UG FIXES:
- compute: fix permadiff regression when iap is omitted from
google_compute_backend_service(#29156)
7.46.0 (August 25th, 2026)
DEPRECATIONS:
- beyondcorp: deprecated
google_beyondcorp_app_connection,google_beyondcorp_app_connector, andgoogle_beyondcorp_app_gatewayresources and data sources. Usegoogle_beyondcorp_security_gatewayandgoogle_beyondcorp_security_gateway_applicationinstead. (#28976)
FEATURES:
- New Data Source:
google_memorystore_acl_policy(#28984) - New Data Source:
google_redis_cluster_acl_policy(#28985) - New List Resource:
google_migration_center_assets_export_job(#28904) - New List Resource:
google_migration_center_discovery_client(#28904) - New List Resource:
google_migration_center_group(#28904) - New List Resource:
google_migration_center_import_job(#28904) - New List Resource:
google_migration_center_preference_set(#28904) - New List Resource:
google_migration_center_report_config(#28904) - New List Resource:
google_migration_center_source(#28904) - New List Resource:
google_network_services_authz_extension(#28978) - New List Resource:
google_network_services_multicast_consumer_association(#28978) - New List Resource:
google_network_services_multicast_domain_activation(#28978) - New List Resource:
google_network_services_multicast_domain_group(#28978) - New List Resource:
google_network_services_multicast_domain(#28978) - New List Resource:
google_network_services_multicast_group_consumer_activation(#28978) - New List Resource:
google_network_services_multicast_group_producer_activation(#28978) - New List Resource:
google_network_services_multicast_group_range_activation(#28978) - New List Resource:
google_network_services_multicast_group_range(#28978) - New List Resource:
google_network_services_multicast_producer_association(#28978) - New Resource:
google_memorystore_acl_policy(#28984) - New Resource:
google_redis_cluster_acl_policy(#28985)
IMPROVEMENTS:
- biglake: added
serde_infofield togoogle_biglake_tableresource (#28990) - ces: added
connector_toolsetandtimeoutfields togoogle_ces_toolsetresource (#28903) - compute: added write-only arguments for IAP
oauth2_client_idandoauth2_client_secrettogoogle_compute_backend_serviceresource (#28809) - discoveryengine: made
google_discovery_engine_search_enginesearch_engine_config.required_subscription_tierupdatable (#28991) - securesourcemanager: added
PULL_REQUEST_COMMENTenum toeventsfield ingoogle_secure_source_manager_hook(#28907) - sql: added
replication_lag_max_secondstogoogle_sql_database_instance(#28813)
BUG FIXES:
- compute: fixed truncation of results at 500 images in
google_compute_imagesdata source (#28909) - container: fixed a permadiff on
enable_private_endpointandmaster_global_access_config.enabledingoogle_container_clusterwhencontrol_plane_endpoints_config.ip_endpoints_config.enabledis set tofalse(#28981) - sql: fixed
google_sql_userreturningMissing Resource Identity After Readwhen the parent Cloud SQL instance is stopped (#28977)
7.45.0 (August 18, 2026)
FEATURES:
- New Data Source:
google_iam_workload_identity_pool_openid_config(#28790) - New Resource:
google_agentic_applications_analyst_agent_persona(#28777) - New Resource:
google_firestore_change_stream(#28800)
IMPROVEMENTS:
- accesscontextmanager: added
dry_run_access_levelsandprincipalfields togoogle_access_context_manager_gcp_user_access_bindingresource (#28767) - accesscontextmanager: updated
group_keyto be optional and conflict withprincipalongoogle_access_context_manager_gcp_user_access_bindingresource (#28767) - bigqueryreservation: added
labelsfield togoogle_bigquery_reservationresource (#28711) - certificatemanager: enabled write-only support for
pem_private_keyongoogle_certificate_manager_certificateresource (#28794) - ces: added
snippets_configfield todata_store_tool.modality_configsandservice_directory_configfield topython_functioningoogle_ces_tool(#28759) - chronicle: added
schedule_customizationsfield togoogle_chronicle_rule_deploymentresource (#28715) - cloudrunv2: added
templates.sandboxesfield togoogle_cloud_run_v2_serviceresource (#28749) - colab: added
custom_environment_spec.shielded_instance_configandworkbench_runtime.vm_imagefields togoogle_colab_notebook_executionresource (#28774) - compute: added
custom_error_response_policyanddefault_error_response_policyfields togoogle_compute_url_mapresource (#18511) - compute: promoted
max_run_durationandon_instance_stop_actionfields ongoogle_compute_instance,google_compute_instance_template, andgoogle_compute_instance_from_machine_imageresources (#18623) - dataplex: added
sql_assertionfield togoogle_dataplex_datascanresource (#18559) - netapp: added
zoneandreplica_zonefields togoogle_netapp_storage_poolresource (#18609) - securityscanner: added
static_ip_scanfield togoogle_security_scanner_scan_configresource (#28786) - vertexai: added
spec.container_spec.portfield togoogle_vertex_ai_reasoning_engineresource (#28762) - workbench: added
compute_instance_idfield togoogle_workbench_instanceresource (#28773)
BUG FIXES:
- alloydb: fixed an issue where
updateMaskURL parameter was dropped during cluster updates (e.g.database_versionupgrade) due to variable shadowing (#28801) - appengine: fixed permadiff in
google_app_engine_standard_app_version(#28745) - bigquery: fixed an issue where updating
google_bigquery_datasetoverwrote fine-grained IAM permissions (#28775) - cloudsecuritycompliance: fixed state drift on
supported_enforcement_modesingoogle_cloud_security_compliance_frameworkresource (#28676) - colab: fixed drift detection on
direct_notebook_source.contentfield ingoogle_colab_notebook_executionresource (#28774) - compute: fixed a panic in
google_compute_shared_vpc_service_projectduringterraform plan/refreshwhen the shared VPC link had been removed outside of Terraform (#28750) - compute: fixed permadiff on
adaptive_protection_config.layer_7_ddos_defense_config.enableingoogle_compute_security_policywhen field is not set in config (#28751) - compute: fixed permadiffs for
google_compute_diskon Fedora CoreOS images (#28712) - networksecurity: fixed
google_network_security_gateway_security_policyto force replacement whennameorlocationis modified (#28776)
7.44.0 (August 11, 2026)
FEATURES:
- New List Resource:
google_bigquery_dataset_iam_member(#28578) - New List Resource:
google_bigquery_table(#28576) - New Resource:
google_chronicle_custom_list(#28618) - New Resource:
google_chronicle_soar_network(#28649) - New Resource:
google_dataform_repository(#28642) - New Resource:
google_dataform_repository_iam_binding(#28642) - New Resource:
google_dataform_repository_iam_member(#28642) - New Resource:
google_dataform_repository_iam_policy(#28642) - New Resource:
google_iam_folder_access_policy(#28664) - New Resource:
google_iam_organization_access_policy(#28664) - New Resource:
google_iam_project_access_policy(#28664) - New Resource:
google_vertex_ai_evaluation_metric(#28665)
IMPROVEMENTS:
- bigquery: added resource identity support to
google_bigquery_table(#28574) - compute: promoted
host_error_timeout_secondsfield ingoogle_compute_instance,google_compute_instance_templateandgoogle_compute_region_instance_templateto GA (#28671) - container: added
high_scale_checkpointing_configblock toaddons_configingoogle_container_cluster(#28669) - dataproc: added
attached_disk_configtodisk_configto support attached disks in thegoogle_dataproc_clusterresource (#28590) - memorystore: documented
TOKEN_AUTHas agoogle-beta-only value forauthorization_modefield ongoogle_memorystore_instanceresource (#28584) - networkservices: added
allow_global_accessfield togoogle_network_services_gateway(#28589) - oracledatabase: added
identity_connectortogoogle_oracle_database_exadb_vm_clusterfor CMEK support (#28615) - securesourcemanager: added
service_accountandscan_configfields togoogle_secure_source_manager_repository(#28662) - sql: added
password_secret_versionanduserfields intogoogle_sql_provision_scriptresource (#28619) - sql: removed
ForceNewconfig fromdisk_typefield ingoogle_sql_database_instance, allowing it to change in future without requiring the database instance to be destroyed and recreated (#28616)
BUG FIXES:
- backupdr: fixed issue where
google_backup_dr_restore_workloaddroppedresource_manager_tagsduring restore requests, causing tags shown in plan to not be applied to restored resources (#28586) - biglakeiceberg: fixed a permadiff in
google_biglake_iceberg_tableby suppressing diffs onlocationwhen the API-returned path contains a suffix folder (#28577) - biglakeiceberg: fixed permadiff on
write.parquet.compression-codecingoogle_biglake_iceberg_table(#28650) - bigquery: fixed a provider panic when reading incomplete IAM conditions on
google_bigquery_dataset_iam_member(#28617) - cloudrunv2: fixed permadiff by setting
template.scaling.max_instance_countto computed ingoogle_cloud_run_v2_service(#28644) - cloudrunv2: fixed permadiff in
template.containers.resources.limitsblock ingoogle_cloud_run_v2_serviceresource (#28670) - cloudsecuritycompliance: fixed state drift on
supported_enforcement_modesingoogle_cloud_security_compliance_frameworkresource (#28676) - container: fixed a permadiff where
