gcp Terraform Google Provider Releases · · 7.46.1

Terraform Provider for Google Cloud v7.46.1 Released

terraforminfragcpgapreviewdeprecationengineergcp-bigquerygcp-cloud-rungcp-gkegcp-cloud-sqlgcp-cloud-storagegcp-dataflowgcp-dataprocgcp-firestore
deprecation feature patch announcement

The Terraform Provider for Google Cloud has been updated to version 7.46.1, primarily addressing a permadiff regression when omitting IAP from the `google_compute_backend_service`. This release also incorporates significant updates from prior versions, including new data sources and resources for Memorystore ACL policies, Migration Center, and various Network Services. Additionally, several BeyondCorp application resources have been deprecated, streamlining the provider for improved Google Cloud infrastructure management. These changes provide expanded infrastructure-as-code capabilities for Google Cloud users and resolve critical issues.

  • New Data Source: google_memorystore_acl_policy
  • New Data Source: google_redis_cluster_acl_policy
  • New List Resource: google_migration_center_assets_export_job
  • New List Resource: google_migration_center_discovery_client
  • New List Resource: google_migration_center_group
Deprecations (2)
  • beyondcorp

    deprecated google_beyondcorp_app_connection, google_beyondcorp_app_connector, and google_beyondcorp_app_gateway resources and data sources. Use google_beyondcorp_security_gateway and google_beyondcorp_security_gateway_application instead

