Skip to content

Bump hashicorp/google from 8.1.0 to 8.3.0 - #50

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/terraform/hashicorp/google-8.3.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/terraform/hashicorp/google-8.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps hashicorp/google from 8.1.0 to 8.3.0.

Release notes

Sourced from hashicorp/google's releases.

v8.3.0

FEATURES:

  • New Data Source: google_compute_service_attachments (#29253)
  • New List Resource: google_firebase_android_app (#29269)
  • New List Resource: google_firebase_apple_app (#29269)
  • New List Resource: google_firebase_web_app (#29269)
  • New List Resource: google_pubsub_topic_iam_member (#29259)
  • New Resource: google_chronicle_case_stage_definition (#29276)
  • New Resource: google_chronicle_case_tag_definition (#29236)
  • New Resource: google_compute_network_edge_security_service (#29248)
  • New Resource: google_data_loss_prevention_content_policy (#29296)
  • New Resource: google_gemini_gda_observability_setting_binding (#29286)
  • New Resource: google_gemini_gda_observability_setting (#29286)
  • New Resource: google_vertex_ai_rag_corpus (#29252)

IMPROVEMENTS:

  • accesscontextmanager: added etag field to google_access_context_manager_service_perimeter (#29261)
  • bigquerydatatransfer: added output fields to google_bigquery_data_transfer_data_source_enrollment (#29267)
  • ces: added channel_profile.whatsapp_config field to google_ces_deployment (#29279)
  • ces: added evaluation_metrics_thresholds.golden_evaluation_metrics_thresholds.tool_matching_settings.extra_tool_call_behavior field to google_ces_app (#29247)
  • ces: added evaluation_metrics_thresholds.golden_evaluation_metrics_thresholds.turn_level_metrics_thresholds.semantic_similarity_channel field to google_ces_app (#29244)
  • ces: added mcp_toolset.tool_overrides field to google_ces_toolset (#29291)
  • ces: added transfer_rules field to google_ces_agent (#29262)
  • chronicle: added base64_image, dynamic_parameters, instance_uri, and weight fields to google_chronicle_environment (#29265)
  • cloudsecuritycompliance: added parameter_spec.sub_parameters.sub_parameters and nested oneof_value fields to google_cloud_security_compliance_cloud_control (#29298)
  • dataplex: added data_documentation_spec.sql_dialect field to google_dataplex_datascan (#29285)
  • dataproc: added instance_flexibility_policy to master_config, worker_config, and secondary_worker_config in google_dataproc_workflow_template (#29287)
  • gkehub: added default_cluster_config.compliance_posture_config and labels to google_gke_hub_fleet (#29245)
  • managedkafka: added public_cluster_config, public_cluster_details, and bootstrap_address fields to google_managed_kafka_cluster resource (#29273)
  • parametermanager: added tags field to google_parameter_manager_parameter and google_parameter_manager_regional_parameter to allow setting tags for parameters at creation time (#29299)

BUG FIXES:

  • accesscontextmanager: fixed bug in google_access_context_manager_service_perimeter where changes to the status / spec fields could cause updates to related ingress/egress policies even if those fields weren't specified on google_access_context_manager_service_perimeter (#29261)
  • accesscontextmanager: fixed sending of etag on update requests for google_access_context_manager_service_perimeter_egress_policy and google_access_context_manager_service_perimeter_ingress_policy to prevent concurrent requests from impacting each other (#29261)
  • biglakeiceberg: fixed an issue where creating a partitioned google_biglake_iceberg_table failed due to missing field-id (#29295)
  • compute: fixed a bug where an explicitly configured advanced_machine_features.performance_monitoring_unit = "STANDARD" was dropped on creation for google_compute_instance, google_compute_instance_template, and google_compute_region_instance_template (#29302)
  • config: fixed diff when artifacts_gcs_bucket is not specified on google_config_deployment (#29258)
  • provider: added validation to reject more than one external_credentials or batching block, matching the existing SDK behavior (#29266)

v8.2.0

NOTES:

  • compute: migrate google_compute_subnetworks data source to use direct HTTP rather than a client library (#29226)

FEATURES:

  • New List Resource: google_appengine_domain_mapping (#29174)
  • New List Resource: google_appengine_service_network_settings (#29174)
  • New List Resource: google_appengine_service_split_traffic (#29174)
  • New List Resource: google_contact_center_insights_analysis_rule (#29146)
  • New List Resource: google_contact_center_insights_assessment_rule (#29146)
  • New List Resource: google_contact_center_insights_auto_labeling_rule (#29146)

... (truncated)

Changelog

Sourced from hashicorp/google's changelog.

