pulumi.Input ToExprOutput() ExprOutput ToExprOutputWithContext(context.Context) ExprOutput }
ExprInput is an input type that accepts ExprArgs and ExprOutput values. You can construct a concrete instance of `ExprInput` via:
ExprArgs{...}
type ExprOutput ¶
type ExprOutput struct{ *pulumi.OutputState }
Represents a textual expression in the Common Expression Language (CEL) syntax. CEL is a C-like expression language. The syntax and semantics of CEL are documented at https://github.com/google/cel-spec. Example (Comparison): title: "Summary size limit" description: "Determines if a summary is less than 100 chars" expression: "document.summary.size() < 100" Example (Equality): title: "Requestor is owner" description: "Determines if requestor is the document owner" expression: "document.owner == request.auth.claims.email" Example (Logic): title: "Public documents" description: "Determine whether the document should be publicly visible" expression: "document.type != 'private' && document.type != 'internal'" Example (Data Manipulation): title: "Notification string" description: "Create a notification string with a timestamp." expression: "'New message received at ' + string(document.create_time)" The exact variables and functions that may be referenced within an expression are determined by the service that evaluates it. See the service documentation for additional information.
func (ExprOutput) Description ¶
func (o ExprOutput) Description() pulumi.StringPtrOutput
Optional. Description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI.
func (ExprOutput) ElementType ¶
func (ExprOutput) ElementType() reflect.Type
func (ExprOutput) Expression ¶
func (o ExprOutput) Expression() pulumi.StringPtrOutput
Textual representation of an expression in Common Expression Language syntax.
func (ExprOutput) Location ¶
func (o ExprOutput) Location() pulumi.StringPtrOutput
Optional. String indicating the location of the expression for error reporting, e.g. a file name and a position in the file.
func (ExprOutput) Title ¶
func (o ExprOutput) Title() pulumi.StringPtrOutput
Optional. Title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression.
func (ExprOutput) ToExprOutput ¶
func (o ExprOutput) ToExprOutput() ExprOutput
func (ExprOutput) ToExprOutputWithContext ¶
func (o ExprOutput) ToExprOutputWithContext(ctx context.Context) ExprOutput
func (ExprOutput) ToExprPtrOutput ¶
func (o ExprOutput) ToExprPtrOutput() ExprPtrOutput
func (ExprOutput) ToExprPtrOutputWithContext ¶
func (o ExprOutput) ToExprPtrOutputWithContext(ctx context.Context) ExprPtrOutput
type ExprPtrInput ¶
type ExprPtrInput interface { pulumi.Input ToExprPtrOutput() ExprPtrOutput ToExprPtrOutputWithContext(context.Context) ExprPtrOutput }
ExprPtrInput is an input type that accepts ExprArgs, ExprPtr and ExprPtrOutput values. You can construct a concrete instance of `ExprPtrInput` via:
ExprArgs{...} or: nil
func ExprPtr ¶
func ExprPtr(v *ExprArgs) ExprPtrInput
type ExprPtrOutput ¶
type ExprPtrOutput struct{ *pulumi.OutputState }
func (ExprPtrOutput) Description ¶
func (o ExprPtrOutput) Description() pulumi.StringPtrOutput
Optional. Description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI.
func (ExprPtrOutput) Elem ¶
func (o ExprPtrOutput) Elem() ExprOutput
func (ExprPtrOutput) ElementType ¶
func (ExprPtrOutput) ElementType() reflect.Type
func (ExprPtrOutput) Expression ¶
func (o ExprPtrOutput) Expression() pulumi.StringPtrOutput
Textual representation of an expression in Common Expression Language syntax.
func (ExprPtrOutput) Location ¶
func (o ExprPtrOutput) Location() pulumi.StringPtrOutput
Optional. String indicating the location of the expression for error reporting, e.g. a file name and a position in the file.
func (ExprPtrOutput) Title ¶
func (o ExprPtrOutput) Title() pulumi.StringPtrOutput
Optional. Title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression.
func (ExprPtrOutput) ToExprPtrOutput ¶
func (o ExprPtrOutput) ToExprPtrOutput() ExprPtrOutput
func (ExprPtrOutput) ToExprPtrOutputWithContext ¶
func (o ExprPtrOutput) ToExprPtrOutputWithContext(ctx context.Context) ExprPtrOutput
type ExprResponse ¶
type ExprResponse struct { // Optional. Description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI. Description string `pulumi:"description"` // Textual representation of an expression in Common Expression Language syntax. Expression string `pulumi:"expression"` // Optional. String indicating the location of the expression for error reporting, e.g. a file name and a position in the file. Location string `pulumi:"location"` // Optional. Title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression. Title string `pulumi:"title"` }
Represents a textual expression in the Common Expression Language (CEL) syntax. CEL is a C-like expression language. The syntax and semantics of CEL are documented at https://github.com/google/cel-spec. Example (Comparison): title: "Summary size limit" description: "Determines if a summary is less than 100 chars" expression: "document.summary.size() < 100" Example (Equality): title: "Requestor is owner" description: "Determines if requestor is the document owner" expression: "document.owner == request.auth.claims.email" Example (Logic): title: "Public documents" description: "Determine whether the document should be publicly visible" expression: "document.type != 'private' && document.type != 'internal'" Example (Data Manipulation): title: "Notification string" description: "Create a notification string with a timestamp." expression: "'New message received at ' + string(document.create_time)" The exact variables and functions that may be referenced within an expression are determined by the service that evaluates it. See the service documentation for additional information.
type ExprResponseOutput ¶
type ExprResponseOutput struct{ *pulumi.OutputState }
Represents a textual expression in the Common Expression Language (CEL) syntax. CEL is a C-like expression language. The syntax and semantics of CEL are documented at https://github.com/google/cel-spec. Example (Comparison): title: "Summary size limit" description: "Determines if a summary is less than 100 chars" expression: "document.summary.size() < 100" Example (Equality): title: "Requestor is owner" description: "Determines if requestor is the document owner" expression: "document.owner == request.auth.claims.email" Example (Logic): title: "Public documents" description: "Determine whether the document should be publicly visible" expression: "document.type != 'private' && document.type != 'internal'" Example (Data Manipulation): title: "Notification string" description: "Create a notification string with a timestamp." expression: "'New message received at ' + string(document.create_time)" The exact variables and functions that may be referenced within an expression are determined by the service that evaluates it. See the service documentation for additional information.