  • vertexai deprecated google_vertex_ai_schedule, an accidentally-added duplicate resource; use google_colab_schedule instead
Features (77)
  • google_memorystore_acl_policy New Data Source: google_memorystore_acl_policy
  • google_redis_cluster_acl_policy New Data Source: google_redis_cluster_acl_policy
  • google_migration_center_assets_export_job New List Resource: google_migration_center_assets_export_job
  • google_migration_center_discovery_client New List Resource: google_migration_center_discovery_client
  • google_migration_center_group New List Resource: google_migration_center_group
  • google_migration_center_import_job New List Resource: google_migration_center_import_job
  • google_migration_center_preference_set New List Resource: google_migration_center_preference_set
  • google_migration_center_report_config New List Resource: google_migration_center_report_config
  • google_migration_center_source New List Resource: google_migration_center_source
  • google_network_services_authz_extension New List Resource: google_network_services_authz_extension
  • google_network_services_multicast_consumer_association New List Resource: google_network_services_multicast_consumer_association
  • google_network_services_multicast_domain_activation New List Resource: google_network_services_multicast_domain_activation
  • google_network_services_multicast_domain_group New List Resource: google_network_services_multicast_domain_group
  • google_network_services_multicast_domain New List Resource: google_network_services_multicast_domain
  • google_network_services_multicast_group_consumer_activation New List Resource: google_network_services_multicast_group_consumer_activation
  • google_network_services_multicast_group_producer_activation New List Resource: google_network_services_multicast_group_producer_activation
  • google_network_services_multicast_group_range_activation New List Resource: google_network_services_multicast_group_range_activation
  • google_network_services_multicast_group_range New List Resource: google_network_services_multicast_group_range
  • google_network_services_multicast_producer_association New List Resource: google_network_services_multicast_producer_association
  • google_memorystore_acl_policy New Resource: google_memorystore_acl_policy
  • google_redis_cluster_acl_policy New Resource: google_redis_cluster_acl_policy
  • google_iam_workload_identity_pool_openid_config New Data Source: google_iam_workload_identity_pool_openid_config
  • google_agentic_applications_analyst_agent_persona New Resource: google_agentic_applications_analyst_agent_persona
  • google_firestore_change_stream New Resource: google_firestore_change_stream
  • google_bigquery_dataset_iam_member New List Resource: google_bigquery_dataset_iam_member
  • google_bigquery_table New List Resource: google_bigquery_table
  • google_chronicle_custom_list New Resource: google_chronicle_custom_list
  • google_chronicle_soar_network New Resource: google_chronicle_soar_network
  • google_dataform_repository New Resource: google_dataform_repository
  • google_dataform_repository_iam_binding New Resource: google_dataform_repository_iam_binding
  • google_dataform_repository_iam_member New Resource: google_dataform_repository_iam_member
  • google_dataform_repository_iam_policy New Resource: google_dataform_repository_iam_policy
  • google_iam_folder_access_policy New Resource: google_iam_folder_access_policy
  • google_iam_organization_access_policy New Resource: google_iam_organization_access_policy
  • google_iam_project_access_policy New Resource: google_iam_project_access_policy
  • google_vertex_ai_evaluation_metric New Resource: google_vertex_ai_evaluation_metric
  • google_compute_instance New List Resource: google_compute_instance
  • google_discovery_engine_assistant New List Resource: google_discovery_engine_assistant
  • google_discovery_engine_chat_engine New List Resource: google_discovery_engine_chat_engine
  • google_discovery_engine_cmek_config New List Resource: google_discovery_engine_cmek_config
  • google_discovery_engine_control New List Resource: google_discovery_engine_control
  • google_discovery_engine_data_store New List Resource: google_discovery_engine_data_store
  • google_discovery_engine_license_config New List Resource: google_discovery_engine_license_config
  • google_discovery_engine_recommendation_engine New List Resource: google_discovery_engine_recommendation_engine
  • google_discovery_engine_schema New List Resource: google_discovery_engine_schema
  • google_discovery_engine_search_engine New List Resource: google_discovery_engine_search_engine
  • google_discovery_engine_serving_config New List Resource: google_discovery_engine_serving_config
  • google_discovery_engine_sitemap New List Resource: google_discovery_engine_sitemap
  • google_discovery_engine_target_site New List Resource: google_discovery_engine_target_site
  • google_discovery_engine_user_store New List Resource: google_discovery_engine_user_store
  • google_project_iam_custom_role New List Resource: google_project_iam_custom_role
  • google_pubsub_subscription_iam_member New List Resource: google_pubsub_subscription_iam_member
  • google_service_account_iam_member New List Resource: google_service_account_iam_member
  • google_cloud_support_support_event_subscription New Resource: google_cloud_support_support_event_subscription
  • google_compute_region_network_policy_traffic_classification_rule New Resource: google_compute_region_network_policy_traffic_classification_rule
  • google_netapp_trial New Resource: google_netapp_trial
  • google_network_connectivity_gateway_advertised_route New Resource: google_network_connectivity_gateway_advertised_route GA promotion
  • google_cloud_quotas_quota_adjuster_settings New Data Source: google_cloud_quotas_quota_adjuster_settings
  • google_service_account_key New List Resource: google_service_account_key
  • google_agent_identity_auth_provider New Resource: google_agent_identity_auth_provider
  • google_apihub_runtime_project_attachment New Resource: google_apihub_runtime_project_attachment
  • google_chronicle_big_query_export New Resource: google_chronicle_big_query_export
  • google_compute_global_vm_extension_policy New Resource: google_compute_global_vm_extension_policy
  • google_compute_rollout_plan New Resource: google_compute_rollout_plan
  • google_vector_search_data_object New Resource: google_vector_search_data_object
  • google_vertex_ai_persistent_resource New Resource: google_vertex_ai_persistent_resource
  • google_chronicle_environment_group New Resource: google_chronicle_environment_group
  • google_compute_router_named_set New Resource: google_compute_router_named_set
  • google_compute_backend_bucket_signed_url_key New List Resource: google_compute_backend_bucket_signed_url_key
  • google_compute_backend_service_signed_url_key New List Resource: google_compute_backend_service_signed_url_key
  • google_compute_network_firewall_policy New List Resource: google_compute_network_firewall_policy
  • google_compute_network_firewall_policy_association New List Resource: google_compute_network_firewall_policy_association
  • google_compute_network_firewall_policy_packet_mirroring_rule New List Resource: google_compute_network_firewall_policy_packet_mirroring_rule
  • google_compute_preview_feature New List Resource: google_compute_preview_feature
  • google_compute_public_advertised_prefix New List Resource: google_compute_public_advertised_prefix
  • google_compute_region_backend_bucket New List Resource: google_compute_region_backend_bucket
  • google_compute_region_network_firewall_policy New List Resource: google_compute_region_network_firewall_policy
Enhancements (83)
  • biglake added serde_info field to google_biglake_table resource
  • ces added connector_toolset and timeout fields to google_ces_toolset resource
  • compute added write-only arguments for IAP oauth2_client_id and oauth2_client_secret to google_compute_backend_service resource
  • discoveryengine made google_discovery_engine_search_engine search_engine_config.required_subscription_tier updatable
  • securesourcemanager added PULL_REQUEST_COMMENT enum to events field in google_secure_source_manager_hook
  • sql added replication_lag_max_seconds to google_sql_database_instance
  • accesscontextmanager added dry_run_access_levels and principal fields to google_access_context_manager_gcp_user_access_binding resource
  • accesscontextmanager updated group_key to be optional and conflict with principal on google_access_context_manager_gcp_user_access_binding resource
  • bigqueryreservation added labels field to google_bigquery_reservation resource
  • certificatemanager enabled write-only support for pem_private_key on google_certificate_manager_certificate resource
  • ces added snippets_config field to data_store_tool.modality_configs and service_directory_config field to python_function in google_ces_tool
  • chronicle added schedule_customizations field to google_chronicle_rule_deployment resource
  • cloudrunv2 added templates.sandboxes field to google_cloud_run_v2_service resource
  • colab added custom_environment_spec.shielded_instance_config and workbench_runtime.vm_image fields to google_colab_notebook_execution resource
  • compute added custom_error_response_policy and default_error_response_policy fields to google_compute_url_map resource
  • compute