8.3.0 (September 15, 2026)

FEATURES:

  • New Data Source: google_compute_service_attachments (#29253)
  • New List Resource: google_firebase_android_app (#29269)
  • New List Resource: google_firebase_apple_app (#29269)
  • New List Resource: google_firebase_web_app (#29269)
  • New List Resource: google_pubsub_topic_iam_member (#29259)
  • New Resource: google_chronicle_case_stage_definition (#29276)
  • New Resource: google_chronicle_case_tag_definition (#29236)
  • New Resource: google_compute_network_edge_security_service (#29248)
  • New Resource: google_data_loss_prevention_content_policy (#29296)
  • New Resource: google_gemini_gda_observability_setting_binding (#29286)
  • New Resource: google_gemini_gda_observability_setting (#29286)
  • New Resource: google_vertex_ai_rag_corpus (#29252)

IMPROVEMENTS:

  • accesscontextmanager: added etag field to google_access_context_manager_service_perimeter (#29261)
  • bigquerydatatransfer: added output fields to google_bigquery_data_transfer_data_source_enrollment (#29267)
  • ces: added channel_profile.whatsapp_config field to google_ces_deployment (#29279)
  • ces: added evaluation_metrics_thresholds.golden_evaluation_metrics_thresholds.tool_matching_settings.extra_tool_call_behavior field to google_ces_app (#29247)
  • ces: added evaluation_metrics_thresholds.golden_evaluation_metrics_thresholds.turn_level_metrics_thresholds.semantic_similarity_channel field to google_ces_app (#29244)
  • ces: added mcp_toolset.tool_overrides field to google_ces_toolset (#29291)
  • ces: added transfer_rules field to google_ces_agent (#29262)
  • chronicle: added base64_image, dynamic_parameters, instance_uri, and weight fields to google_chronicle_environment (#29265)
  • cloudsecuritycompliance: added parameter_spec.sub_parameters.sub_parameters and nested oneof_value fields to google_cloud_security_compliance_cloud_control (#29298)
  • dataplex: added data_documentation_spec.sql_dialect field to google_dataplex_datascan (#29285)
  • dataproc: added instance_flexibility_policy to master_config, worker_config, and secondary_worker_config in google_dataproc_workflow_template (#29287)
  • gkehub: added default_cluster_config.compliance_posture_config and labels to google_gke_hub_fleet (#29245)
  • managedkafka: added public_cluster_config, public_cluster_details, and bootstrap_address fields to google_managed_kafka_cluster resource (#29273)
  • parametermanager: added tags field to google_parameter_manager_parameter and google_parameter_manager_regional_parameter to allow setting tags for parameters at creation time (#29299)

BUG FIXES:

  • accesscontextmanager: fixed bug in google_access_context_manager_service_perimeter where changes to the status / spec fields could cause updates to related ingress/egress policies even if those fields weren't specified on google_access_context_manager_service_perimeter (#29261)
  • accesscontextmanager: fixed sending of etag on update requests for google_access_context_manager_service_perimeter_egress_policy and google_access_context_manager_service_perimeter_ingress_policy to prevent concurrent requests from impacting each other (#29261)
  • biglakeiceberg: fixed an issue where creating a partitioned google_biglake_iceberg_table failed due to missing field-id (#29295)
  • compute: fixed a bug where an explicitly configured advanced_machine_features.performance_monitoring_unit = "STANDARD" was dropped on creation for google_compute_instance, google_compute_instance_template, and google_compute_region_instance_template (#29302)
  • config: fixed diff when artifacts_gcs_bucket is not specified on google_config_deployment (#29258)
  • provider: added validation to reject more than one external_credentials or batching block, matching the existing SDK behavior (#29266)

8.2.0 (September 8, 2026)

NOTES:

  • compute: migrate google_compute_subnetworks data source to use direct HTTP rather than a client library (#29226)

FEATURES:

  • New List Resource: google_appengine_domain_mapping (#29174)
  • New List Resource: google_appengine_service_network_settings (#29174)
  • New List Resource: google_appengine_service_split_traffic (#29174)
  • New List Resource: google_contact_center_insights_analysis_rule (#29146)

... (truncated)

Commits
  • 7ec95d4 Changelog 8.3.0 (ga) (#29356)
  • 3bcfb57 Fixed WAF config tests (#18655) (#29305)
  • f6890c8 vertexai: harden & de-flake gateway_configs acceptance coverage on google_ver...
  • 235771a Added sweeper.wait_for_delete for debugging purposes (#18973) (#29303)
  • 76a835a compute: fix performance_monitoring_unit STANDARD dropped on create (#18964) ...
  • 753b441 managedkafka: add security warning to allowed_source_ip_ranges description (#...
  • bd9e7ef Fix Developer Connect insights config basic test missing apphub viewe… (#1896...
  • 5adb36e Add tags to Parameter Manager Resource (#18942) (#29299)
  • da3b66e cloudsecuritycompliance: add nested parameter_spec fields to google_cloud_sec...
  • 4880f20 memorystore: make sample resources sweepable (#18953) (#29297)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [hashicorp/google](https://github.com/hashicorp/terraform-provider-google) from 8.1.0 to 8.3.0.
- [Release notes](https://github.com/hashicorp/terraform-provider-google/releases)
- [Changelog](https://github.com/hashicorp/terraform-provider-google/blob/main/CHANGELOG.md)
- [Commits](hashicorp/terraform-provider-google@v8.1.0...v8.3.0)

---
updated-dependencies:
- dependency-name: hashicorp/google
  dependency-version: 8.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 21, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: terraform. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown

Terraform plan in .