ignore_node_count_changeswas not persisted ingoogle_container_cluster.node_pool(#28573) - container: fixed an issue where
google_container_node_poolandgoogle_container_clusterfailed to invalidate their Instance Group Manager cache when a resize occurred or whenignore_node_count_changeswas active (#28585) - networkconnectivity: made
networkfield ingoogle_network_connectivity_transportoptional (#28639) - recaptchaenterprise: fixed updates to
google_recaptcha_enterprise_keyso existingchallenge_settings.action_settingsentries are preserved when the action map changes (#28673) - servicenetworking: fixed
google_service_networking_connectionignoring the configureddeletetimeout, which used thecreatetimeout instead (#28641)
7.43.0 (August 4, 2026)
NOTES:
- docs(workflows): added warning to
source_contentsfield ongoogle_workflows_workflownoting that it will become required in version 8.0.0 (#28524) - firestore: clarified which resource to use for which kind of index in Standard and Enterprise editions (#28529)
FEATURES:
- New List Resource:
google_compute_instance(#28548) - New List Resource:
google_discovery_engine_assistant(#28525) - New List Resource:
google_discovery_engine_chat_engine(#28525) - New List Resource:
google_discovery_engine_cmek_config(#28525) - New List Resource:
google_discovery_engine_control(#28525) - New List Resource:
google_discovery_engine_data_store(#28525) - New List Resource:
google_discovery_engine_license_config(#28525) - New List Resource:
google_discovery_engine_recommendation_engine(#28525) - New List Resource:
google_discovery_engine_schema(#28525) - New List Resource:
google_discovery_engine_search_engine(#28525) - New List Resource:
google_discovery_engine_serving_config(#28525) - New List Resource:
google_discovery_engine_sitemap(#28525) - New List Resource:
google_discovery_engine_target_site(#28525) - New List Resource:
google_discovery_engine_user_store(#28525) - New List Resource:
google_project_iam_custom_role(#28526) - New List Resource:
google_pubsub_subscription_iam_member(#28549) - New List Resource:
google_service_account_iam_member(#28553) - New Resource:
google_cloud_support_support_event_subscription(#28517) - New Resource:
google_compute_region_network_policy_traffic_classification_rule(#28504) - New Resource:
google_netapp_trial(#28503) - New Resource:
google_network_connectivity_gateway_advertised_routeGA promotion (#28471)
IMPROVEMENTS:
- apigee: added
service_accountfield togoogle_apigee_api_deploymentresource (#28552) - apihub: added
source_project_idfield togoogle_apihub_plugin_instanceresource (#28530) - artifactregistry: added
no_cachefield togoogle_artifact_registry_repository.remote_repository_config(#28506) - bigquery: added
data_governance_tags_infofield togoogle_bigquery_tableresource (#28532) - bigqueryanalyticshub: added
proposerfield togoogle_bigquery_analytics_hub_query_template(#28518) - bigqueryanalyticshub: promoted
google_bigquery_analytics_hub_query_templateto GA (#28518) - bigquerydatapolicyv2: added
data_governance_tagfield togoogle_bigquery_datapolicyv2_data_policyresource (#28463) - bigqueryreservation: added
principalfield togoogle_bigquery_reservation_assignmentresource (#28508) - cloudrunv: added
sandbox_launcherfield to the containers ofgoogle_cloud_run_serviceresource (#28521) - cloudrunv2: added
sandbox_launcherfield to the containers ofgoogle_cloud_run_v2_serviceresource (#28521) - compute: promoted
ncc_gatewayfield ingoogle_compute_routerto GA (#28471) - discoveryengine: added
acl_enabledfield togoogle_discovery_engine_data_storeresource (#28465) - networkconnectivity: promoted
gatewayfield ingoogle_network_connectivity_spoketo GA (#28471) - privateca: made
config.subject_config.subject.organizationoptional ingoogle_privateca_certificate(#28464) - vertexai: added
traffic_configfield and live traffic split update support togoogle_vertex_ai_reasoning_engine(#28473)
BUG FIXES:
- apigee: fixed
continue_on_errorargument being dropped ingoogle_apigee_flowhook, aligning provider behavior with the Apigee API (#28554) - compute: fixed panic when setting scheduling attributes in
google_compute_region_instance_template(ga) (#28467) - gkehub2: made field
spec.workloadidentity.scopeTenancyPoolin resourcegoogle_gke_hub_featurenot required. (#28472)
7.42.0 (July 28, 2026)
NOTES:
- compute: migrated
google_compute_region_instance_templateresource to use direct HTTP rather than a client library (#28431)
DEPRECATIONS:
- vertexai: deprecated
google_vertex_ai_schedule, an accidentally-added duplicate resource; usegoogle_colab_scheduleinstead. (#28406)
FEATURES:
- New Data Source:
google_cloud_quotas_quota_adjuster_settings(#28383) - New List Resource:
google_service_account_key(#28430) - New Resource:
google_agent_identity_auth_provider(#28447) - New Resource:
google_apihub_runtime_project_attachment(#28449) - New Resource:
google_chronicle_big_query_export(#28403) - New Resource:
google_compute_global_vm_extension_policy(#28445) - New Resource:
google_compute_rollout_plan(#28445) - New Resource:
google_vector_search_data_object(#28434) - New Resource:
google_vertex_ai_persistent_resource(#28435)
IMPROVEMENTS:
- bigquery: added
table_typefield togoogle_bigquery_routineresource (#28446) - cloudrunv2: added
start_execution_tokenandrun_execution_tokenfields togoogle_cloud_run_v2_jobresource (#28384) - colab: added
catch_up,create_pipeline_job_request,create_time,last_pause_time,last_resume_time,last_scheduled_run_response,max_concurrent_active_run_count,next_run_time,started_run_count, andupdate_timefields, and sub-fields undercreate_notebook_execution_job_request.notebook_execution_job(create_time,custom_environment_spec,encryption_spec,job_state,kernel_name,labels,name,schedule_resource_name,workbench_runtime) and undercreate_notebook_execution_job_request(notebook_execution_job_id,parent) togoogle_colab_scheduleresource (#28406) - compute: added
effective_locationfield togoogle_compute_interconnectresource (#28416) - compute: added
request_headersandresponse_headersfields tolog_configongoogle_compute_backend_serviceandgoogle_compute_region_backend_serviceresources (#28421) - compute: added identity support to
google_compute_instance, allowing resource import using anidentityblock (#28433) - compute: changed
locationfield to mutable forgoogle_compute_interconnectresource (#28416) - container: added
addons_config.node_readiness_configfield togoogle_container_clusterresource (#28417) - container: added
rollback_safe_upgrade,desired_emulated_version, andemulated_versionfields togoogle_container_clusterresource (#28442) - container: increased default timeout to 2 hours for
google_container_node_poolresource (#28382) - dataproc: added
confidential_instance_typefield togoogle_dataproc_clusterresource (#28371) - gkehub: added
min_control_plane_version,min_node_version,target_control_plane_version,target_node_version, andoperational_statefields togoogle_gke_hub_rollout_sequenceresource (#28429) - hypercomputecluster: increased default timeouts for
google_hypercomputecluster_clusterto 120 minutes (#28448) - modelarmor: added field
template_metadata.filter_version_selectortogoogle_model_armor_templateresource (#28402) - sql: added identity support to
google_sql_userforterraform querysupport (#28428)
BUG FIXES:
- bigtable: fixed an issue where
bigtable_custom_endpointanduniverse_domainwere ignored when creating Bigtable resources (#28404) - compute: fixed an issue where diffs in
google_compute_security_policywere not detected (#28420) - gkehub: fixed
rollout_creation_scopeandupgrade_typesfields ingoogle_gke_hub_rollout_sequenceresource (#28429) - osconfig: added client-side validation to ensure
resource_hierarchy_selectorandlocation_selectorare not set at the same time ingoogle_os_config_v2_policy_orchestrator,google_os_config_v2_policy_orchestrator_for_folder, andgoogle_os_config_v2_policy_orchestrator_for_organization(#28407) - secretmanager: fixed an issue where
google_secret_manager_secret_versionwould fail at apply time if neithersecret_datanorsecret_data_wowas set (#28419) - sql: fixed issue where updates to
settings.ip_configuration.psc_config.allowed_consumer_projectsingoogle_sql_database_instancewere silently ignored on in-place updates (#28444) - vertexai: fixed
google_vertex_ai_endpoint_with_model_garden_deploymentdestroying and recreating the endpoint whenmin_replica_count,max_replica_count,required_replica_count, orautoscaling_metric_specschanged (#28401)
7.41.0 (July 17, 2026)
FEATURES:
- New Resource:
google_chronicle_environment_group(#28338) - New Resource:
google_compute_router_named_set(#28326) - New List Resource:
google_compute_backend_bucket_signed_url_key(#28357) - New List Resource:
google_compute_backend_service_signed_url_key(#28357) - New List Resource:
google_compute_network_firewall_policy(#28357) - New List Resource:
google_compute_network_firewall_policy_association(#28357) - New List Resource:
google_compute_network_firewall_policy_packet_mirroring_rule(#28357) - New List Resource:
google_compute_preview_feature(#28357) - New List Resource:
google_compute_public_advertised_prefix(#28357) - New List Resource:
google_compute_region_backend_bucket(#28357) - New List Resource:
google_compute_region_network_firewall_policy(#28357)
IMPROVEMENTS:
- accesscontextmanager: added
allowed_service_patternsandservice_patterns_enforcement_scopesfields togoogle_access_context_manager_service_perimeterto support VPC Service Controls for non-GCP APIs. (#28349) - accesscontextmanager: added
pscEndpointtosourcesiningress_fromandegress_fromunder resourcesgoogle_access_context_manager_service_perimeterand variants (#28307) - backupdr: added
backup_blocked_by_vault_access_restrictiontodata.google_backup_dr_data_sourceresource (#28361) - backupdr: added
force_update_access_restrictiontogoogle_backup_dr_backup_vaultresource (#28361) - backupdr: added update support for
access_restrictiontogoogle_backup_dr_backup_vaultresource (#28361) - certificatemanager: added in-place update support for the
self_managedcertificate data (pem_certificate/pem_private_key) ongoogle_certificate_manager_certificate; changing the certificate data is now applied via update instead of forcing recreation (#28337) - cloudrunv2: added
tagsfield togoogle_cloud_run_v2_serviceandgoogle_cloud_run_v2_jobresources to allow setting tags for services and jobs at creation time. (#28328) - cloudsql: added
max_custom_on_demand_retention_daysto create backup_plan example for sqladmin (#28343) - compute: added 3500GB and 7000GB SSD partition size to
google_compute_instance_templateresource (#28352) - compute: added
FLEX_STARTandRESERVATION_BOUNDsupport togoogle_compute_instance,google_compute_instance_template, andgoogle_compute_region_instance_templateresources (#28365) - container: added the support for updating
node_image_configandimage_typefields at the same time (#28283) - dataproc: added
confidential_instance_typetogoogle_dataproc_clusterresource (#28371) - dataproc: added
instance_selection.disk_configfield togoogle_dataproc_clusterresource (#28339) - discoveryengine: added
enable_llm_layout_parsingandenable_get_processed_documentfields togoogle_discovery_engine_data_storeresource (#28284) - sql: added
instance_auto_dns_statusandwrite_endpoint_auto_dns_statusoutput fields topsc_auto_connectionsblock ingoogle_sql_database_instanceresource (#28331) - sql: added
include_replicas_for_major_version_upgradefield togoogle_sql_database_instanceresource (#28345) - sql: added
switch_transaction_logs_to_cloud_storage_enabledfield togoogle_sql_database_instanceresource (#28318) - vertexai: promoted
google_vertex_ai_semantic_governance_policy_engineresource to GA (#28347) - workbench: added
enable_deletion_protectionfield togoogle_workbench_instanceresource (#28355) - workbench: added
resource_policiesfield togoogle_workbench_instanceresource (#28354) - workbench: added support for
min_cpu_platformingoogle_workbench_instanceresource (#28369) - workstations: added
instance_metadatafield togoogle_workstations_workstation_configresource (#28342)
BUG FIXES:
- compute: fixed bug where a permadiff on
google_compute_reservation_region_commitment.existing_reservationswould persist after upgrading (#28353) - compute: fixed permadiff on
keepalive_intervalforgoogle_compute_routerbgpblock when set to default value (#28285) - resourcemanager: fixed validation of
target_service_accountanddelegatesin thegoogle_service_account_access_token,google_service_account_id_token, andgoogle_service_account_jwtdata sources, and ofnamein thegoogle_service_account_keydata source, to reject identifiers that contain path separators (#28308) - securityposture: fixed a bug where the
enforcefield ingoogle_securityposture_posturewas always set, causing failures for list constraints. (#28359) - vmwareengine: added correct
update_maskvalue togoogle_vmwareengine_private_cloudupdates (#28360)
7.40.0 (July 14, 2026)
DEPRECATIONS:
- storage: the
admit-on-second-missvalue forgoogle_storage_anywhere_cache.admission_policyis deprecated and will be removed in a future major release. The backend will ignore this attribute and treat it asadmit-on-first-miss. (#28210)
NOTES:
- compute: migrated
google_compute_instancecode related to advanced machine features to use direct HTTP rather than a client library (#28160)
FEATURES:
- New Data Source:
google_data_catalog_taxonomy(#28237) - New Data Source:
google_oracle_database_exascale_db_storage_vault(#28260) - New List Resource: 'google_project' (#28041)
- New List Resource:
google_compute_instant_snapshot(#28256) - New List Resource:
google_compute_region_instant_snapshot(#28256) - New List Resource:
google_compute_region_target_http_proxy(#28256) - New List Resource:
google_compute_region_target_tcp_proxy(#28256) - New List Resource:
google_compute_region_url_map(#28256) - New List Resource:
google_compute_rollout_plan(#28256) - New List Resource:
google_compute_target_grpc_proxy(#28256) - New List Resource:
google_compute_target_http_proxy(#28256) - New List Resource:
google_compute_target_ssl_proxy(#28256) - New List Resource:
google_compute_target_tcp_proxy(#28256) - New List Resource:
google_dns_managed_zone(#28257) - New List Resource:
google_oracle_database_exascale_db_storage_vaults(#28260) - New Resource:
google_chronicle_findings_refinement_deployment(#28240) - New Resource:
google_chronicle_soar_domain(#28214) - New Resource:
google_iap_agent_registry_agent_iam_binding(#28231) - New Resource:
google_iap_agent_registry_agent_iam_member(#28231) - New Resource:
google_iap_agent_registry_agent_iam_policy(#28231) - New Resource:
google_iap_agent_registry_endpoint_iam_binding(#28231) - New Resource:
google_iap_agent_registry_endpoint_iam_member(#28231) - New Resource:
google_iap_agent_registry_endpoint_iam_policy(#28231) - New Resource:
google_iap_agent_registry_mcp_server_iam_binding(#28231) - New Resource:
google_iap_agent_registry_mcp_server_iam_member(#28231) - New Resource:
google_iap_agent_registry_mcp_server_iam_policy(#28231) - New Resource:
google_tags_tag_binding_collection(#28180) - New Resource:
google_vector_search_index(#28238) - New Resource:
google_chronicle_environment(#28206) - New Resource:
google_chronicle_data_export(#28239)
IMPROVEMENTS:
- agentregistry: added
namefield togoogle_agent_registry_bindingresource (#28207) - agentregistry: added
namefield togoogle_agent_registry_serviceresource (#28207) - appengine: added
app_engine_bundled_servicesfield togoogle_app_engine_standard_app_versionresource (#28213) - biglakeiceberg: add support for
CATALOG_TYPE_FEDERATEDwithfederated_catalog_optionstogoogle_biglake_iceberg_catalog(#28241) - compute: added
target_typeandtarget_forwarding_rulestogoogle_compute_region_network_firewall_policy_with_rulesresource (#28061) - compute: added
workload_identity_configfields togoogle_compute_instanceandgoogle_compute_instance_templateresources (#28266) - compute: added
instance_lifecycle_policy.on_repair.allow_changing_zonefield togoogle_compute_instance_group_managerandgoogle_compute_instance_region_group_manager. (#28174) - container: added
ANY_RESERVATION_THEN_FAILoption toconsume_reservation_typefield ingoogle_container_clusterandgoogle_container_node_poolresources (#28060) - container: added
custom_node_initconfiguration block tonode_config(supporting Cloud Storage and Secret Manager) for bothgoogle_container_clusterandgoogle_container_node_poolresources. (#28262) - container: added
maintenance_policyfield togoogle_container_node_poolresource (#28217) - container: added
recurring_maintenance_windowfield togoogle_container_clusterresource (#28227) - dataplex: added
catalog_publishing_enabledfield togoogle_dataplex_datascanresource (#28232) - dlp: added
inspect_config.min_likelihood_per_info_typetogoogle_data_loss_prevention_inspect_template(#28236) - firestore: added
skip_waitfield togoogle_firestore_fieldresource, skipping the wait for index creation (#28222) - oracledatabase: added support for configuring Exascale-based VM clusters on top of dedicated storage vaults via the
exascale_db_storage_vaultparameter andstorage_management_typeto determine if VM Cluster is ASM or EXASCALE ingoogle_oracle_database_cloud_vm_cluster(#28197) - oracledatabase: added
exadata_infrastructurefield togoogle_oracle_database_exascale_db_storage_vaultresource (#28177) - oracledatabase: added
exascale_db_storage_vaultandstorage_management_typefields togoogle_oracle_database_cloud_vm_clustersdata source (#28260) - sql: added
enforce_new_sql_network_architecturefield togoogle_sql_database_instanceresource (#28233) - sql: added
psc_auto_connection_policy_enabledfield and output-onlyservice_connection_policyandservice_connection_policy_creation_resultfields togoogle_sql_database_instanceresource (#28225) - storagetransfer: added
private_network_serviceto resourcegoogle_storage_transfer_job(#28178)
BUG FIXES:
- bigtable: fixed a bug where
row_affinityupdates did not persist ongoogle_bigtable_app_profile(#28215) - bug: fixed labels diff in
google_project(#28229) - chronicle: suppressed a permadiff on