func (ExprResponseOutput) Description ¶
func (o ExprResponseOutput) Description() pulumi.StringOutput
Optional. Description of the expression. This is a longer text which describes the expression, e.g. when hovered over it in a UI.
func (ExprResponseOutput) ElementType ¶
func (ExprResponseOutput) ElementType() reflect.Type
func (ExprResponseOutput) Expression ¶
func (o ExprResponseOutput) Expression() pulumi.StringOutput
Textual representation of an expression in Common Expression Language syntax.
func (ExprResponseOutput) Location ¶
func (o ExprResponseOutput) Location() pulumi.StringOutput
Optional. String indicating the location of the expression for error reporting, e.g. a file name and a position in the file.
func (ExprResponseOutput) Title ¶
func (o ExprResponseOutput) Title() pulumi.StringOutput
Optional. Title for the expression, i.e. a short string describing its purpose. This can be used e.g. in UIs which allow to enter the expression.
func (ExprResponseOutput) ToExprResponseOutput ¶
func (o ExprResponseOutput) ToExprResponseOutput() ExprResponseOutput
func (ExprResponseOutput) ToExprResponseOutputWithContext ¶
func (o ExprResponseOutput) ToExprResponseOutputWithContext(ctx context.Context) ExprResponseOutput
type IdentityAwareProxyClient ¶ added in v0.3.0
type IdentityAwareProxyClient struct { pulumi.CustomResourceState BrandId pulumi.StringOutput `pulumi:"brandId"` // Human-friendly name given to the OAuth client. DisplayName pulumi.StringOutput `pulumi:"displayName"` // Unique identifier of the OAuth client. Name pulumi.StringOutput `pulumi:"name"` Project pulumi.StringOutput `pulumi:"project"` // Client secret of the OAuth client. Secret pulumi.StringOutput `pulumi:"secret"` }
Creates an Identity Aware Proxy (IAP) OAuth client. The client is owned by IAP. Requires that the brand for the project exists and that it is set for internal-only use. Auto-naming is currently not supported for this resource.
func GetIdentityAwareProxyClient ¶ added in v0.3.0
func GetIdentityAwareProxyClient(ctx *pulumi.Context, name string, id pulumi.IDInput, state *IdentityAwareProxyClientState, opts ...pulumi.ResourceOption) (*IdentityAwareProxyClient, error)
GetIdentityAwareProxyClient gets an existing IdentityAwareProxyClient resource's state with the given name, ID, and optional state properties that are used to uniquely qualify the lookup (nil if not required).
func NewIdentityAwareProxyClient ¶ added in v0.3.0
func NewIdentityAwareProxyClient(ctx *pulumi.Context, name string, args *IdentityAwareProxyClientArgs, opts ...pulumi.ResourceOption) (*IdentityAwareProxyClient, error)
NewIdentityAwareProxyClient registers a new resource with the given unique name, arguments, and options.
func (*IdentityAwareProxyClient) ElementType ¶ added in v0.3.0
func (*IdentityAwareProxyClient) ElementType() reflect.Type
func (*IdentityAwareProxyClient) ToIdentityAwareProxyClientOutput ¶ added in v0.3.0
func (i *IdentityAwareProxyClient) ToIdentityAwareProxyClientOutput() IdentityAwareProxyClientOutput
func (*IdentityAwareProxyClient) ToIdentityAwareProxyClientOutputWithContext ¶ added in v0.3.0
func (i *IdentityAwareProxyClient) ToIdentityAwareProxyClientOutputWithContext(ctx context.Context) IdentityAwareProxyClientOutput
type IdentityAwareProxyClientArgs ¶ added in v0.3.0
type IdentityAwareProxyClientArgs struct { BrandId pulumi.StringInput // Human-friendly name given to the OAuth client. DisplayName pulumi.StringPtrInput Project pulumi.StringPtrInput }
The set of arguments for constructing a IdentityAwareProxyClient resource.
func (IdentityAwareProxyClientArgs) ElementType ¶ added in v0.3.0
func (IdentityAwareProxyClientArgs) ElementType() reflect.Type
type IdentityAwareProxyClientInput ¶ added in v0.3.0
type IdentityAwareProxyClientInput interface { pulumi.Input ToIdentityAwareProxyClientOutput() IdentityAwareProxyClientOutput ToIdentityAwareProxyClientOutputWithContext(ctx context.Context) IdentityAwareProxyClientOutput }
type IdentityAwareProxyClientOutput ¶ added in v0.3.0
type IdentityAwareProxyClientOutput struct{ *pulumi.OutputState }
func (IdentityAwareProxyClientOutput) BrandId ¶ added in v0.21.0
func (o IdentityAwareProxyClientOutput) BrandId() pulumi.StringOutput
func (IdentityAwareProxyClientOutput) DisplayName ¶ added in v0.19.0
func (o IdentityAwareProxyClientOutput) DisplayName() pulumi.StringOutput
Human-friendly name given to the OAuth client.
func (IdentityAwareProxyClientOutput) ElementType ¶ added in v0.3.0
func (IdentityAwareProxyClientOutput) ElementType() reflect.Type
func (IdentityAwareProxyClientOutput) Name ¶ added in v0.19.0
func (o IdentityAwareProxyClientOutput) Name() pulumi.StringOutput
Unique identifier of the OAuth client.
func (IdentityAwareProxyClientOutput) Project ¶ added in v0.21.0
func (o IdentityAwareProxyClientOutput) Project() pulumi.StringOutput
func (IdentityAwareProxyClientOutput) Secret ¶ added in v0.19.0
func (o IdentityAwareProxyClientOutput) Secret() pulumi.StringOutput
Client secret of the OAuth client.