Plan: 1 to add, 2 to change, 24 to destroy.
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+   create
!~  update in-place
-   destroy

Terraform will perform the following actions:

  # module.infrastructure.google_project_iam_member.project_roles["roles/artifactregistry.admin"] will be created
+   resource "google_project_iam_member" "project_roles" {
+       etag    = (known after apply)
+       id      = (known after apply)
+       member  = "serviceAccount:gha-cloud-functions-deployment@jeffreyhung-test.iam.gserviceaccount.com"
+       project = "jeffreyhung-test"
+       role    = "roles/artifactregistry.admin"
    }

  # module.infrastructure.google_storage_bucket.staging_bucket will be updated in-place
!~  resource "google_storage_bucket" "staging_bucket" {
        id                          = "jeffreyhung-test-cloud-function-staging"
        name                        = "jeffreyhung-test-cloud-function-staging"
#        (19 unchanged attributes hidden)

+       lifecycle_rule {
+           action {
+               type          = "Delete"
#                (1 unchanged attribute hidden)
            }
+           condition {
+               age                    = 90
+               matches_prefix         = []
+               matches_storage_class  = []
+               matches_suffix         = []
+               with_state             = (known after apply)
#                (3 unchanged attributes hidden)
            }
        }

#        (2 unchanged blocks hidden)
    }

  # module.infrastructure.google_storage_bucket_iam_binding.tfstate-bucket-iam will be updated in-place
!~  resource "google_storage_bucket_iam_binding" "tfstate-bucket-iam" {
        id      = "b/jeffreyhung-test-tfstate/roles/storage.objectUser"
!~      members = [
-           "serviceAccount:gha-cf-tf-plan@jeffreyhung-test.iam.gserviceaccount.com",
#            (1 unchanged element hidden)
        ]
#        (3 unchanged attributes hidden)
    }

  # module.infrastructure.google_storage_bucket_iam_member.staging_bucket_get will be destroyed
  # (because google_storage_bucket_iam_member.staging_bucket_get is not in configuration)
-   resource "google_storage_bucket_iam_member" "staging_bucket_get" {
-       bucket = "b/jeffreyhung-test-cloud-function-staging" -> null
-       etag   = "CAg=" -> null
-       id     = "b/jeffreyhung-test-cloud-function-staging/roles/storage.objectViewer/serviceAccount:gha-cloud-functions-deployment@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member = "serviceAccount:gha-cloud-functions-deployment@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       role   = "roles/storage.objectViewer" -> null
    }

  # module.infrastructure.google_storage_bucket_iam_member.tfstate_bucket_get will be destroyed
  # (because google_storage_bucket_iam_member.tfstate_bucket_get is not in configuration)
-   resource "google_storage_bucket_iam_member" "tfstate_bucket_get" {
-       bucket = "b/jeffreyhung-test-tfstate" -> null
-       etag   = "CBM=" -> null
-       id     = "b/jeffreyhung-test-tfstate/roles/storage.objectViewer/serviceAccount:gha-cloud-functions-deployment@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member = "serviceAccount:gha-cloud-functions-deployment@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       role   = "roles/storage.objectViewer" -> null
    }

  # module.functions.module.cloud_function_gen2["example-gen2-cron"].google_cloudfunctions2_function.function will be destroyed
  # (because module.functions.module.cloud_function_gen2["example-gen2-cron"] is not in configuration)
-   resource "google_cloudfunctions2_function" "function" {
-       deletion_policy  = "DELETE" -> null
-       description      = "gen2 cloud function example" -> null
-       effective_labels = {
-           "owner"       = "team-security"
-           "terraformed" = "true"
        } -> null
-       environment      = "GEN_2" -> null
-       id               = "projects/jeffreyhung-test/locations/us-west1/functions/example-gen2-cron" -> null
-       labels           = {
-           "owner"       = "team-security"
-           "terraformed" = "true"
        } -> null
-       location         = "us-west1" -> null
-       name             = "example-gen2-cron" -> null
-       project          = "jeffreyhung-test" -> null
-       state            = "ACTIVE" -> null
-       terraform_labels = {
-           "owner"       = "team-security"
-           "terraformed" = "true"
        } -> null
-       update_time      = "2026-09-03T00:07:07.957984113Z" -> null
-       url              = "https://us-west1-jeffreyhung-test.cloudfunctions.net/example-gen2-cron" -> null
#        (1 unchanged attribute hidden)

-       build_config {
-           build                 = "projects/546928617664/locations/us-west1/builds/689bc512-1b28-4e90-b83d-b0950abe0740" -> null
-           docker_repository     = "projects/jeffreyhung-test/locations/us-west1/repositories/gcf-artifacts" -> null
-           entry_point           = "main" -> null
-           environment_variables = {
-               "ENV_1" = "jeffreyhung-test"
-               "ENV_2" = "345"
            } -> null
-           runtime               = "python311" -> null
#            (2 unchanged attributes hidden)

-           source {
-               storage_source {
-                   bucket     = "jeffreyhung-test-cloud-function-staging" -> null
-                   generation = 1724887117997665 -> null
-                   object     = "src-03bdfabf8c7adb2ef887fe89f69a0dbe.zip" -> null
                }
            }
        }