google_chronicle_rule.textcaused by the Chronicle API appending a trailing newline to every stored rule body (#28216) - cloudscheudler: added retries for "409: sync mutate calls cannot be queued" error for
google_cloud_scheduler_job(#28164) - compute: fixed an issue where
preview = falseupdates forgoogle_compute_organization_security_policy_rulewere omitted from API requests. (#28223) - compute: fixed bug where it wasn't possible to disable
enable_proxy_protocolongoogle_compute_service_attachmentresource (#28264) - datastream: fixed a bug in update functionality in
google_datastream_connection_profilemongodb_profile.additional_options(#28254) - eventarc: fixed a type mismatch when an
google_eventarc_triggerresource returns non-emptyconditions. (#28226) - filestore: aligned
google_filestore_instanceresource timeouts with the Filestore service instance operations TTLs (#28208) - gemini: fixed truncated timeouts in
google_gemini_code_tools_setting,google_gemini_data_sharing_with_google_setting_binding,google_gemini_gemini_gcp_enablement_setting_binding, andgoogle_gemini_release_channel_setting_binding(#28220) - hypercomputecluster: fixed 20-minute timeout limit during
google_hypercomputecluster_clusterresource creation (#28182) - logging: fixed an issue where errors on update would not be propagated in
google_logging_project_bucket_config(#28055) - observability: fixed unintentionally long timeouts in
google_observability_folder_settings,google_observability_organization_settings, andgoogle_observability_project_settings(#28220) - oracledatabase: fixed early client-side timeouts and aligned default schema timeouts with backend async polling limits on
google_oracle_database_exadb_vm_cluster,google_oracle_database_odb_network,google_oracle_database_odb_subnet,google_oracle_database_goldengate_connection,google_oracle_database_goldengate_deployment, andgoogle_oracle_database_goldengate_connection_assignment. (#28228) - oracledatabase: fixed truncated timeouts in
google_oracle_database_exadb_vm_cluster,google_oracle_database_goldengate_connection, andgoogle_oracle_database_odb_subnet(#28220) - privilegedaccessmanager: fixed a permadiff on
google_privileged_access_manager_entitlementfor entitlements created without an approval workflow (#28224) - provider: fixed validation of
external_credentials.identity_tokento reject malformed JWTs containing empty segments (#28258)
7.39.0 (June 30, 2026)
NOTES:
- compute: migrated
google_compute_instance_templateresource partially to use direct HTTP rather than a client library (#28010) - compute: migrated
google_compute_network_peeringresource to use direct HTTP rather than a client library (#28021) - compute: migrated metadata handling to use direct HTTP rather than a client library (#27968)
FEATURES:
- New Data Source:
google_agent_registry_agent(#28028) - New Data Source:
google_agent_registry_endpoint(#28028) - New Data Source:
google_agent_registry_mcp_server(#28028) - New Data Source:
google_compute_instance_groups(#27981) - New Data Source:
google_storage_control_folder_intelligence_findings_summary(#28019) - New Data Source:
google_storage_control_organization_intelligence_findings_summary(#28019) - New Data Source:
google_storage_control_project_intelligence_findings_summary(#28019) - New Resource:
google_agent_registry_binding(#28028) - New Resource:
google_agent_registry_service(#28028) - New Resource:
google_artifact_registry_project_config(#28009) - New Resource:
google_chronicle_findings_refinement(#28035) - New Resource:
google_compute_bulk_per_instance_config(#28031) - New Resource:
google_compute_firewall_policy_iam_binding(#27978) - New Resource:
google_compute_firewall_policy_iam_member(#27978) - New Resource:
google_compute_firewall_policy_iam_policy(#27978) - New Resource:
google_compute_network_firewall_policy_iam_binding(#27978) - New Resource:
google_compute_network_firewall_policy_iam_member(#27978) - New Resource:
google_compute_network_firewall_policy_iam_policy(#27978) - New Resource:
google_compute_region_network_firewall_policy_iam_binding(#27978) - New Resource:
google_compute_region_network_firewall_policy_iam_member(#27978) - New Resource:
google_compute_region_network_firewall_policy_iam_policy(#27978) - New Resource:
google_compute_region_resize_request(#27984) - New Resource:
google_compute_zone_vm_extension_policy(#28034) - New Resource:
google_gke_hub_rollout_sequence(#28007) - New Resource:
google_iap_agent_registry_iam_binding(#28032) - New Resource:
google_iap_agent_registry_iam_member(#28032) - New Resource:
google_iap_agent_registry_iam_policy(#28032) - New Resource:
google_iap_location_web_iam_binding(#28032) - New Resource:
google_iap_location_web_iam_member(#28032) - New Resource:
google_iap_location_web_iam_policy(#28032) - New Resource:
google_oracle_database_cloud_exadata_infrastructure_exascale_config(#28033) - New List Resource:
google_bigquery_dataset(#28005) - New List Resource:
google_compute_cross_site_network(#28018) - New List Resource:
google_compute_external_vpn_gateway(#28018) - New List Resource:
google_compute_global_network_endpoint_group(#28018) - New List Resource:
google_compute_ha_vpn_gateway(#28018) - New List Resource:
google_compute_interconnect_attachment_group(#28018) - New List Resource:
google_compute_interconnect_group(#28018) - New List Resource:
google_compute_public_delegated_prefix(#28018) - New List Resource:
google_compute_region_commitment(#28018) - New List Resource:
google_compute_region_network_endpoint_group(#28018) - New List Resource:
google_compute_vpn_gateway(#28018) - New List Resource:
google_compute_wire_group(#28018) - New List Resource:
google_folder_iam_member(#27993) - New List Resource:
google_kms_crypto_key_version(#28006) - New List Resource:
google_project(#28041) - New List Resource:
google_project_service(#27989)
IMPROVEMENTS:
- bigquery: added
external_runtime_options.container_request_concurrencyfield togoogle_bigquery_routineresource (#28029) - compute: added
instance_lifecycle_policy.on_failed_health_checkfield in resourcesgoogle_compute_instance_group_managerandgoogle_compute_region_instance_group_manager(ga) (#27992) - container: added new fields
shutdown_grace_period_secondsandshutdown_grace_period_critical_pods_secondstonode_kubelet_configblock. (#28015) - container: promoted
agent_sandbox_configaddon field underaddons_configingoogle_container_clusterto GA (#28017) - dataplex: added
iconfield togoogle_dataplex_data_productresource (#27986) - dataplex: added
namefield togoogle_dataplex_data_product_data_assetresource (#28020) - dlp: added
allow_limited_availability_info_typestogoogle_data_loss_prevention_inspect_template(#28024) - networkservices: added
forward_attributesfield togoogle_network_services_lb_edge_extension,google_network_services_lb_route_extension, andgoogle_network_services_lb_traffic_extensionresources (#28012)
BUG FIXES:
- compute: fixed a panic in
google_compute_project_metadataandgoogle_compute_project_metadata_itemwhen project common instance metadata items contain null/empty values. (#28008) - compute: fixed a validation error on
google_compute_instance(Provisioned IOPS cannot be specified with disk type pd-balanced) that occurred during updates on instances with Hyperdisk Balanced boot disks. (#27975) - dataproc: fixed a bug where changing
policy_idongoogle_dataproc_autoscaling_policyplanned an in-place update and failed; it now correctly forces resource replacement (destroy and recreate). (#28036) - firestore: added retries on 409 errors in
google_firestore_user_credsresource (#27972) - iam: fixed ephemeral
google_service_account_keyproducing a 404 due to duplicate/keysin the URL whenfetch_key = trueandnameis provided (#27980)
7.38.0 (June 23, 2026)
NOTES:
- bigquery: migrated
google_bigquery_tableresource to use direct HTTP rather than a client library (#27909) - compute: migrated
resource_compute_instance_template_test.go.tmplresource to use direct HTTP rather than a client library (#27859) - compute: migrated
google_compute_resource_compute_instanceto use direct HTTP rather than a client library (#27925) - compute: migrated parts of
google_compute_instanceand shared instance functions to use direct HTTP (#27815)
FEATURES:
- New Data Source:
google_storage_control_project_intelligence_finding_revision(#27912) - New Data Source:
google_storage_control_project_intelligence_finding_revisions(#27912) - New Resource:
google_biglake_hive_catalog(#27892) - New Resource:
google_chronicle_feed(#27860) - New Resource:
google_chronicle_parser_extension(#27906) - New Resource:
google_dataplex_metadata_feed(#27934) - New Resource:
google_network_services_agent_gateway(#27803) - New Resource:
google_vertex_ai_schedule(#27895) - New Resource:
google_vertex_ai_tensorboard_run(#27913) - New List Resource:
google_compute_address(#27917) - New List Resource:
google_compute_cross_site_network(#27864) - New List Resource:
google_compute_https_health_check(#27917) - New List Resource:
google_compute_node_template(#27917) - New List Resource:
google_compute_packet_mirroring(#27917) - New List Resource:
google_compute_region_autoscaler(#27917) - New List Resource:
google_compute_region_composite_health_check(#27917) - New List Resource:
google_compute_region_health_aggregation_policy(#27917) - New List Resource:
google_compute_region_health_source(#27917) - New List Resource:
google_project_iam_member(#27905) - New List Resource:
google_pubsub_topic(#27914) - New List Resource:
google_secret_manager_secret(#27910)
IMPROVEMENTS:
- apigee: added
consumer_keyandconsumer_secretfields togoogle_apigee_developer_appto allow specifying a static credential (#27820) - artifactregistry: added update support for
upstream_credentialstogoogle_artifact_registry_repository(#27819) - biglakeiceberg: added
CATALOG_TYPE_BIGLAKEenum tocatalog_typefield and addedrestricted_locations_config.restricted_locationsfield ingoogle_biglake_iceberg_catalogresource (#27930) - biglakeiceberg: added
sort_orderfield togoogle_biglake_iceberg_tableresource (#27865) - ces: added
timeoutandtool_fake_configfields togoogle_ces_toolandgoogle_ces_toolsetresource (#27907) - compute: added
params.resource_manager_tagsfield togoogle_compute_snapshotresource (#27869) - compute: made
network_endpoints.ip_addressoptional ingoogle_compute_network_endpointsresource to support attaching endpoints to a network endpoint group of typeGCE_VM_IP_DEDICATED_BACKEND(#27870) - container: added
dataplane_optimization_modeingoogle_container_cluster(#27861) - container: added
ignore_node_count_changesfield togoogle_container_clusterandgoogle_container_node_poolresources. When set to true, the provider ignores drift via external node count changes and skips related IGM API queries, resolving long plan times on clusters with a large number of instance groups. (#27896) - container: added
skip_node_pool_refreshfield togoogle_container_clusterresource. When set to true, thegoogle_container_clusterskips refreshing and settingnode_poolsfrom the API, resolving long plan times on clusters with a large number of node pools. Note that this results innode_poolsbeing set to an empty list in state (#27896) - container: added
taint_configblock togoogle_container_clusterandgoogle_container_node_pool(#27884) - container: improved GKE node pool read performance by caching instance group metadata longer (#27896)
- datastream: added
additional_optionsfield togoogle_datastream_connection_profileresource (#27915) - iamworkforcepool: write-only support for
oidc.client_secretingoogle_iam_workforce_pool_provider(#27867) - kms: added resource identity support for
google_kms_crypto_key_versionresource (#27883) - networkservices: added
dns_peering_configfield togoogle_network_services_agent_gatewayresource (#27813) - sql: added
mode,dns_servers,admin_credential_secret_name, andorganizational_unitfields toactive_directory_configblock ingoogle_sql_database_instanceresource for SQL Server instances (#27862) - storage: added
lifecycle_rule.condition.size_above_bytesandlifecycle_rule.condition.size_below_bytesfields togoogle_storage_bucketresource (#27857)
BUG FIXES:
- apigee:
google_apigee_developer_appnow updatesapi_productsandscopeson the existing credential instead of creating a new credential (consumer key) on update (#27929) - biglake: allow
locationto be set ongoogle_biglake_iceberg_namespace(#27814) - biglake: fixed creation failure of
google_biglake_iceberg_tableresource when the referencedgoogle_biglake_iceberg_cataloghascredential_modeset toCREDENTIAL_MODE_VENDED_CREDENTIALSdue to a missingX-Iceberg-Access-Delegationheader (#27903) - compute: fixed broken import of
share_settingsongoogle_compute_reservation(#27916) - datastream: fixed a positional diff when adding objects to the
salesforce_source_config.include_objectsfield ingoogle_datastream_streamresource (#27926) - iamworkforcepool: marked sensitive and ignore_read as true for
security_tokeningoogle_iam_workforce_pool_provider_scim_tokenresource (#27812) - networkconnectivity: fixed
google_network_connectivity_regional_endpointbeing recreated on every apply whenaddressis set to a resource URI (#27923) - networkservices: fixed
namefield expansion forgoogle_network_services_agent_gatewayresources so that short names are automatically expanded to full resource names, preventing API validation errors on create and update. (#27902)
7.37.0 (June 16, 2026)
NOTES:
- compute: migrated
EnableDisplayfields ingoogle_compute_instanceresources to use direct HTTP rather than a client library (#27778) - compute: migrated
desired_statusblock andstartInstanceOperationinresource_compute_instance.go.tmplto use direct HTTP rather than a client library (#27755) - compute: migrated
getInstance,getDisk,Deleteand thesetMetadataupdate block inresource_compute_instance.go.tmplto use direct HTTP rather than a client library (#27716) - compute: migrated part of
google_compute_instanceto use direct HTTP rather than a client library (#27788)
DEPRECATIONS:
- cloudrunv2: deprecated
http_get.http_headers.portfield in container startup probe and liveness probe ingoogle_cloud_run_v2_worker_poolresource because it is not supported in Cloud Run API. This field will be removed in a future major release. (#27800) - cloudsecuritycompliance: deprecated the
organizationfield ongoogle_cloud_security_compliance_cloud_control,google_cloud_security_compliance_framework, andgoogle_cloud_security_compliance_framework_deployment. Useparentinstead (#27769) - networkservices: deprecated
protocolsongoogle_network_services_agent_gateway(#27802)
FEATURES:
- New Data Source:
google_oracle_database_goldengate_deployment_versions(#27771) - New Data Source:
google_storage_control_project_intelligence_finding(#27764) - New Data Source:
google_storage_control_project_intelligence_findings(#27764) - New Resource:
google_chronicle_parser(#27801) - New Resource:
google_migration_center_import_data_file(#27721) - New Resource:
google_network_services_agent_gateway(#27803) - New Resource:
google_vertex_ai_tensorboard_experiment(#27796) - New List Resource:
google_bigquery_dataset_access(#27758) - New List Resource:
google_cloud_scheduler_job(#27758) - New List Resource:
google_dns_record_set(#27792) - New List Resource:
google_monitoring_alert_policy(#27758) - New List Resource:
google_pubsub_subscription(#27758)
IMPROVEMENTS:
- apigee: added new resource
google_apigee_environment_debugmaskfor managing Apigee environment debug masks (#27719) - backupdr: added support for
use_project_service_accountflag ingoogle_backup_dr_restore_workloaddisk and compute restores (#27797) - cloudrunv2: added
http_get.http_headers.namefield to container startup probe and liveness probe ingoogle_cloud_run_v2_worker_poolresource (#27800) - cloudrunv2: added
template.clientandtemplate.client_versionfields togoogle_cloud_run_v2_worker_poolresource (#27757) - cloudsecuritycompliance: added support for project parent to
google_cloud_security_compliance_cloud_control,google_cloud_security_compliance_framework, andgoogle_cloud_security_compliance_framework_deploymentvia the newparentfield. Theorganizationfield has been deprecated. (#27769) - compute: added
params.resource_manager_tagsfield togoogle_compute_reservationresource (#27770) - compute: added data sources for
google_compute_target_http_proxy,google_compute_target_https_proxy,google_compute_region_target_http_proxy, andgoogle_compute_region_target_https_proxy(#27767) - container: added
addons_config.slurm_operator_configfield togoogle_container_clusterresource (#27765) - container: added
node_image_configfield togoogle_container_node_poolandgoogle_container_clusterresources (#27794) - databasemigrationservice: added
stateandstop_on_warningsfields togoogle_database_migration_service_migration_jobresource (#27731) - dns: added resource identity support for
google_dns_record_setresource (#27792) - networksecurity: added
network_rulesfield ongoogle_network_security_authz_policyresource (#27821) - pubsub: added
first_revision_idandlast_revision_idfields togoogle_pubsub_topicresource (#27718) - sql: added
settings.ip_configuration.psc_config.psc_auto_dns_enabledandsettings.ip_configuration.psc_config.psc_write_endpoint_dns_enabledfields togoogle_sql_database_instanceresource (#27776)
BUG FIXES:
- apigee: fixed
google_apigee_apinot detecting local bundle changes due to a missing default ondetect_md5hash, and fixed the test sweeper's list URL (#27791) - apigee: fixed
google_apigee_security_actionupdate failure by enabling PATCH-based updates now that the Apigee Security Actions API supports mutations (#27768) - apigee: fixed a perma-diff for
api_productsandscopesfields ingoogle_apigee_developer_appresource when updating them with multiple items (#27789) - apigee: fixed an issue where the resource would attempt recreation if the
key_expires_infield was set ingoogle_apigee_developer_appresource (#27779) - ces: fixed persistent diff in
google_ces_guardrailwhenllm_prompt_securityis configured withdefault_settings(#27766) - cloudrun: fixed a permadiff for the
run.googleapis.com/gpu-zonal-redundancy-disabledannotation ingoogle_cloud_run_service(#27787) - cloudrunv2: fixed bug where only one