func (IdentityAwareProxyClientOutput) ToIdentityAwareProxyClientOutput ¶ added in v0.3.0
func (o IdentityAwareProxyClientOutput) ToIdentityAwareProxyClientOutput() IdentityAwareProxyClientOutput
func (IdentityAwareProxyClientOutput) ToIdentityAwareProxyClientOutputWithContext ¶ added in v0.3.0
func (o IdentityAwareProxyClientOutput) ToIdentityAwareProxyClientOutputWithContext(ctx context.Context) IdentityAwareProxyClientOutput
type IdentityAwareProxyClientState ¶ added in v0.3.0
type IdentityAwareProxyClientState struct { }
func (IdentityAwareProxyClientState) ElementType ¶ added in v0.3.0
func (IdentityAwareProxyClientState) ElementType() reflect.Type
type LookupBrandArgs ¶ added in v0.4.0
type LookupBrandOutputArgs ¶ added in v0.8.0
type LookupBrandOutputArgs struct { BrandId pulumi.StringInput `pulumi:"brandId"` Project pulumi.StringPtrInput `pulumi:"project"` }
func (LookupBrandOutputArgs) ElementType ¶ added in v0.8.0
func (LookupBrandOutputArgs) ElementType() reflect.Type
type LookupBrandResult ¶ added in v0.4.0
type LookupBrandResult struct { // Application name displayed on OAuth consent screen. ApplicationTitle string `pulumi:"applicationTitle"` // Identifier of the brand. NOTE: GCP project number achieves the same brand identification purpose as only one brand per project can be created. Name string `pulumi:"name"` // Whether the brand is only intended for usage inside the G Suite organization only. OrgInternalOnly bool `pulumi:"orgInternalOnly"` // Support email displayed on the OAuth consent screen. SupportEmail string `pulumi:"supportEmail"` }
func LookupBrand ¶ added in v0.4.0
func LookupBrand(ctx *pulumi.Context, args *LookupBrandArgs, opts ...pulumi.InvokeOption) (*LookupBrandResult, error)
Retrieves the OAuth brand of the project.
type LookupBrandResultOutput ¶ added in v0.8.0
type LookupBrandResultOutput struct{ *pulumi.OutputState }
func LookupBrandOutput ¶ added in v0.8.0
func LookupBrandOutput(ctx *pulumi.Context, args LookupBrandOutputArgs, opts ...pulumi.InvokeOption) LookupBrandResultOutput
func (LookupBrandResultOutput) ApplicationTitle ¶ added in v0.8.0
func (o LookupBrandResultOutput) ApplicationTitle() pulumi.StringOutput
Application name displayed on OAuth consent screen.
func (LookupBrandResultOutput) ElementType ¶ added in v0.8.0
func (LookupBrandResultOutput) ElementType() reflect.Type
func (LookupBrandResultOutput) Name ¶ added in v0.8.0
func (o LookupBrandResultOutput) Name() pulumi.StringOutput
Identifier of the brand. NOTE: GCP project number achieves the same brand identification purpose as only one brand per project can be created.
func (LookupBrandResultOutput) OrgInternalOnly ¶ added in v0.8.0
func (o LookupBrandResultOutput) OrgInternalOnly() pulumi.BoolOutput
Whether the brand is only intended for usage inside the G Suite organization only.
func (LookupBrandResultOutput) SupportEmail ¶ added in v0.8.0
func (o LookupBrandResultOutput) SupportEmail() pulumi.StringOutput
Support email displayed on the OAuth consent screen.
func (LookupBrandResultOutput) ToLookupBrandResultOutput ¶ added in v0.8.0
func (o LookupBrandResultOutput) ToLookupBrandResultOutput() LookupBrandResultOutput
func (LookupBrandResultOutput) ToLookupBrandResultOutputWithContext ¶ added in v0.8.0
func (o LookupBrandResultOutput) ToLookupBrandResultOutputWithContext(ctx context.Context) LookupBrandResultOutput
type LookupDestGroupArgs ¶ added in v0.18.0
type LookupDestGroupOutputArgs ¶ added in v0.18.0
type LookupDestGroupOutputArgs struct { DestGroupId pulumi.StringInput `pulumi:"destGroupId"` Location pulumi.StringInput `pulumi:"location"` Project pulumi.StringPtrInput `pulumi:"project"` }
func (LookupDestGroupOutputArgs) ElementType ¶ added in v0.18.0
func (LookupDestGroupOutputArgs) ElementType() reflect.Type
type LookupDestGroupResult ¶ added in v0.18.0
type LookupDestGroupResult struct { // Unordered list. List of CIDRs that this group applies to. Cidrs []string `pulumi:"cidrs"` // Unordered list. List of FQDNs that this group applies to. Fqdns []string `pulumi:"fqdns"` // Immutable. Identifier for the TunnelDestGroup. Must be unique within the project and contain only lower case letters (a-z) and dashes (-). Name string `pulumi:"name"` }
func LookupDestGroup ¶ added in v0.18.0
func LookupDestGroup(ctx *pulumi.Context, args *LookupDestGroupArgs, opts ...pulumi.InvokeOption) (*LookupDestGroupResult, error)
Retrieves an existing TunnelDestGroup.
type LookupDestGroupResultOutput ¶ added in v0.18.0
type LookupDestGroupResultOutput struct{ *pulumi.OutputState }
func LookupDestGroupOutput ¶ added in v0.18.0
func LookupDestGroupOutput(ctx *pulumi.Context, args LookupDestGroupOutputArgs, opts ...pulumi.InvokeOption) LookupDestGroupResultOutput
func (LookupDestGroupResultOutput) Cidrs ¶ added in v0.18.0
func (o LookupDestGroupResultOutput) Cidrs() pulumi.StringArrayOutput
Unordered list. List of CIDRs that this group applies to.
func (LookupDestGroupResultOutput) ElementType ¶ added in v0.18.0
func (LookupDestGroupResultOutput) ElementType() reflect.Type
func (LookupDestGroupResultOutput) Fqdns ¶ added in v0.18.0
func (o LookupDestGroupResultOutput) Fqdns() pulumi.StringArrayOutput
Unordered list. List of FQDNs that this group applies to.
func (LookupDestGroupResultOutput) Name ¶ added in v0.18.0
func (o LookupDestGroupResultOutput) Name() pulumi.StringOutput
Immutable. Identifier for the TunnelDestGroup. Must be unique within the project and contain only lower case letters (a-z) and dashes (-).