-       service_config {
-           all_traffic_on_latest_revision   = true -> null
-           available_cpu                    = "0.0833" -> null
-           available_memory                 = "256M" -> null
-           environment_variables            = {
-               "ENV_1"            = "jeffreyhung-test"
-               "ENV_2"            = "345"
-               "LOG_EXECUTION_ID" = "****"
            } -> null
-           ingress_settings                 = "ALLOW_ALL" -> null
-           max_instance_count               = 100 -> null
-           max_instance_request_concurrency = 1 -> null
-           min_instance_count               = 0 -> null
-           service                          = "projects/jeffreyhung-test/locations/us-west1/services/example-gen2-cron" -> null
-           service_account_email            = "cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-           timeout_seconds                  = 60 -> null
-           uri                              = "https://example-gen2-cron-cxy77enrhq-uw.a.run.app" -> null
#            (5 unchanged attributes hidden)

-           secret_environment_variables {
-               key        = "test_key_1" -> null
-               project_id = "jeffreyhung-test" -> null
-               secret     = "test_key_1" -> null
-               version    = "latest" -> null
            }
        }
    }

  # module.functions.module.cloud_function_gen2["example-gen2-cron"].google_cloudfunctions2_function_iam_member.invoker_iam will be destroyed
  # (because google_cloudfunctions2_function_iam_member.invoker_iam is not in configuration)
-   resource "google_cloudfunctions2_function_iam_member" "invoker_iam" {
-       cloud_function = "projects/jeffreyhung-test/locations/us-west1/functions/example-gen2-cron" -> null
-       etag           = "BwZaiO7Aygw=" -> null
-       id             = "projects/jeffreyhung-test/locations/us-west1/functions/example-gen2-cron/roles/cloudfunctions.invoker/serviceAccount:cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       location       = "us-west1" -> null
-       member         = "serviceAccount:cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project        = "jeffreyhung-test" -> null
-       role           = "roles/cloudfunctions.invoker" -> null
    }

  # module.functions.module.cloud_function_gen2["example-gen2-cron"].google_project_iam_member.function_sa_logwriter_iam will be destroyed
  # (because module.functions.module.cloud_function_gen2["example-gen2-cron"] is not in configuration)
-   resource "google_project_iam_member" "function_sa_logwriter_iam" {
-       etag    = "BwZaiO8+XAk=" -> null
-       id      = "jeffreyhung-test/roles/logging.logWriter/serviceAccount:cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member  = "serviceAccount:cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project = "jeffreyhung-test" -> null
-       role    = "roles/logging.logWriter" -> null
    }

  # module.functions.module.cloud_function_gen2["example-gen2-cron"].google_secret_manager_secret_iam_member.secret_iam["test_key_1"] will be destroyed
  # (because module.functions.module.cloud_function_gen2["example-gen2-cron"] is not in configuration)
-   resource "google_secret_manager_secret_iam_member" "secret_iam" {
-       etag      = "BwYszAAiUZ0=" -> null
-       id        = "projects/jeffreyhung-test/secrets/test_key_1/roles/secretmanager.secretAccessor/serviceAccount:cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member    = "serviceAccount:cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project   = "jeffreyhung-test" -> null
-       role      = "roles/secretmanager.secretAccessor" -> null
-       secret_id = "projects/jeffreyhung-test/secrets/test_key_1" -> null
    }

  # module.functions.module.cloud_function_gen2["example-gen2-cron"].google_service_account.function_sa will be destroyed
  # (because module.functions.module.cloud_function_gen2["example-gen2-cron"] is not in configuration)
-   resource "google_service_account" "function_sa" {
-       account_id      = "cf-example-gen2-cron" -> null
-       deletion_policy = "DELETE" -> null
-       description     = "Service account for example-gen2-cron, owned by team-security, managed by Terraform" -> null
-       disabled        = false -> null
-       display_name    = "Cloud Function Service Account for example-gen2-cron" -> null
-       email           = "cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       id              = "projects/jeffreyhung-test/serviceAccounts/cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member          = "serviceAccount:cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       name            = "projects/jeffreyhung-test/serviceAccounts/cf-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project         = "jeffreyhung-test" -> null
-       unique_id       = "105361016037165043108" -> null
    }

  # module.functions.module.cloud_function_gen2["example-gen2-cron"].google_storage_bucket_object.zip will be destroyed
  # (because module.functions.module.cloud_function_gen2["example-gen2-cron"] is not in configuration)
-   resource "google_storage_bucket_object" "zip" {
-       bucket              = "jeffreyhung-test-cloud-function-staging" -> null
-       content_type        = "application/zip" -> null
-       crc32c              = "GfLWGQ==" -> null
-       deletion_policy     = "DELETE" -> null
-       detect_md5hash      = "A736v4x62y74h/6J9poNvg==" -> null
-       event_based_hold    = false -> null
-       generation          = 1784932750923616 -> null
-       id                  = "jeffreyhung-test-cloud-function-staging-src-03bdfabf8c7adb2ef887fe89f69a0dbe.zip" -> null
-       md5hash             = "A736v4x62y74h/6J9poNvg==" -> null
-       md5hexhash          = "03bdfabf8c7adb2ef887fe89f69a0dbe" -> null
-       media_link          = "https://storage.googleapis.com/download/storage/v1/b/jeffreyhung-test-cloud-function-staging/o/src-03bdfabf8c7adb2ef887fe89f69a0dbe.zip?generation=1784932750923616&alt=media" -> null
-       metadata            = {
-           "owner"       = "team-security"
-           "terraformed" = "true"
        } -> null
-       name                = "src-03bdfabf8c7adb2ef887fe89f69a0dbe.zip" -> null
-       output_name         = "src-03bdfabf8c7adb2ef887fe89f69a0dbe.zip" -> null
-       self_link           = "https://www.googleapis.com/storage/v1/b/jeffreyhung-test-cloud-function-staging/o/src-03bdfabf8c7adb2ef887fe89f69a0dbe.zip" -> null
-       source              = "/tmp/example-gen2-cron.zip" -> null
-       storage_class       = "STANDARD" -> null
-       temporary_hold      = false -> null
#        (6 unchanged attributes hidden)
    }