http_get.http_headersblock could be specified in container startup probe and liveness probe ingoogle_cloud_run_v2_worker_poolresource (#27800) - compute: fixed an issue in
google_compute_subnetworkwheresecondary_ip_rangeentries linked to aninternal_rangecould not be removed and adding new ranges would sometimes fail due to positional shifts (#27175) (#27720) - compute: fixed diff when using
existing_reservationsfield ingoogle_region_commitment(#27775) - compute: fixed rules in
google_compute_security_policybeing unnecessarily recreated due to TypeSet hash instability (#27754) - sql: fixed inconsistent result after apply error when adding
usersof typeCLOUD_IAM_GROUPwith capitalized domain names for MySQL (#27784) - storage: fixed OOM issue for
google_storage_bucketforce_destroyby limiting the number of outstanding tasks to 2000 (#27777)
7.36.0 (June 9, 2026)
FEATURES:
- New Data Source:
google_apigee_instance(#27683) - New Data Source:
google_oracle_database_goldengate_deployment_types(#27634) - New Resource:
google_apigee_datastore(#27607) - New Resource:
google_discovery_engine_search_engine_iam_binding(#27703) - New Resource:
google_license_manager_configuration(#27707) - New Resource:
google_migration_center_import_job(#27599) - New List Resource:
google_compute_disk(#27608) - New List Resource:
google_compute_image(#27608) - New List Resource:
google_compute_snapshot(#27608) - New List Resource:
google_storage_hmac_key(#27637)
IMPROVEMENTS:
- accesscontextmanager: added in-place update for
egress_fromandegress_tofields ingoogle_access_context_manager_service_perimeter_egress_policyresource (#27690) - accesscontextmanager: added in-place update for
egress_fromandegress_tofields ingoogle_access_context_manager_service_perimeter_ingress_policyresource (#27690) - bigquery: added IAM support (
google_bigquery_routine_iam_policy,google_bigquery_routine_iam_binding,google_bigquery_routine_iam_member) forgoogle_bigquery_routineresource (#27704) - bigtable: added
automated_backup_policy.locationsfield ingoogle_bigtable_tableresource (#27646) - ces: added
agent_tool,file_search_tool, andwidget_toolfields to thegoogle_ces_toolresource (#27681) - ces: added
google_search_tool.prompt_configanddata_store_tool.data_store_sourcefields to thegoogle_ces_toolresource (#27681) - ces: exposed
remote_agent_tool,connector_tool, andmcp_toolas read-only (output-only) attributes ingoogle_ces_tool(#27681) - container: added
node_creation_configfield togoogle_container_clusterresource (#27702) - container: added
node_drain_config.pdb_timeout_durationandnode_drain_config.grace_termination_durationfields togoogle_container_node_poolandgoogle_container_clusterresources (#27694) - data_catalog: added
RICHTEXTto allowed values ofprimitive_typeongoogle_data_catalog_tag_templatefields. (#27672) - dataplex: added IAM support for
google_dataplex_data_productresource (iam_policy,iam_binding,iam_member) (#27652) - dataplex: added
access_approval_configfield togoogle_dataplex_data_productresource (#27652) - hypercomputecluster: marked
network_resourcesfield as required ingoogle_hypercomputecluster_clusterresource to align with API validation (#27655) - networksecurity:
google_network_security_ull_mirroring_engine,google_network_security_ull_mirroring_collector, andgoogle_network_security_ull_mirroring_collector_ruleresources promoted to GA (#27710) - securesourcemanager: added
psc_allowed_projectsfield togoogle_secure_source_manager_instanceresource (#27695) - workbench: added
NVIDIA_RTX6000to the supportedgce_setup.accelerator_configs.typevalues ongoogle_workbench_instanceresource(#27709)
BUG FIXES:
- apigee: send zero values for
ip_header_indexingoogle_apigee_environmentresource (#27670) - backupdr: fixed an issue where
google_backup_dr_restore_workloaddid not use the correct API JSON names for networking/reservation fields (#27680) - compute: fixed an issue where updating
connection_limitin theconsumer_accept_listsblock ofgoogle_compute_service_attachmentwould not trigger a resource update. (#27688) - compute: fixed regional backend reference in
google_compute_regional_url_mapresource (#27705) - dlp: fixed error when reading
google_data_loss_prevention_discovery_configcaused by nested error details (#27669) - sql: fixed permadiff on
connection_pool_configwhenconnection_pooling_enabledis set tofalse(#27711) - tags: fixed
google_tags_location_tag_bindingfailing withOperation location does not match service location 'global'during creation (#27668) - vertexai: fixed
terraform importofgoogle_vertex_ai_index_endpoint_deployed_indexfailing with "Cannot determine region" when provider-levelregion/zoneis unset (#27692)
7.35.0 (June 2, 2026)
FEATURES:
- New Data Source:
google_oracle_database_goldengate_connection_types(#27567) - New Resource:
google_chronicle_findings_refinement(#27591) - New Resource:
google_dataplex_data_product(#27588) - New Resource:
google_dataplex_data_product_data_asset(#27588) - New Resource:
google_migration_center_discovery_client(#27572) - New Resource:
google_migration_center_report(#27548) - New Resource:
google_oracle_database_goldengate_connection_assignment(#27566) - New Resource:
google_oracle_database_goldengate_connection(#27587) - New Resource:
google_oracle_database_goldengate_deployment(#27575) - New List Resource:
google_compute_firewall(#27549) - New List Resource:
google_compute_global_address(#27549) - New List Resource:
google_compute_subnetwork(#27549) - New List Resource:
google_sql_database(#27552)
IMPROVEMENTS:
- compute: added
target_typeandtarget_forwarding_rulesfields togoogle_compute_network_firewall_policy_ruleresource (#27538) - container: added
crash_loop_back_off.max_container_restart_periodfield togoogle_container_node_poolandgoogle_container_clusterresources (#27574) - container: added additional value
KCP_VPAforlogging_config.enable_componentsfield togoogle_container_clusterresource (#27546) - dataplex: added
service_accountsupport togoogle_dataplex_data_productaccess group principals (#27588) - firestore: added
ttl_config.expiration_offsetfield togoogle_firestore_fieldresource (#27589) - netapp: added
ontap_sourcefield togoogle_netapp_backupresource (#27584) - networkmanagement: added
gke_podandnetwork_typefields togoogle_network_management_connectivity_testresource (#27585)
BUG FIXES:
- resourcemanager: fixed a bug where ephemeral
google_service_account_keyfailed on deletion if the parent service account had already been deleted (#27541) - storage: fixed missing identity error when updating values in
google_storage_bucket(#27605)
7.34.0 (May 27, 2026)
NOTES:
- compute: migrated
google_compute_region_instance_templateto use direct HTTP rather than a client library (#27471) - compute: migrated
google_compute_instance_group_managerresource to use direct HTTP rather than a client library (#27441)
FEATURES:
- New Data Source:
google_compute_service_attachment(#27526) - New Data Source:
google_oracle_database_goldengate_deployment_environments(#27499) - New Resource:
google_config_deployment(#27438) - New Resource:
google_dialogflow_sip_trunk(#27468) - New Resource:
google_migration_center_assets_export_job(#27466) - New Resource:
google_migration_center_report_config(#27395) - New Resource:
google_migration_center_settings(#27465) - New Resource:
google_migration_center_source(#27496)
IMPROVEMENTS:
- bigtable: added
editionfield togoogle_bigtable_instanceresource (#27507) - ces: added
fail_openfield tollm_prompt_securityblock ingoogle_ces_guardrailresource (#27497) - ces: added read-only
fail_openfield tollm_prompt_securityblock ingoogle_ces_app_versionresource (#27497) - compute: added
ip_versionandip_collectionfields tosecondary_ip_rangefield ingoogle_compute_subnetworkresource (#27432) - compute: added
post_quantum_key_exchangefield togoogle_compute_ssl_policyandgoogle_compute_region_ssl_policyresources (#27479) - compute: added support in the
google_compute_networkdatasource for looking up a network byself_linkin addition toname(#27509) - container: added
agent_sandbox_configfield togoogle_container_clusterresource (#27482) - container: added
node_config.gpudirect_strategyandnode_pool.node_config.gpudirect_strategytoclusterresource, addednode_config.gpudirect_strategytonode_poolresource (#27495) - dataflow: Added
create_ignore_already_existsfield togoogle_dataflow_flex_template_jobresource to handle 409 conflicts (#27476) - datafusion: added
maintenance_policyfield togoogle_data_fusion_instanceresource (#27470) - iam: add resource identity support for
iam_memberresources (#27383) - networkconnectivity:
google_network_connectivity_transportresource promoted to GA (#27440) - oracledatabase: added
identity_connectortogoogle_oracle_database_cloud_vm_clusterfor CMEK support (#27435) - project: added Resource Identity support to
google_project_iam_binding(#27502) - project: added Resource Identity support to
google_project_iam_policy(#27503) - sql: promoted Hyperdisk fields,
data_disk_provisioned_iopsanddata_disk_provisioned_throughputto GA (#27437)
BUG FIXES:
- bigtable: fixed an issue where