func (LookupDestGroupResultOutput) ToLookupDestGroupResultOutput ¶ added in v0.18.0
func (o LookupDestGroupResultOutput) ToLookupDestGroupResultOutput() LookupDestGroupResultOutput
func (LookupDestGroupResultOutput) ToLookupDestGroupResultOutputWithContext ¶ added in v0.18.0
func (o LookupDestGroupResultOutput) ToLookupDestGroupResultOutputWithContext(ctx context.Context) LookupDestGroupResultOutput
type LookupIdentityAwareProxyClientArgs ¶ added in v0.4.0
type LookupIdentityAwareProxyClientOutputArgs ¶ added in v0.8.0
type LookupIdentityAwareProxyClientOutputArgs struct { BrandId pulumi.StringInput `pulumi:"brandId"` IdentityAwareProxyClientId pulumi.StringInput `pulumi:"identityAwareProxyClientId"` Project pulumi.StringPtrInput `pulumi:"project"` }
func (LookupIdentityAwareProxyClientOutputArgs) ElementType ¶ added in v0.8.0
func (LookupIdentityAwareProxyClientOutputArgs) ElementType() reflect.Type
type LookupIdentityAwareProxyClientResult ¶ added in v0.4.0
type LookupIdentityAwareProxyClientResult struct { // Human-friendly name given to the OAuth client. DisplayName string `pulumi:"displayName"` // Unique identifier of the OAuth client. Name string `pulumi:"name"` // Client secret of the OAuth client. Secret string `pulumi:"secret"` }
func LookupIdentityAwareProxyClient ¶ added in v0.4.0
func LookupIdentityAwareProxyClient(ctx *pulumi.Context, args *LookupIdentityAwareProxyClientArgs, opts ...pulumi.InvokeOption) (*LookupIdentityAwareProxyClientResult, error)
Retrieves an Identity Aware Proxy (IAP) OAuth client. Requires that the client is owned by IAP.
type LookupIdentityAwareProxyClientResultOutput ¶ added in v0.8.0
type LookupIdentityAwareProxyClientResultOutput struct{ *pulumi.OutputState }
func LookupIdentityAwareProxyClientOutput ¶ added in v0.8.0
func LookupIdentityAwareProxyClientOutput(ctx *pulumi.Context, args LookupIdentityAwareProxyClientOutputArgs, opts ...pulumi.InvokeOption) LookupIdentityAwareProxyClientResultOutput
func (LookupIdentityAwareProxyClientResultOutput) DisplayName ¶ added in v0.8.0
func (o LookupIdentityAwareProxyClientResultOutput) DisplayName() pulumi.StringOutput
Human-friendly name given to the OAuth client.
func (LookupIdentityAwareProxyClientResultOutput) ElementType ¶ added in v0.8.0
func (LookupIdentityAwareProxyClientResultOutput) ElementType() reflect.Type
func (LookupIdentityAwareProxyClientResultOutput) Name ¶ added in v0.8.0
func (o LookupIdentityAwareProxyClientResultOutput) Name() pulumi.StringOutput
Unique identifier of the OAuth client.
func (LookupIdentityAwareProxyClientResultOutput) Secret ¶ added in v0.8.0
func (o LookupIdentityAwareProxyClientResultOutput) Secret() pulumi.StringOutput
Client secret of the OAuth client.
func (LookupIdentityAwareProxyClientResultOutput) ToLookupIdentityAwareProxyClientResultOutput ¶ added in v0.8.0
func (o LookupIdentityAwareProxyClientResultOutput) ToLookupIdentityAwareProxyClientResultOutput() LookupIdentityAwareProxyClientResultOutput
func (LookupIdentityAwareProxyClientResultOutput) ToLookupIdentityAwareProxyClientResultOutputWithContext ¶ added in v0.8.0
func (o LookupIdentityAwareProxyClientResultOutput) ToLookupIdentityAwareProxyClientResultOutputWithContext(ctx context.Context) LookupIdentityAwareProxyClientResultOutput
type LookupV1IamPolicyArgs ¶ added in v0.4.0
type LookupV1IamPolicyArgs struct {
V1Id string `pulumi:"v1Id"`
}
type LookupV1IamPolicyOutputArgs ¶ added in v0.8.0
type LookupV1IamPolicyOutputArgs struct {
V1Id pulumi.StringInput `pulumi:"v1Id"`
}
func (LookupV1IamPolicyOutputArgs) ElementType ¶ added in v0.8.0
func (LookupV1IamPolicyOutputArgs) ElementType() reflect.Type
type LookupV1IamPolicyResult ¶ added in v0.4.0
type LookupV1IamPolicyResult struct { // Associates a list of `members`, or principals, with a `role`. Optionally, may specify a `condition` that determines how and when the `bindings` are applied. Each of the `bindings` must contain at least one principal. The `bindings` in a `Policy` can refer to up to 1,500 principals; up to 250 of these principals can be Google groups. Each occurrence of a principal counts towards these limits. For example, if the `bindings` grant 50 different roles to `user:alice@example.com`, and not to any other principal, then you can add another 1,450 principals to the `bindings` in the `Policy`. Bindings []BindingResponse `pulumi:"bindings"` // `etag` is used for optimistic concurrency control as a way to help prevent simultaneous updates of a policy from overwriting each other. It is strongly suggested that systems make use of the `etag` in the read-modify-write cycle to perform policy updates in order to avoid race conditions: An `etag` is returned in the response to `getIamPolicy`, and systems are expected to put that etag in the request to `setIamPolicy` to ensure that their change will be applied to the same version of the policy. **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. Etag string `pulumi:"etag"` // Specifies the format of the policy. Valid values are `0`, `1`, and `3`. Requests that specify an invalid value are rejected. Any operation that affects conditional role bindings must specify version `3`. This requirement applies to the following operations: * Getting a policy that includes a conditional role binding * Adding a conditional role binding to a policy * Changing a conditional role binding in a policy * Removing any role binding, with or without a condition, from a policy that includes conditions **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. If a policy does not include any conditions, operations on that policy may specify any valid version or leave the field unset. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies). Version int `pulumi:"version"` }
func LookupV1IamPolicy ¶ added in v0.4.0
func LookupV1IamPolicy(ctx *pulumi.Context, args *LookupV1IamPolicyArgs, opts ...pulumi.InvokeOption) (*LookupV1IamPolicyResult, error)
Gets the access control policy for an Identity-Aware Proxy protected resource. More information about managing access via IAP can be found at: https://cloud.google.com/iap/docs/managing-access#managing_access_via_the_api
type LookupV1IamPolicyResultOutput ¶ added in v0.8.0
type LookupV1IamPolicyResultOutput struct{ *pulumi.OutputState }
func LookupV1IamPolicyOutput ¶ added in v0.8.0
func LookupV1IamPolicyOutput(ctx *pulumi.Context, args LookupV1IamPolicyOutputArgs, opts ...pulumi.InvokeOption) LookupV1IamPolicyResultOutput
func (LookupV1IamPolicyResultOutput) Bindings ¶ added in v0.8.0
func (o LookupV1IamPolicyResultOutput) Bindings() BindingResponseArrayOutput
Associates a list of `members`, or principals, with a `role`. Optionally, may specify a `condition` that determines how and when the `bindings` are applied. Each of the `bindings` must contain at least one principal. The `bindings` in a `Policy` can refer to up to 1,500 principals; up to 250 of these principals can be Google groups. Each occurrence of a principal counts towards these limits. For example, if the `bindings` grant 50 different roles to `user:alice@example.com`, and not to any other principal, then you can add another 1,450 principals to the `bindings` in the `Policy`.