  # module.functions.module.cloud_function_gen2["get-gh-app-token"].google_cloudfunctions2_function.function will be destroyed
  # (because module.functions.module.cloud_function_gen2["get-gh-app-token"] is not in configuration)
-   resource "google_cloudfunctions2_function" "function" {
-       deletion_policy  = "DELETE" -> null
-       description      = "example for using github app in cloud function" -> null
-       effective_labels = {
-           "goog-terraform-provisioned" = "true"
-           "owner"                      = "team-security"
-           "terraformed"                = "true"
        } -> null
-       environment      = "GEN_2" -> null
-       id               = "projects/jeffreyhung-test/locations/us-west1/functions/get-gh-app-token" -> null
-       labels           = {
-           "owner"       = "team-security"
-           "terraformed" = "true"
        } -> null
-       location         = "us-west1" -> null
-       name             = "get-gh-app-token" -> null
-       project          = "jeffreyhung-test" -> null
-       state            = "ACTIVE" -> null
-       terraform_labels = {
-           "goog-terraform-provisioned" = "true"
-           "owner"                      = "team-security"
-           "terraformed"                = "true"
        } -> null
-       update_time      = "2026-09-02T18:06:38.144698120Z" -> null
-       url              = "https://us-west1-jeffreyhung-test.cloudfunctions.net/get-gh-app-token" -> null
#        (1 unchanged attribute hidden)

-       build_config {
-           build                 = "projects/546928617664/locations/us-west1/builds/44b67eb2-bda5-421c-99fe-414f6c835c9a" -> null
-           docker_repository     = "projects/jeffreyhung-test/locations/us-west1/repositories/gcf-artifacts" -> null
-           entry_point           = "main" -> null
-           environment_variables = {} -> null
-           runtime               = "python311" -> null
#            (2 unchanged attributes hidden)

-           automatic_update_policy {}

-           source {
-               storage_source {
-                   bucket     = "jeffreyhung-test-cloud-function-staging" -> null
-                   generation = 1738104634112667 -> null
-                   object     = "src-b8accd8c1708a7aa08b64f4e46452c3b.zip" -> null
                }
            }
        }

-       service_config {
-           all_traffic_on_latest_revision   = true -> null
-           available_cpu                    = "0.0833" -> null
-           available_memory                 = "256M" -> null
-           environment_variables            = {
-               "LOG_EXECUTION_ID" = "****"
            } -> null
-           ingress_settings                 = "ALLOW_ALL" -> null
-           max_instance_count               = 100 -> null
-           max_instance_request_concurrency = 1 -> null
-           min_instance_count               = 0 -> null
-           service                          = "projects/jeffreyhung-test/locations/us-west1/services/get-gh-app-token" -> null
-           service_account_email            = "cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-           timeout_seconds                  = 60 -> null
-           uri                              = "https://get-gh-app-token-cxy77enrhq-uw.a.run.app" -> null
#            (5 unchanged attributes hidden)

-           secret_environment_variables {
-               key        = "GH_APP_ID" -> null
-               project_id = "jeffreyhung-test" -> null
-               secret     = "GH_APP_ID" -> null
-               version    = "latest" -> null
            }
-           secret_environment_variables {
-               key        = "GH_APP_INSTALLATION_ID" -> null
-               project_id = "jeffreyhung-test" -> null
-               secret     = "GH_APP_INSTALLATION_ID" -> null
-               version    = "latest" -> null
            }
-           secret_environment_variables {
-               key        = "GH_APP_PRI_KEY" -> null
-               project_id = "jeffreyhung-test" -> null
-               secret     = "GH_APP_PRI_KEY" -> null
-               version    = "latest" -> null
            }
        }
    }

  # module.functions.module.cloud_function_gen2["get-gh-app-token"].google_cloudfunctions2_function_iam_member.invoker_iam will be destroyed
  # (because google_cloudfunctions2_function_iam_member.invoker_iam is not in configuration)
-   resource "google_cloudfunctions2_function_iam_member" "invoker_iam" {
-       cloud_function = "projects/jeffreyhung-test/locations/us-west1/functions/get-gh-app-token" -> null
-       etag           = "BwYt5cWtNig=" -> null
-       id             = "projects/jeffreyhung-test/locations/us-west1/functions/get-gh-app-token/roles/cloudfunctions.invoker/serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       location       = "us-west1" -> null
-       member         = "serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project        = "jeffreyhung-test" -> null
-       role           = "roles/cloudfunctions.invoker" -> null
    }