bigtable_custom_endpointanduniverse_domainwere ignored when creating Bigtable resources. (#27515) - compute: fixed an issue in
google_compute_subnetworkwheresecondary_ip_rangeentries linked to aninternal_rangecould not be removed and adding new ranges would sometimes fail due to positional shifts (#27175) (#27512) - compute: marked encryption keys as immutable and sensitive across compute and backupdr resources (#27508)
- dialogflow: corrected
AUDIOENCODING_SPEEX_WITH_HEADER_BYTEenum value toAUDIO_ENCODING_SPEEX_WITH_HEADER_BYTEforaudio_encodingfield ingoogle_dialogflow_conversation_profileresource (#27459) - resourcemanager: resolved a one-time diff for
deletion_policythat would occur on existing and importedgoogle_project_serviceresources following upgrading to v7.32.0 (#27484)
7.33.0 (May 19, 2026)
NOTES:
- compute: migrated
google_compute_target_poolresource to use direct HTTP rather than a client library (#12212) - compute: migrated
google_compute_instance_group_managerresource to use direct HTTP rather than a client library (#12206) - compute: migrated
google_compute_project_default_network_tierresource to use direct HTTP rather than a client library (#12201) - compute: migrated
google_compute_router_statusdata source to use direct HTTP rather than a client library (#12174) - compute: migrated
google_compute_instance_group_managerresource to use direct HTTP rather than a client library (#12216) - compute: partially migrated
google_compute_instanceresource to use direct HTTP rather then a client library (#12205)
FEATURES:
- New Data Source:
google_logging_log_view(#12226) - New Resource:
google_apigee_data_collector(#12190) - New Resource:
google_chronicle_native_dashboard(ga) (#12188) - New Resource:
google_contact_center_insights_encryption_spec(#12225)
IMPROVEMENTS:
- backupdr: added
guest_flushfield togoogle_backup_dr_backup_planresource andgoogle_backup_dr_backupdata source. (#12229) - backupdr: added
guest_flushfield togoogle_backup_dr_backup_planresource andgoogle_backup_dr_backupdata source. (#12230) - ces: added
security_settingsfield togoogle_ces_deploymentresource (#12227) - ces: added
tool_execution_modefield togoogle_ces_appresource (#12221) - compute: added
stabilization_periodfield togoogle_compute_autoscalerandgoogle_compute_region_autoscalerresources (#12232) - compute: added support for "ARP_BROADCAST_PRIMARY_RANGE" values to the
resolve_subnet_maskfield ingoogle_compute_subnetworkresource (#12176) - compute: added support for "GCE_VM_IP_DEDICATED_BACKEND" to the
network_endpoint_typefield ingoogle_compute_network_endpoint_groupresource (#12176) - compute: migrated
data_source_google_compute_regionsto use direct HTTP rather than a client library (#12202) - container: added
pod_snapshot_configfield togoogle_container_clusterresource (GA) (#12196) - container: added
secret_sync_configfield togoogle_container_clusterresource (ga) (#12215) - databasemigrationservice: added
databaseandprivate_connectivityfields togoogle_database_migration_service_connection_profileresource (#12203) - databasemigrationservice: added
postgres_homogeneous_configfield togoogle_database_migration_service_migration_jobresource (#12203) - databasemigrationservice: added
psc_interface_configfield togoogle_database_migration_service_private_connectionresource (#12184) - hypercomputecluster: added
terminal_storage_classandper_unit_storage_throughputfields to thegoogle_hypercomputecluster_clusterresource (#12234) - netapp: added
ontap_sourcefield togoogle_netapp_backupresource (beta) (#12231) - provider: support for a
deletion_policyfield has been added to almost all resources in the provider. Details on its usage can be found within individual resource documentation if supported. (#12183) - storagebatchoperations: added
descriptionfield togoogle_storage_batch_operations_jobresource (#12207) - workstations: added
workstation_authorization_urlandworkstation_launch_urlfields to thegoogle_workstations_workstation_clusterresource. (#12185)
BUG FIXES:
- apigee: fixed forced replacement when importing
google_apigee_sharedflow_deploymentresource, whereservice_accountread as null (#12228) - bigqueryconnection: fixed an issue where
configuration.authentication.username_password.password.secret_typeis not populated and a diff onconfiguration.authentication.username_password.usernameafter import ingoogle_bigquery_connectionresource (#12179) - bigqueryreservation: Fixed
google_bigquery_reservation_assignmentreturning a confusing 404 error whenreservationis a bare name andlocationis not set (#12210) - ces: updated supported values for
channel_type,modality, andthemeingoogle_ces_deployment(#12227) - compute: updated
google_compute_forwarding_ruleresource to properly prompt for resource recreation when updating thetargetfield between different "serviceAttachments", rather than having an in-place update blocked by an API error. (#12214) - modelarmor: fixed permadiff and
REQUEST_FIELD_MISSINGerror whentemplate_metadatais omitted fromgoogle_model_armor_template(#12222) - networkconnectivity: fixed an issue where
google_network_connectivity_destinationwas not recognizing thenamefield as mapping to an API value (#12224) - networkconnectivity: fixed an issue where
google_network_connectivity_multicloud_data_transfer_configwas not recognizing thenamefield as mapping to an API value (#12224) - resourcemanager: added verification polling to
google_service_accountupdates to ensure the resource is consistent before succeeding (#12217)
7.32.0 (May 12, 2026)
NOTES:
- compute: migrated
google_compute_instance_from_machineresource to use direct HTTP rather than a client library (#27260) - compute: migrated
google_compute_instance_group_managerresource to use direct HTTP rather than a client library (#27259) - compute: migrated
google_compute_zonesdata source to use direct HTTP rather than a client library (#27261) - compute: migrated
google_compute_project_metadata_itemresource to use direct HTTP rather than a client library (#27200)
FEATURES:
- New Data Source:
google_compute_region_instant_snapshot_iam_policy(#27281) - New Resource:
google_chronicle_dashboard_chart(#27275) - New Resource:
google_compute_region_instant_snapshot_iam_binding(#27281) - New Resource:
google_compute_region_instant_snapshot_iam_member(#27281) - New Resource:
google_compute_region_instant_snapshot_iam_policy(#27281) - New Resource:
google_compute_region_instant_snapshot(#27281)
IMPROVEMENTS:
- compute: added
IDPFvalue tonic_typeinresource_compute_instance_template(#27244) - compute: added
IDPFvalue tonic_typeinresource_compute_instance(#27244) - compute: added
IDPFvalue tonic_typeinresource_compute_region_instance_template(#27244) - compute: added
address_idfield togoogle_compute_addressresource (#27216) - compute: added
advanced_options_configfield ongoogle_compute_organization_security_policyresource (#27255) - compute: added
connection_tracking_policyfield togoogle_compute_region_backend_serviceresource (#27217) - compute: added
image,source_image_encryption_key, andsource_image_idfields togoogle_compute_region_diskresource. This field is currently behind an allowlist. (#27243) - compute: added
replica_zonesfield togoogle_compute_instanceresource (#27258) - compute: added
request_bodyfield ongoogle_compute_security_policy_ruleresource (#27252) - compute: added update support for
ip_collectionfield togoogle_compute_subnetworkresource (#27265) - discoveryengine: added
config_idattribute togoogle_discovery_engine_widget_config(#27278) - networksecurity: added support for project
parentvalues togoogle_network_security_firewall_endpoint(#27222) - recaptchaenterprise: added
POLICY_BASED_CHALLENGEvalue tointegration_typefield and added newchallenge_settingsfield togoogle_recaptcha_enterprise_key(#27221) - redis: added new node types supported in
google_redis_cluster. (#27242) - resourcemanager: add
private_keyandprivate_key_typefields to ephemeralgoogle_service_account_keyresource (#27279) - storage: added
ingest_on_writefield forgoogle_storage_anywhere_cacheresource (#27271) - workstations: added
gce_hdfield togoogle_workstations_workstation_configresource (#27201)
BUG FIXES:
- cloudfunctions2: fixed bug where
all_traffic_on_latest_revision = falsewas ignored ingoogle_cloudfunctions2_function(#27256) - compute: fixed permadiff when removing
preconfigured_waf_configfrom agoogle_compute_security_policyrule (#27276)
7.31.0 (May 5, 2026)
NOTES:
- compute: migrated
google_compute_instance.network_interfacefield to use direct HTTP rather than a client library (#27104) - compute: migrated
google_compute_imagedatasource to use direct HTTP rather then a client library (#27179) - compute: migrated
partner_metadatafield ongoogle_compute_instance,google_compute_instance_template, andgoogle_compute_region_instance_templateto use direct HTTP rather than a client library (#27131) - compute: migrated
google_compute_node_typesdata source to use direct HTTP rather than a client library (#27184) - compute: migrated
google_compute_region_instance_groupdata source to use direct HTTP rather than a client library (#27178) - compute: migrated