func (LookupV1IamPolicyResultOutput) ElementType ¶ added in v0.8.0
func (LookupV1IamPolicyResultOutput) ElementType() reflect.Type
func (LookupV1IamPolicyResultOutput) Etag ¶ added in v0.8.0
func (o LookupV1IamPolicyResultOutput) Etag() pulumi.StringOutput
`etag` is used for optimistic concurrency control as a way to help prevent simultaneous updates of a policy from overwriting each other. It is strongly suggested that systems make use of the `etag` in the read-modify-write cycle to perform policy updates in order to avoid race conditions: An `etag` is returned in the response to `getIamPolicy`, and systems are expected to put that etag in the request to `setIamPolicy` to ensure that their change will be applied to the same version of the policy. **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost.
func (LookupV1IamPolicyResultOutput) ToLookupV1IamPolicyResultOutput ¶ added in v0.8.0
func (o LookupV1IamPolicyResultOutput) ToLookupV1IamPolicyResultOutput() LookupV1IamPolicyResultOutput
func (LookupV1IamPolicyResultOutput) ToLookupV1IamPolicyResultOutputWithContext ¶ added in v0.8.0
func (o LookupV1IamPolicyResultOutput) ToLookupV1IamPolicyResultOutputWithContext(ctx context.Context) LookupV1IamPolicyResultOutput
func (LookupV1IamPolicyResultOutput) Version ¶ added in v0.8.0
func (o LookupV1IamPolicyResultOutput) Version() pulumi.IntOutput
Specifies the format of the policy. Valid values are `0`, `1`, and `3`. Requests that specify an invalid value are rejected. Any operation that affects conditional role bindings must specify version `3`. This requirement applies to the following operations: * Getting a policy that includes a conditional role binding * Adding a conditional role binding to a policy * Changing a conditional role binding in a policy * Removing any role binding, with or without a condition, from a policy that includes conditions **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. If a policy does not include any conditions, operations on that policy may specify any valid version or leave the field unset. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).
type V1IamBinding ¶ added in v0.26.0
type V1IamBinding struct { pulumi.CustomResourceState // An IAM Condition for a given binding. See https://cloud.google.com/iam/docs/conditions-overview for additional details. Condition iam.ConditionPtrOutput `pulumi:"condition"` // The etag of the resource's IAM policy. Etag pulumi.StringOutput `pulumi:"etag"` // Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding. Members pulumi.StringArrayOutput `pulumi:"members"` // The name of the resource to manage IAM policies for. Name pulumi.StringOutput `pulumi:"name"` // The project in which the resource belongs. If it is not provided, a default will be supplied. Project pulumi.StringOutput `pulumi:"project"` // Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`. Role pulumi.StringOutput `pulumi:"role"` }
Sets the access control policy for an Identity-Aware Proxy protected resource. Replaces any existing policy. More information about managing access via IAP can be found at: https://cloud.google.com/iap/docs/managing-access#managing_access_via_the_api
func GetV1IamBinding ¶ added in v0.26.0
func GetV1IamBinding(ctx *pulumi.Context, name string, id pulumi.IDInput, state *V1IamBindingState, opts ...pulumi.ResourceOption) (*V1IamBinding, error)
GetV1IamBinding gets an existing V1IamBinding resource's state with the given name, ID, and optional state properties that are used to uniquely qualify the lookup (nil if not required).
func NewV1IamBinding ¶ added in v0.26.0
func NewV1IamBinding(ctx *pulumi.Context, name string, args *V1IamBindingArgs, opts ...pulumi.ResourceOption) (*V1IamBinding, error)
NewV1IamBinding registers a new resource with the given unique name, arguments, and options.
func (*V1IamBinding) ElementType ¶ added in v0.26.0
func (*V1IamBinding) ElementType() reflect.Type
func (*V1IamBinding) ToV1IamBindingOutput ¶ added in v0.26.0
func (i *V1IamBinding) ToV1IamBindingOutput() V1IamBindingOutput
func (*V1IamBinding) ToV1IamBindingOutputWithContext ¶ added in v0.26.0
func (i *V1IamBinding) ToV1IamBindingOutputWithContext(ctx context.Context) V1IamBindingOutput
type V1IamBindingArgs ¶ added in v0.26.0
type V1IamBindingArgs struct { // An IAM Condition for a given binding. Condition iam.ConditionPtrInput // Identities that will be granted the privilege in role. Each entry can have one of the following values: // // * user:{emailid}: An email address that represents a specific Google account. For example, alice@gmail.com or joe@example.com. // * serviceAccount:{emailid}: An email address that represents a service account. For example, my-other-app@appspot.gserviceaccount.com. // * group:{emailid}: An email address that represents a Google group. For example, admins@example.com. // * domain:{domain}: A G Suite domain (primary, instead of alias) name that represents all the users of that domain. For example, google.com or example.com. Members pulumi.StringArrayInput // The name of the resource to manage IAM policies for. Name pulumi.StringInput // The role that should be applied. Only one `IamBinding` can be used per role. Role pulumi.StringInput }
The set of arguments for constructing a V1IamBinding resource.