  # module.functions.module.cloud_function_gen2["get-gh-app-token"].google_project_iam_member.function_sa_logwriter_iam will be destroyed
  # (because module.functions.module.cloud_function_gen2["get-gh-app-token"] is not in configuration)
-   resource "google_project_iam_member" "function_sa_logwriter_iam" {
-       etag    = "BwZaiO8+XAk=" -> null
-       id      = "jeffreyhung-test/roles/logging.logWriter/serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member  = "serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project = "jeffreyhung-test" -> null
-       role    = "roles/logging.logWriter" -> null
    }

  # module.functions.module.cloud_function_gen2["get-gh-app-token"].google_secret_manager_secret_iam_member.secret_iam["GH_APP_ID"] will be destroyed
  # (because module.functions.module.cloud_function_gen2["get-gh-app-token"] is not in configuration)
-   resource "google_secret_manager_secret_iam_member" "secret_iam" {
-       etag      = "BwYsy/kbUZY=" -> null
-       id        = "projects/jeffreyhung-test/secrets/GH_APP_ID/roles/secretmanager.secretAccessor/serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member    = "serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project   = "jeffreyhung-test" -> null
-       role      = "roles/secretmanager.secretAccessor" -> null
-       secret_id = "projects/jeffreyhung-test/secrets/GH_APP_ID" -> null
    }

  # module.functions.module.cloud_function_gen2["get-gh-app-token"].google_secret_manager_secret_iam_member.secret_iam["GH_APP_INSTALLATION_ID"] will be destroyed
  # (because module.functions.module.cloud_function_gen2["get-gh-app-token"] is not in configuration)
-   resource "google_secret_manager_secret_iam_member" "secret_iam" {
-       etag      = "BwYsy/keYIs=" -> null
-       id        = "projects/jeffreyhung-test/secrets/GH_APP_INSTALLATION_ID/roles/secretmanager.secretAccessor/serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member    = "serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project   = "jeffreyhung-test" -> null
-       role      = "roles/secretmanager.secretAccessor" -> null
-       secret_id = "projects/jeffreyhung-test/secrets/GH_APP_INSTALLATION_ID" -> null
    }

  # module.functions.module.cloud_function_gen2["get-gh-app-token"].google_secret_manager_secret_iam_member.secret_iam["GH_APP_PRI_KEY"] will be destroyed
  # (because module.functions.module.cloud_function_gen2["get-gh-app-token"] is not in configuration)
-   resource "google_secret_manager_secret_iam_member" "secret_iam" {
-       etag      = "BwYsy/jhXsg=" -> null
-       id        = "projects/jeffreyhung-test/secrets/GH_APP_PRI_KEY/roles/secretmanager.secretAccessor/serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member    = "serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project   = "jeffreyhung-test" -> null
-       role      = "roles/secretmanager.secretAccessor" -> null
-       secret_id = "projects/jeffreyhung-test/secrets/GH_APP_PRI_KEY" -> null
    }

  # module.functions.module.cloud_function_gen2["get-gh-app-token"].google_service_account.function_sa will be destroyed
  # (because module.functions.module.cloud_function_gen2["get-gh-app-token"] is not in configuration)
-   resource "google_service_account" "function_sa" {
-       account_id      = "cf-get-gh-app-token" -> null
-       deletion_policy = "DELETE" -> null
-       description     = "Service account for get-gh-app-token, owned by team-security, managed by Terraform" -> null
-       disabled        = false -> null
-       display_name    = "Cloud Function Service Account for get-gh-app-token" -> null
-       email           = "cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       id              = "projects/jeffreyhung-test/serviceAccounts/cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member          = "serviceAccount:cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       name            = "projects/jeffreyhung-test/serviceAccounts/cf-get-gh-app-token@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project         = "jeffreyhung-test" -> null
-       unique_id       = "104033735476450477916" -> null
    }

  # module.functions.module.cloud_function_gen2["get-gh-app-token"].google_storage_bucket_object.zip will be destroyed
  # (because module.functions.module.cloud_function_gen2["get-gh-app-token"] is not in configuration)
-   resource "google_storage_bucket_object" "zip" {
-       bucket              = "jeffreyhung-test-cloud-function-staging" -> null
-       content_type        = "application/zip" -> null
-       crc32c              = "JHDtsQ==" -> null
-       deletion_policy     = "DELETE" -> null
-       detect_md5hash      = "uKzNjBcIp6oItk9ORkUsOw==" -> null
-       event_based_hold    = false -> null
-       generation          = 1788372339084652 -> null
-       id                  = "jeffreyhung-test-cloud-function-staging-src-b8accd8c1708a7aa08b64f4e46452c3b.zip" -> null
-       md5hash             = "uKzNjBcIp6oItk9ORkUsOw==" -> null
-       md5hexhash          = "b8accd8c1708a7aa08b64f4e46452c3b" -> null
-       media_link          = "https://storage.googleapis.com/download/storage/v1/b/jeffreyhung-test-cloud-function-staging/o/src-b8accd8c1708a7aa08b64f4e46452c3b.zip?generation=1788372339084652&alt=media" -> null
-       metadata            = {
-           "owner"       = "team-security"
-           "terraformed" = "true"
        } -> null
-       name                = "src-b8accd8c1708a7aa08b64f4e46452c3b.zip" -> null
-       output_name         = "src-b8accd8c1708a7aa08b64f4e46452c3b.zip" -> null
-       self_link           = "https://www.googleapis.com/storage/v1/b/jeffreyhung-test-cloud-function-staging/o/src-b8accd8c1708a7aa08b64f4e46452c3b.zip" -> null
-       source              = "/tmp/get-gh-app-token.zip" -> null
-       storage_class       = "STANDARD" -> null
-       temporary_hold      = false -> null
#        (6 unchanged attributes hidden)
    }