google_compute_subnetworkdata source to use direct HTTP rather than a client library (#27167) - compute: migrated
google_compute_vpn_gatewaydata source to use direct HTTP rather than a client library (#27168)
FEATURES:
- New Data Source:
google_artifact_registry_file(#27183) - New Resource:
google_ces_app_root_agent_association(#27123) - New Resource:
google_contact_center_insights_qa_question(#27169) - New Resource:
google_contact_center_insights_qa_scorecard_revision(#27169) - New Resource:
google_contact_center_insights_qa_scorecard(#27169) - New Resource:
google_firebase_app_check_resource_policy(#27185)
IMPROVEMENTS:
- clouddeploy: added
default_poolandprivate_poolfields togoogle_clouddeploy_targetresource (#27187) - clouddeploy: added
tasksandanalysisfields togoogle_clouddeploy_delivery_pipelineresource (#27187) - compute: added
params.resource_manager_tagsfield togoogle_compute_image(#27107) - compute: added
params.resource_manager_tagsfield togoogle_compute_region_commitmentresource (#27181) - compute: added
resource_policies.workload_policytogoogle_compute_region_instance_group_managerresource (#27170) - compute: marked csek disk encryption key fields as sensitive in compute resources (#27193)
- container: added
node_pool.network_config.accelerator_network_profiletogoogle_container_clusterresource andnetwork_config.accelerator_network_profiletogoogle_container_node_poolresource (#27171) - databasemigrationservice: added
objects_configfield togoogle_database_migration_service_migration_jobresource (#27180) - dataplex: added
attributes,template_reference,enable_catalog_basedRules, andfilterfields togoogle_dataplex_datascanresource (#27130) - firestore: added
search_configfield togoogle_firestore_indexresource (#27108) - oracle_database: added
pluggable_database_id,pluggable_database_namefields togoogle_oracle_database_db_systemresource (#27127)
BUG FIXES:
- provider: fixed a bad
timeoutsdiff across a number of resources that had resource identity support added in7.29.0(#27189) - assuredworkloads: made assuredworkloads resources use GA endpoint instead of beta (#27122)
- bigquery: fixed
ignore_auto_generated_schemaevaluation forgoogle_bigquery_tableexternal tables which caused spurious replacement (#27188) - cloudscheduler: fixed perpetual diff on
google_cloud_scheduler_job.http_target.headerswhenoidc_tokenoroauth_tokenis set (#27173) - servicenetworking: fixed a permadiff issue of
reserved_peering_rangesingoogle_service_networking_connection(#27132) - storage: fix inconsistent plan issue for
google_storage_notification.custom_attributesfield (#27129)
7.30.0 (Apr 28, 2026)
BREAKING CHANGES:
- apigee: fixed
google_apigee_env_keystoreto require thenamefield which is mandatory in the Apigee API (#27006)
FEATURES:
- New Data Source:
google_data_lineage_config(#27098) - New Resource:
google_artifact_registry_rule(#27049) - New Resource:
google_data_lineage_config(#27098) - New Resource:
google_document_ai_schema(#27102) - New Resource:
google_firebase_remote_config_remote_config(#27050)
IMPROVEMENTS:
- provider: added support for
prefer_global_endpointsandprefer_regional_endpointsto the provider configuration. Support for regional endpoints will be rolled out on a per-product level (#27014) - artifactregistry: added support for regionalized endpoints (#27014)
- assuredworkloads: added
SPAIN_DATA_BOUNDARY_BY_TELEFONICAvalue topartnerfield ongoogle_assured_workloads_workloadresource (#27027) - bigqueryconnection: added
configurationblock togoogle_bigquery_connectionresource to support AlloyDB and other connector types via the BigQuery Connector framework (#27029) - bigtable: added support for
tagstogoogle_bigtable_instance(#27060) - cloudrunv2: added
DISKfields togoogle_cloud_run_v2_jobresource (#27052) - cloudrunv2: added
DISKfields togoogle_cloud_run_v2_worker_poolresource (#27048) - compute: add
params.resourceManagerTagsfield to thegoogle_compute_storage_pool(#27051) - compute: added
cache_policyfield togoogle_compute_url_map(#27011) - compute: added
params.resource_manager_tagsfield togoogle_compute_instant_snapshotresource (#27087) - compute: added
resource_manager_tagsfield togoogle_compute_machine_imageresource (#27075) - container: added
node_config.linux_node_config.accurate_time_configfield togoogle_container_node_poolresource (#27064) - container: added
node_pool.node_config.linux_node_config.accurate_time_configandnode_config.linux_node_config.accurate_time_configfields togoogle_container_clusterresource (#27064) - container: added
node_pool.node_config.linux_node_config.swap_configfield togoogle_container_node_poolresource (#26982) - container: increased default timeout for
google_container_clusterto 90 minutes (from 40/60 depending on operation) andgoogle_container_node_poolto 60 minutes (from 30) (#27101) - discoveryengine: added
destionation_configs.destionations.portanddestionation_configs.paramsfields togoogle_discovery_engine_data_connectorresource (#27058) - dns: added support for IAM conditions to
google_dns_managed_zoneresource (#27010) - datastream: added
deletion_policyfield to control whether child routes are force-deleted togoogle_datastream_private_connection(#27033) - networkconnectivity: added support for IAM conditions to
google_network_connectivity_hubresource (#27005) - networksecurity: added
parentfield togoogle_network_security_address_groupsdata source (#27082) - workbench: added support for new disk types and accelerators to
google_workbench_instance(#27061)
BUG FIXES:
- alloydb: fixed
google_alloydb_clusterso thatmaintenance_update_policy.maintenance_windows.start_time.hourscan be set to0(midnight) (#26981) - ces: fixed type mismatch in
google_ces_appvariable default value (#27084) - compute: fixed an issue where an erroneous error could occur for having an unset
zonefield ingoogle_compute_instance_template(#27076) - compute: fixed permadiff for
iap.oauth2_client_idingoogle_compute_backend_serviceandgoogle_compute_region_backend_servicewhen the API returns a single space (#26975) - container: fixed a permadiff in
google_container_clusterwheredatabase_encryption.statereturningALL_OBJECTS_ENCRYPTION_ENABLEDinstead of the configuredENCRYPTEDcaused unintended reapplies (#27040) - dataplex: fixed acceptance test failure for one time scans (#27095)
- dialogflowcx: fixed a perma-diff in
google_dialogflow_cx_test_casewhensession_parameterswas omitted from the configuration (#26985) - hypercomputecluster: fixed a permadiff in
google_hypercomputecluster_clusterwhencount,static_node_count, ormax_dynamic_node_countwere explicitly set to0. (#27073) - identityplatform: fixed a premadiff on
multi_tenantingoogle_identity_platform_configresource. Removing the value from config will now preserve the existing settings instead of removing them. (#26986) - memorystore: fixed an issue preventing updating multiple properties at once for
google_redis_cluster(#27077)
NOTES:
- compute: Migrate
resource_compute_instance_group.go.tmplresource to use direct HTTP rather then a client library (#27080) - compute: migrated
compute-operationresource to use direct HTTP rather then a client library (#27053) - compute: migrated
compute_backend_bucket_security_policyresource to use direct HTTP rather than a client library (#27012) - compute: migrated
compute_instance_network_interface_helpersresource to use direct HTTP rather than a client library (#27104) - compute: migrated
data_source_google_compute_addresses.go.tmpldata source to use direct HTTP rather then a client library (#27016) - compute: migrated
data_source_google_compute_machine_typesdatasource to use direct HTTP rather than a client library (#27017) - compute: migrated
google_disk_testto use direct HTTP rather than a client library (#27079) - compute: migrated
resource_compute_disk_async_replicationresource to use direct HTTP rather then a client library (#27028) - compute: migrated
resource_compute_http_health_check_test.go.tmplresource to use direct HTTP rather then a client library (#27057)
7.29.0 (Apr 21, 2026)
NOTES:
- provider: List resources are now supported in both google and google-beta providers with the introduction of
google_service_accountlist resource - more info can be found here (#26938)
FEATURES:
- New Data Source:
google_firebase_admin_sdk_config(#26901) - New Resource:
google_chronicle_datatable_row(#26960) - New Resource:
google_chronicle_datatable(#26895) - New Resource:
google_dataform_folder(#26881) - New Resource:
google_dataform_team_folder(#26881) - New Resource:
google_firebase_storage_default_bucket(#26965)
IMPROVEMENTS:
- alloydb: added
track_client_addressfield togoogle_alloydb_instanceresource (#26964) - clouddeploy: added
tasksfield togoogle_clouddeploy_custom_target_typeresource (#26941) - compute: added
header_actionandredirect_optionsfields togoogle_compute_organization_security_policy_ruleresource (#26942) - dataplex: added
execution_identityfield togoogle_dataplex_datascanresource (#26924) - dataproc: added
cluster_config.enginefield togoogle_dataproc_clusterresource (#26962) - iambeta: added
trust_default_shared_cafield to `go...