func (V1IamBindingArgs) ElementType ¶ added in v0.26.0
func (V1IamBindingArgs) ElementType() reflect.Type
type V1IamBindingInput ¶ added in v0.26.0
type V1IamBindingInput interface { pulumi.Input ToV1IamBindingOutput() V1IamBindingOutput ToV1IamBindingOutputWithContext(ctx context.Context) V1IamBindingOutput }
type V1IamBindingOutput ¶ added in v0.26.0
type V1IamBindingOutput struct{ *pulumi.OutputState }
func (V1IamBindingOutput) Condition ¶ added in v0.26.0
func (o V1IamBindingOutput) Condition() iam.ConditionPtrOutput
An IAM Condition for a given binding. See https://cloud.google.com/iam/docs/conditions-overview for additional details.
func (V1IamBindingOutput) ElementType ¶ added in v0.26.0
func (V1IamBindingOutput) ElementType() reflect.Type
func (V1IamBindingOutput) Etag ¶ added in v0.26.0
func (o V1IamBindingOutput) Etag() pulumi.StringOutput
The etag of the resource's IAM policy.
func (V1IamBindingOutput) Members ¶ added in v0.26.0
func (o V1IamBindingOutput) Members() pulumi.StringArrayOutput
Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding.
func (V1IamBindingOutput) Name ¶ added in v0.26.0
func (o V1IamBindingOutput) Name() pulumi.StringOutput
The name of the resource to manage IAM policies for.
func (V1IamBindingOutput) Project ¶ added in v0.26.0
func (o V1IamBindingOutput) Project() pulumi.StringOutput
The project in which the resource belongs. If it is not provided, a default will be supplied.
func (V1IamBindingOutput) Role ¶ added in v0.26.0
func (o V1IamBindingOutput) Role() pulumi.StringOutput
Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`.
func (V1IamBindingOutput) ToV1IamBindingOutput ¶ added in v0.26.0
func (o V1IamBindingOutput) ToV1IamBindingOutput() V1IamBindingOutput
func (V1IamBindingOutput) ToV1IamBindingOutputWithContext ¶ added in v0.26.0
func (o V1IamBindingOutput) ToV1IamBindingOutputWithContext(ctx context.Context) V1IamBindingOutput
type V1IamBindingState ¶ added in v0.26.0
type V1IamBindingState struct { }
func (V1IamBindingState) ElementType ¶ added in v0.26.0
func (V1IamBindingState) ElementType() reflect.Type
type V1IamMember ¶ added in v0.26.0
type V1IamMember struct { pulumi.CustomResourceState // An IAM Condition for a given binding. See https://cloud.google.com/iam/docs/conditions-overview for additional details. Condition iam.ConditionPtrOutput `pulumi:"condition"` // The etag of the resource's IAM policy. Etag pulumi.StringOutput `pulumi:"etag"` // Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding. Member pulumi.StringOutput `pulumi:"member"` // The name of the resource to manage IAM policies for. Name pulumi.StringOutput `pulumi:"name"` // The project in which the resource belongs. If it is not provided, a default will be supplied. Project pulumi.StringOutput `pulumi:"project"` // Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`. Role pulumi.StringOutput `pulumi:"role"` }
Sets the access control policy for an Identity-Aware Proxy protected resource. Replaces any existing policy. More information about managing access via IAP can be found at: https://cloud.google.com/iap/docs/managing-access#managing_access_via_the_api
func GetV1IamMember ¶ added in v0.26.0
func GetV1IamMember(ctx *pulumi.Context, name string, id pulumi.IDInput, state *V1IamMemberState, opts ...pulumi.ResourceOption) (*V1IamMember, error)
GetV1IamMember gets an existing V1IamMember resource's state with the given name, ID, and optional state properties that are used to uniquely qualify the lookup (nil if not required).
func NewV1IamMember ¶ added in v0.26.0
func NewV1IamMember(ctx *pulumi.Context, name string, args *V1IamMemberArgs, opts ...pulumi.ResourceOption) (*V1IamMember, error)
NewV1IamMember registers a new resource with the given unique name, arguments, and options.
func (*V1IamMember) ElementType ¶ added in v0.26.0
func (*V1IamMember) ElementType() reflect.Type
func (*V1IamMember) ToV1IamMemberOutput ¶ added in v0.26.0
func (i *V1IamMember) ToV1IamMemberOutput() V1IamMemberOutput
func (*V1IamMember) ToV1IamMemberOutputWithContext ¶ added in v0.26.0
func (i *V1IamMember) ToV1IamMemberOutputWithContext(ctx context.Context) V1IamMemberOutput
type V1IamMemberArgs ¶ added in v0.26.0
type V1IamMemberArgs struct { // An IAM Condition for a given binding. Condition iam.ConditionPtrInput // Identity that will be granted the privilege in role. The entry can have one of the following values: // // * user:{emailid}: An email address that represents a specific Google account. For example, alice@gmail.com or joe@example.com. // * serviceAccount:{emailid}: An email address that represents a service account. For example, my-other-app@appspot.gserviceaccount.com. // * group:{emailid}: An email address that represents a Google group. For example, admins@example.com. // * domain:{domain}: A G Suite domain (primary, instead of alias) name that represents all the users of that domain. For example, google.com or example.com. Member pulumi.StringInput // The name of the resource to manage IAM policies for. Name pulumi.StringInput // The role that should be applied. Role pulumi.StringInput }
The set of arguments for constructing a V1IamMember resource.
func (V1IamMemberArgs) ElementType ¶ added in v0.26.0
func (V1IamMemberArgs) ElementType() reflect.Type
type V1IamMemberInput ¶ added in v0.26.0
type V1IamMemberInput interface { pulumi.Input ToV1IamMemberOutput() V1IamMemberOutput ToV1IamMemberOutputWithContext(ctx context.Context) V1IamMemberOutput }
type V1IamMemberOutput ¶ added in v0.26.0
type V1IamMemberOutput struct{ *pulumi.OutputState }
func (V1IamMemberOutput) Condition ¶ added in v0.26.0
func (o V1IamMemberOutput) Condition() iam.ConditionPtrOutput
An IAM Condition for a given binding. See https://cloud.google.com/iam/docs/conditions-overview for additional details.
func (V1IamMemberOutput) ElementType ¶ added in v0.26.0
func (V1IamMemberOutput) ElementType() reflect.Type
func (V1IamMemberOutput) Etag ¶ added in v0.26.0
func (o V1IamMemberOutput) Etag() pulumi.StringOutput
The etag of the resource's IAM policy.
func (V1IamMemberOutput) Member ¶ added in v0.26.0
func (o V1IamMemberOutput) Member() pulumi.StringOutput
Specifies the principals requesting access for a Google Cloud resource. `members` can have the following values: * `allUsers`: A special identifier that represents anyone who is on the internet; with or without a Google account. * `allAuthenticatedUsers`: A special identifier that represents anyone who is authenticated with a Google account or a service account. Does not include identities that come from external identity providers (IdPs) through identity federation. * `user:{emailid}`: An email address that represents a specific Google account. For example, `alice@example.com` . * `serviceAccount:{emailid}`: An email address that represents a Google service account. For example, `my-other-app@appspot.gserviceaccount.com`. * `serviceAccount:{projectid}.svc.id.goog[{namespace}/{kubernetes-sa}]`: An identifier for a [Kubernetes service account](https://cloud.google.com/kubernetes-engine/docs/how-to/kubernetes-service-accounts). For example, `my-project.svc.id.goog[my-namespace/my-kubernetes-sa]`. * `group:{emailid}`: An email address that represents a Google group. For example, `admins@example.com`. * `domain:{domain}`: The G Suite domain (primary) that represents all the users of that domain. For example, `google.com` or `example.com`. * `deleted:user:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a user that has been recently deleted. For example, `alice@example.com?uid=123456789012345678901`. If the user is recovered, this value reverts to `user:{emailid}` and the recovered user retains the role in the binding. * `deleted:serviceAccount:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a service account that has been recently deleted. For example, `my-other-app@appspot.gserviceaccount.com?uid=123456789012345678901`. If the service account is undeleted, this value reverts to `serviceAccount:{emailid}` and the undeleted service account retains the role in the binding. * `deleted:group:{emailid}?uid={uniqueid}`: An email address (plus unique identifier) representing a Google group that has been recently deleted. For example, `admins@example.com?uid=123456789012345678901`. If the group is recovered, this value reverts to `group:{emailid}` and the recovered group retains the role in the binding.
func (V1IamMemberOutput) Name ¶ added in v0.26.0
func (o V1IamMemberOutput) Name() pulumi.StringOutput
The name of the resource to manage IAM policies for.
func (V1IamMemberOutput) Project ¶ added in v0.26.0
func (o V1IamMemberOutput) Project() pulumi.StringOutput
The project in which the resource belongs. If it is not provided, a default will be supplied.
func (V1IamMemberOutput) Role ¶ added in v0.26.0
func (o V1IamMemberOutput) Role() pulumi.StringOutput
Role that is assigned to the list of `members`, or principals. For example, `roles/viewer`, `roles/editor`, or `roles/owner`.
func (V1IamMemberOutput) ToV1IamMemberOutput ¶ added in v0.26.0
func (o V1IamMemberOutput) ToV1IamMemberOutput() V1IamMemberOutput
func (V1IamMemberOutput) ToV1IamMemberOutputWithContext ¶ added in v0.26.0
func (o V1IamMemberOutput) ToV1IamMemberOutputWithContext(ctx context.Context) V1IamMemberOutput
type V1IamMemberState ¶ added in v0.26.0
type V1IamMemberState struct { }
func (V1IamMemberState) ElementType ¶ added in v0.26.0
func (V1IamMemberState) ElementType() reflect.Type
type V1IamPolicy ¶
type V1IamPolicy struct { pulumi.CustomResourceState // Associates a list of `members`, or principals, with a `role`. Optionally, may specify a `condition` that determines how and when the `bindings` are applied. Each of the `bindings` must contain at least one principal. The `bindings` in a `Policy` can refer to up to 1,500 principals; up to 250 of these principals can be Google groups. Each occurrence of a principal counts towards these limits. For example, if the `bindings` grant 50 different roles to `user:alice@example.com`, and not to any other principal, then you can add another 1,450 principals to the `bindings` in the `Policy`. Bindings BindingResponseArrayOutput `pulumi:"bindings"` // `etag` is used for optimistic concurrency control as a way to help prevent simultaneous updates of a policy from overwriting each other. It is strongly suggested that systems make use of the `etag` in the read-modify-write cycle to perform policy updates in order to avoid race conditions: An `etag` is returned in the response to `getIamPolicy`, and systems are expected to put that etag in the request to `setIamPolicy` to ensure that their change will be applied to the same version of the policy. **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. Etag pulumi.StringOutput `pulumi:"etag"` V1Id pulumi.StringOutput `pulumi:"v1Id"` // Specifies the format of the policy. Valid values are `0`, `1`, and `3`. Requests that specify an invalid value are rejected. Any operation that affects conditional role bindings must specify version `3`. This requirement applies to the following operations: * Getting a policy that includes a conditional role binding * Adding a conditional role binding to a policy * Changing a conditional role binding in a policy * Removing any role binding, with or without a condition, from a policy that includes conditions **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. If a policy does not include any conditions, operations on that policy may specify any valid version or leave the field unset. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies). Version pulumi.IntOutput `pulumi:"version"` }
Sets the access control policy for an Identity-Aware Proxy protected resource. Replaces any existing policy. More information about managing access via IAP can be found at: https://cloud.google.com/iap/docs/managing-access#managing_access_via_the_api Note - this resource's API doesn't support deletion. When deleted, the resource will persist on Google Cloud even though it will be deleted from Pulumi state.