  # module.functions.module.cronjob-gen2["example-gen2-cron"].google_cloud_run_service_iam_member.cj_gen2_cron_invoker will be destroyed
  # (because module.functions.module.cronjob-gen2["example-gen2-cron"] is not in configuration)
-   resource "google_cloud_run_service_iam_member" "cj_gen2_cron_invoker" {
-       etag     = "BwYgxaRHaoI=" -> null
-       id       = "v1/projects/jeffreyhung-test/locations/us-west1/services/example-gen2-cron/roles/run.invoker/serviceAccount:cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       location = "us-west1" -> null
-       member   = "serviceAccount:cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project  = "jeffreyhung-test" -> null
-       role     = "roles/run.invoker" -> null
-       service  = "v1/projects/jeffreyhung-test/locations/us-west1/services/example-gen2-cron" -> null
    }

  # module.functions.module.cronjob-gen2["example-gen2-cron"].google_cloud_scheduler_job.cron_scheduler will be destroyed
  # (because module.functions.module.cronjob-gen2["example-gen2-cron"] is not in configuration)
-   resource "google_cloud_scheduler_job" "cron_scheduler" {
-       attempt_deadline = "320s" -> null
-       deletion_policy  = "DELETE" -> null
-       description      = "gen2 cloud function example" -> null
-       id               = "projects/jeffreyhung-test/locations/us-west1/jobs/example-gen2-cron" -> null
-       name             = "example-gen2-cron" -> null
-       paused           = false -> null
-       project          = "jeffreyhung-test" -> null
-       region           = "us-west1" -> null
-       schedule         = "0 * * * *" -> null
-       state            = "ENABLED" -> null
-       time_zone        = "America/New_York" -> null

-       http_target {
-           headers     = {} -> null
-           http_method = "GET" -> null
-           uri         = "https://us-west1-jeffreyhung-test.cloudfunctions.net/example-gen2-cron" -> null
#            (1 unchanged attribute hidden)

-           oidc_token {
-               audience              = "https://us-west1-jeffreyhung-test.cloudfunctions.net/example-gen2-cron" -> null
-               service_account_email = "cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
            }
        }
    }

  # module.functions.module.cronjob-gen2["example-gen2-cron"].google_cloudfunctions2_function_iam_member.cj_gen2_cron_invoker will be destroyed
  # (because module.functions.module.cronjob-gen2["example-gen2-cron"] is not in configuration)
-   resource "google_cloudfunctions2_function_iam_member" "cj_gen2_cron_invoker" {
-       cloud_function = "projects/jeffreyhung-test/locations/us-west1/functions/example-gen2-cron" -> null
-       etag           = "BwZaiO7Aygw=" -> null
-       id             = "projects/jeffreyhung-test/locations/us-west1/functions/example-gen2-cron/roles/cloudfunctions.invoker/serviceAccount:cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       location       = "us-west1" -> null
-       member         = "serviceAccount:cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project        = "jeffreyhung-test" -> null
-       role           = "roles/cloudfunctions.invoker" -> null
    }

  # module.functions.module.cronjob-gen2["example-gen2-cron"].google_service_account.cronjob_sa will be destroyed
  # (because module.functions.module.cronjob-gen2["example-gen2-cron"] is not in configuration)
-   resource "google_service_account" "cronjob_sa" {
-       account_id      = "cj-example-gen2-cron" -> null
-       deletion_policy = "DELETE" -> null
-       description     = "Service account for example-gen2-cron, owned by team-security, managed by Terraform" -> null
-       disabled        = false -> null
-       display_name    = "CronJob Service Account for example-gen2-cron" -> null
-       email           = "cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       id              = "projects/jeffreyhung-test/serviceAccounts/cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member          = "serviceAccount:cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       name            = "projects/jeffreyhung-test/serviceAccounts/cj-example-gen2-cron@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project         = "jeffreyhung-test" -> null
-       unique_id       = "109079883649630638593" -> null
    }