    promoted max_run_duration and on_instance_stop_action fields on google_compute_instance, google_compute_instance_template, and google_compute_instance_from_machine_image resources

  • dataplex added sql_assertion field to google_dataplex_datascan resource
  • netapp added zone and replica_zone fields to google_netapp_storage_pool resource
  • securityscanner added static_ip_scan field to google_security_scanner_scan_config resource
  • vertexai added spec.container_spec.port field to google_vertex_ai_reasoning_engine resource
  • workbench added compute_instance_id field to google_workbench_instance resource
  • bigquery added resource identity support to google_bigquery_table
  • compute

    promoted host_error_timeout_seconds field in google_compute_instance, google_compute_instance_template and google_compute_region_instance_template to GA

  • container added high_scale_checkpointing_config block to addons_config in google_container_cluster
  • dataproc added attached_disk_config to disk_config to support attached disks in the google_dataproc_cluster resource
  • memorystore documented TOKEN_AUTH as a google-beta-only value for authorization_mode field on google_memorystore_instance resource
  • networkservices added allow_global_access field to google_network_services_gateway
  • oracledatabase added identity_connector to google_oracle_database_exadb_vm_cluster for CMEK support
  • securesourcemanager added service_account and scan_config fields to google_secure_source_manager_repository
  • sql added password_secret_version and user fields into google_sql_provision_script resource
  • sql

    removed ForceNew config from disk_type field in google_sql_database_instance, allowing it to change in future without requiring the database instance to be destroyed and recreated

  • apigee added service_account field to google_apigee_api_deployment resource
  • apihub added source_project_id field to google_apihub_plugin_instance resource
  • artifactregistry added no_cache field to google_artifact_registry_repository.remote_repository_config
  • bigquery added data_governance_tags_info field to google_bigquery_table resource
  • bigqueryanalyticshub added proposer field to google_bigquery_analytics_hub_query_template
  • bigqueryanalyticshub promoted google_bigquery_analytics_hub_query_template to GA
  • bigquerydatapolicyv2 added data_governance_tag field to google_bigquery_datapolicyv2_data_policy resource
  • bigqueryreservation added principal field to google_bigquery_reservation_assignment resource
  • cloudrunv added sandbox_launcher field to the containers of google_cloud_run_service resource
  • cloudrunv2 added sandbox_launcher field to the containers of google_cloud_run_v2_service resource
  • compute promoted ncc_gateway field in google_compute_router to GA
  • discoveryengine added acl_enabled field to google_discovery_engine_data_store resource
  • networkconnectivity promoted gateway field in google_network_connectivity_spoke to GA
  • privateca made config.subject_config.subject.organization optional in google_privateca_certificate
  • vertexai added traffic_config field and live traffic split update support to google_vertex_ai_reasoning_engine
  • bigquery added table_type field to google_bigquery_routine resource
  • cloudrunv2 added start_execution_token and run_execution_token fields to google_cloud_run_v2_jobresource
  • colab

    added catch_up, create_pipeline_job_request, create_time, last_pause_time, last_resume_time, last_scheduled_run_response, max_concurrent_active_run_count, next_run_time, started_run_count, and update_time fields, and sub-fields under create_notebook_execution_job_request.notebook_execution_job (create_time, custom_environment_spec, encryption_spec, job_state, kernel_name, labels, name, schedule_resource_name, workbench_runtime) and under create_notebook_execution_job_request (notebook_execution_job_id, parent) to google_colab_schedule resource

  • compute added effective_location field to google_compute_interconnect resource
  • compute

    added request_headers and response_headers fields to log_config on google_compute_backend_service and google_compute_region_backend_service resources

  • compute added identity support to google_compute_instance, allowing resource import using an identity block
  • compute changed location field to mutable for google_compute_interconnect resource
  • container added addons_config.node_readiness_config field to google_container_cluster resource
  • container added rollback_safe_upgrade, desired_emulated_version, and emulated_version fields to google_container_cluster resource
  • container increased default timeout to 2 hours for google_container_node_poolresource
  • dataproc added confidential_instance_type field to google_dataproc_cluster resource
  • gkehub

    added min_control_plane_version, min_node_version, target_control_plane_version, target_node_version, and operational_state fields to google_gke_hub_rollout_sequence resource

  • hypercomputecluster increased default timeouts for google_hypercomputecluster_cluster to 120 minutes
  • modelarmor added field template_metadata.filter_version_selector to google_model_armor_template resource
  • sql added identity support to google_sql_user for terraform query support
  • accesscontextmanager

    added allowed_service_patterns and service_patterns_enforcement_scopes fields to google_access_context_manager_service_perimeter to support VPC Service Controls for non-GCP APIs

  • accesscontextmanager added pscEndpoint to sources in ingress_from and egress_from under resources google_access_context_manager_service_perimeter and variants
  • backupdr added backup_blocked_by_vault_access_restriction to data.google_backup_dr_data_source resource
  • backupdr added force_update_access_restriction to google_backup_dr_backup_vault resource
  • backupdr added update support for access_restriction to google_backup_dr_backup_vault resource
  • certificatemanager

    added in-place update support for the self_managed certificate data (pem_certificate / pem_private_key) on google_certificate_manager_certificate; changing the certificate data is now applied via update instead of forcing recreation

  • cloudrunv2

    added tags field to google_cloud_run_v2_service and google_cloud_run_v2_job resources to allow setting tags for services and jobs at creation time

  • cloudsql added max_custom_on_demand_retention_days to create backup_plan example for sqladmin
  • compute added 3500GB and 7000GB SSD partition size to google_compute_instance_template resource
  • compute

    added FLEX_START and RESERVATION_BOUND support to google_compute_instance, google_compute_instance_template, and google_compute_region_instance_template resources

  • container added the support for updating node_image_config and image_type fields at the same time
  • dataproc added confidential_instance_type to google_dataproc_cluster resource
  • dataproc added instance_selection.disk_config field to google_dataproc_cluster resource
  • discoveryengine added enable_llm_layout_parsing and enable_get_processed_document fields to google_discovery_engine_data_store resource
  • sql

    added instance_auto_dns_status and write_endpoint_auto_dns_status output fields to psc_auto_connections block in google_sql_database_instance resource

  • sql added include_replicas_for_major_version_upgrade field to google_sql_database_instance resource
  • sql added switch_transaction_logs_to_cloud_storage_enabled field to google_sql_database_instance resource
  • vertexai promoted google_vertex_ai_semantic_governance_policy_engine resource to GA
  • workbench added enable_deletion_protection field to google_workbench_instance resource
  • workbench added resource_policies field to google_workbench_instance resource
  • workbench added support for min_cpu_platform in google_workbench_instance resource
  • workstations added instance_metadata field to google_workstations_workstation_config resource
Fixes (35)
  • compute fix permadiff regression when iap is omitted from google_compute_backend_service
  • compute fixed truncation of results at 500 images in google_compute_images data source
  • container

    fixed a permadiff on enable_private_endpoint and master_global_access_config.enabled in google_container_cluster when control_plane_endpoints_config.ip_endpoints_config.enabled is set to false

  • sql fixed google_sql_user returning Missing Resource Identity After Read when the parent Cloud SQL instance is stopped
  • alloydb fixed an issue where updateMask URL parameter was dropped during cluster updates (e.g. database_version upgrade) due to variable shadowing
  • appengine fixed permadiff in google_app_engine_standard_app_version
  • bigquery fixed an issue where updating google_bigquery_dataset overwrote fine-grained IAM permissions
  • cloudsecuritycompliance fixed state drift on supported_enforcement_modes in google_cloud_security_compliance_framework resource
  • colab fixed drift detection on direct_notebook_source.content field in google_colab_notebook_execution resource
  • compute

    fixed a panic in google_compute_shared_vpc_service_project during terraform plan/refresh when the shared VPC link had been removed outside of Terraform

  • compute

    fixed permadiff on adaptive_protection_config.layer_7_ddos_defense_config.enable in google_compute_security_policy when field is not set in config

  • compute fixed permadiffs for google_compute_disk on Fedora CoreOS images
  • networksecurity fixed google_network_security_gateway_security_policy to force replacement when name or location is modified
  • backupdr

    fixed issue where google_backup_dr_restore_workload dropped resource_manager_tags during restore requests, causing tags shown in plan to not be applied to restored resources

  • biglakeiceberg fixed a permadiff in google_biglake_iceberg_table by suppressing diffs on location when the API-returned path contains a suffix folder
  • biglakeiceberg fixed permadiff on write.parquet.compression-codec in google_biglake_iceberg_table
  • bigquery fixed a provider panic when reading incomplete IAM conditions on google_bigquery_dataset_iam_member
  • cloudrunv2 fixed permadiff by setting template.scaling.max_instance_count to computed in google_cloud_run_v2_service
  • cloudrunv2 fixed permadiff in template.containers.resources.limits block in google_cloud_run_v2_service resource
  • cloudsecuritycompliance fixed state drift on supported_enforcement_modes in google_cloud_security_compliance_framework resource
  • container fixed a permadiff where ignore_node_count_changes was not persisted in google_container_cluster.node_pool
  • container

    fixed an issue where google_container_node_pool and google_container_cluster failed to invalidate their Instance Group Manager cache when a resize occurred or when ignore_node_count_changes was active

  • networkconnectivity made network field in google_network_connectivity_transport optional
  • recaptchaenterprise

    fixed updates to google_recaptcha_enterprise_key so existing challenge_settings.action_settings entries are preserved when the action map changes

  • servicenetworking fixed google_service_networking_connection ignoring the configured delete timeout, which used the create timeout instead
  • apigee fixed continue_on_error argument being dropped in google_apigee_flowhook, aligning provider behavior with the Apigee API
  • compute fixed panic when setting scheduling attributes in google_compute_region_instance_template (ga)
  • gkehub2 made field spec.workloadidentity.scopeTenancyPool in resource google_gke_hub_feature not required
  • bigtable fixed an issue where bigtable_custom_endpoint and universe_domain were ignored when creating Bigtable resources
  • compute fixed an issue where diffs in google_compute_security_policy were not detected
  • gkehub fixed rollout_creation_scope and upgrade_types fields in google_gke_hub_rollout_sequence resource
  • osconfig

    added client-side validation to ensure resource_hierarchy_selector and location_selector are not set at the same time in google_os_config_v2_policy_orchestrator, google_os_config_v2_policy_orchestrator_for_folder, and google_os_config_v2_policy_orchestrator_for_organization

  • secretmanager fixed an issue where google_secret_manager_secret_version would fail at apply time if neither secret_data nor secret_data_wo was set
  • sql

    fixed issue where updates to settings.ip_configuration.psc_config.allowed_consumer_projects in google_sql_database_instance were silently ignored on in-place updates

  • vertexai

    fixed google_vertex_ai_endpoint_with_model_garden_deployment destroying and recreating the endpoint when min_replica_count, max_replica_count, required_replica_count, or autoscaling_metric_specs changed

Notes (3)
  • docs(workflows): added warning to source_contents field on google_workflows_workflow noting that it will become required in version 8.0.0
  • firestore clarified which resource to use for which kind of index in Standard and Enterprise editions
  • compute migrated google_compute_region_instance_template resource to use direct HTTP rather than a client library
Read the original announcement →

https://github.com/hashicorp/terraform-provider-google/releases/tag/v7.46.1

Related releases