func GetV1IamPolicy ¶
func GetV1IamPolicy(ctx *pulumi.Context, name string, id pulumi.IDInput, state *V1IamPolicyState, opts ...pulumi.ResourceOption) (*V1IamPolicy, error)
GetV1IamPolicy gets an existing V1IamPolicy resource's state with the given name, ID, and optional state properties that are used to uniquely qualify the lookup (nil if not required).
func NewV1IamPolicy ¶
func NewV1IamPolicy(ctx *pulumi.Context, name string, args *V1IamPolicyArgs, opts ...pulumi.ResourceOption) (*V1IamPolicy, error)
NewV1IamPolicy registers a new resource with the given unique name, arguments, and options.
func (*V1IamPolicy) ElementType ¶
func (*V1IamPolicy) ElementType() reflect.Type
func (*V1IamPolicy) ToV1IamPolicyOutput ¶
func (i *V1IamPolicy) ToV1IamPolicyOutput() V1IamPolicyOutput
func (*V1IamPolicy) ToV1IamPolicyOutputWithContext ¶
func (i *V1IamPolicy) ToV1IamPolicyOutputWithContext(ctx context.Context) V1IamPolicyOutput
type V1IamPolicyArgs ¶
type V1IamPolicyArgs struct { // Associates a list of `members`, or principals, with a `role`. Optionally, may specify a `condition` that determines how and when the `bindings` are applied. Each of the `bindings` must contain at least one principal. The `bindings` in a `Policy` can refer to up to 1,500 principals; up to 250 of these principals can be Google groups. Each occurrence of a principal counts towards these limits. For example, if the `bindings` grant 50 different roles to `user:alice@example.com`, and not to any other principal, then you can add another 1,450 principals to the `bindings` in the `Policy`. Bindings BindingArrayInput // `etag` is used for optimistic concurrency control as a way to help prevent simultaneous updates of a policy from overwriting each other. It is strongly suggested that systems make use of the `etag` in the read-modify-write cycle to perform policy updates in order to avoid race conditions: An `etag` is returned in the response to `getIamPolicy`, and systems are expected to put that etag in the request to `setIamPolicy` to ensure that their change will be applied to the same version of the policy. **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. Etag pulumi.StringPtrInput V1Id pulumi.StringInput // Specifies the format of the policy. Valid values are `0`, `1`, and `3`. Requests that specify an invalid value are rejected. Any operation that affects conditional role bindings must specify version `3`. This requirement applies to the following operations: * Getting a policy that includes a conditional role binding * Adding a conditional role binding to a policy * Changing a conditional role binding in a policy * Removing any role binding, with or without a condition, from a policy that includes conditions **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. If a policy does not include any conditions, operations on that policy may specify any valid version or leave the field unset. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies). Version pulumi.IntPtrInput }
The set of arguments for constructing a V1IamPolicy resource.
func (V1IamPolicyArgs) ElementType ¶
func (V1IamPolicyArgs) ElementType() reflect.Type
type V1IamPolicyInput ¶
type V1IamPolicyInput interface { pulumi.Input ToV1IamPolicyOutput() V1IamPolicyOutput ToV1IamPolicyOutputWithContext(ctx context.Context) V1IamPolicyOutput }
type V1IamPolicyOutput ¶
type V1IamPolicyOutput struct{ *pulumi.OutputState }
func (V1IamPolicyOutput) Bindings ¶ added in v0.19.0
func (o V1IamPolicyOutput) Bindings() BindingResponseArrayOutput
Associates a list of `members`, or principals, with a `role`. Optionally, may specify a `condition` that determines how and when the `bindings` are applied. Each of the `bindings` must contain at least one principal. The `bindings` in a `Policy` can refer to up to 1,500 principals; up to 250 of these principals can be Google groups. Each occurrence of a principal counts towards these limits. For example, if the `bindings` grant 50 different roles to `user:alice@example.com`, and not to any other principal, then you can add another 1,450 principals to the `bindings` in the `Policy`.
func (V1IamPolicyOutput) ElementType ¶
func (V1IamPolicyOutput) ElementType() reflect.Type
func (V1IamPolicyOutput) Etag ¶ added in v0.19.0
func (o V1IamPolicyOutput) Etag() pulumi.StringOutput
`etag` is used for optimistic concurrency control as a way to help prevent simultaneous updates of a policy from overwriting each other. It is strongly suggested that systems make use of the `etag` in the read-modify-write cycle to perform policy updates in order to avoid race conditions: An `etag` is returned in the response to `getIamPolicy`, and systems are expected to put that etag in the request to `setIamPolicy` to ensure that their change will be applied to the same version of the policy. **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost.
func (V1IamPolicyOutput) ToV1IamPolicyOutput ¶
func (o V1IamPolicyOutput) ToV1IamPolicyOutput() V1IamPolicyOutput
func (V1IamPolicyOutput) ToV1IamPolicyOutputWithContext ¶
func (o V1IamPolicyOutput) ToV1IamPolicyOutputWithContext(ctx context.Context) V1IamPolicyOutput
func (V1IamPolicyOutput) V1Id ¶ added in v0.21.0
func (o V1IamPolicyOutput) V1Id() pulumi.StringOutput
func (V1IamPolicyOutput) Version ¶ added in v0.19.0
func (o V1IamPolicyOutput) Version() pulumi.IntOutput
Specifies the format of the policy. Valid values are `0`, `1`, and `3`. Requests that specify an invalid value are rejected. Any operation that affects conditional role bindings must specify version `3`. This requirement applies to the following operations: * Getting a policy that includes a conditional role binding * Adding a conditional role binding to a policy * Changing a conditional role binding in a policy * Removing any role binding, with or without a condition, from a policy that includes conditions **Important:** If you use IAM Conditions, you must include the `etag` field whenever you call `setIamPolicy`. If you omit this field, then IAM allows you to overwrite a version `3` policy with a version `1` policy, and all of the conditions in the version `3` policy are lost. If a policy does not include any conditions, operations on that policy may specify any valid version or leave the field unset. To learn which resources support conditions in their IAM policies, see the [IAM documentation](https://cloud.google.com/iam/help/conditions/resource-policies).
type V1IamPolicyState ¶
type V1IamPolicyState struct { }
func (V1IamPolicyState) ElementType ¶
func (V1IamPolicyState) ElementType() reflect.Type