  # module.workflows.module.workflows["example-eventarc"].google_service_account.workflow_sa will be destroyed
  # (because module.workflows.module.workflows["example-eventarc"] is not in configuration)
-   resource "google_service_account" "workflow_sa" {
-       account_id      = "wf-example-eventarc" -> null
-       deletion_policy = "DELETE" -> null
-       description     = "Service account for example-eventarc, owned by team-security, managed by Terraform" -> null
-       disabled        = false -> null
-       display_name    = "Workflow Service Account for example-eventarc" -> null
-       email           = "wf-example-eventarc@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       id              = "projects/jeffreyhung-test/serviceAccounts/wf-example-eventarc@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member          = "serviceAccount:wf-example-eventarc@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       name            = "projects/jeffreyhung-test/serviceAccounts/wf-example-eventarc@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project         = "jeffreyhung-test" -> null
-       unique_id       = "113531995145961483452" -> null
    }

  # module.workflows.module.workflows["example-eventarc"].google_workflows_workflow.workflow will be destroyed
  # (because module.workflows.module.workflows["example-eventarc"] is not in configuration)
-   resource "google_workflows_workflow" "workflow" {
-       create_time             = "2025-01-30T22:29:16.501888137Z" -> null
-       deletion_policy         = "DELETE" -> null
-       deletion_protection     = true -> null
-       description             = "example workflow with eventarc" -> null
-       effective_labels        = {
-           "goog-terraform-provisioned" = "true"
-           "owner"                      = "team-security"
-           "terraformed"                = "true"
        } -> null
-       id                      = "projects/jeffreyhung-test/locations/us-west1/workflows/example-eventarc" -> null
-       labels                  = {
-           "owner"       = "team-security"
-           "terraformed" = "true"
        } -> null
-       name                    = "example-eventarc" -> null
-       project                 = "jeffreyhung-test" -> null
-       revision_id             = "000001-88d" -> null
-       service_account         = "projects/jeffreyhung-test/serviceAccounts/wf-example-eventarc@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       source_contents         = <<-EOT
            main:
              steps:
                - example_gen2_cron:
                    call: http.post
                    args:
                      url: https://us-west1-jeffreyhung-test.cloudfunctions.net/example-gen2-cron
                      auth:
                        type: OIDC
                        audience: https://us-west1-jeffreyhung-test.cloudfunctions.net/example-gen2-cron
        EOT -> null
-       state                   = "ACTIVE" -> null
-       terraform_labels        = {
-           "goog-terraform-provisioned" = "true"
-           "owner"                      = "team-security"
-           "terraformed"                = "true"
        } -> null
-       update_time             = "2025-02-12T17:04:55.372682917Z" -> null
-       user_env_vars           = {} -> null
#        (3 unchanged attributes hidden)
    }

  # module.workflows.module.workflows["example1"].google_service_account.workflow_sa will be destroyed
  # (because module.workflows.module.workflows["example1"] is not in configuration)
-   resource "google_service_account" "workflow_sa" {
-       account_id      = "wf-example1" -> null
-       deletion_policy = "DELETE" -> null
-       description     = "Service account for example1, owned by team-security, managed by Terraform" -> null
-       disabled        = false -> null
-       display_name    = "Workflow Service Account for example1" -> null
-       email           = "wf-example1@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       id              = "projects/jeffreyhung-test/serviceAccounts/wf-example1@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       member          = "serviceAccount:wf-example1@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       name            = "projects/jeffreyhung-test/serviceAccounts/wf-example1@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       project         = "jeffreyhung-test" -> null
-       unique_id       = "111860599451351782149" -> null
    }

  # module.workflows.module.workflows["example1"].google_workflows_workflow.workflow will be destroyed
  # (because module.workflows.module.workflows["example1"] is not in configuration)
-   resource "google_workflows_workflow" "workflow" {
-       create_time             = "2025-01-28T22:57:34.911814537Z" -> null
-       deletion_policy         = "DELETE" -> null
-       deletion_protection     = true -> null
-       description             = "example workflow" -> null
-       effective_labels        = {
-           "goog-terraform-provisioned" = "true"
-           "owner"                      = "team-security"
-           "terraformed"                = "true"
        } -> null
-       id                      = "projects/jeffreyhung-test/locations/us-west1/workflows/example1" -> null
-       labels                  = {
-           "owner"       = "team-security"
-           "terraformed" = "true"
        } -> null
-       name                    = "example1" -> null
-       project                 = "jeffreyhung-test" -> null
-       revision_id             = "000001-2ab" -> null
-       service_account         = "projects/jeffreyhung-test/serviceAccounts/wf-example1@jeffreyhung-test.iam.gserviceaccount.com" -> null
-       source_contents         = <<-EOT
            main:
              steps:
                - example_gen2_cron:
                    call: http.post
                    args:
                      url: https://us-west1-jeffreyhung-test.cloudfunctions.net/example-gen2-cron
                      auth:
                        type: OIDC
                        audience: https://us-west1-jeffreyhung-test.cloudfunctions.net/example-gen2-cron
        EOT -> null
-       state                   = "ACTIVE" -> null
-       terraform_labels        = {
-           "goog-terraform-provisioned" = "true"
-           "owner"                      = "team-security"
-           "terraformed"                = "true"
        } -> null
-       update_time             = "2025-02-12T17:04:55.409684045Z" -> null
-       user_env_vars           = {} -> null
#        (3 unchanged attributes hidden)
    }

Plan: 1 to add, 2 to change, 24 to destroy.

📝 Plan generated in Terraform Plan #75

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants