github hashicorp/terraform-provider-google v7.46.1

7 hours ago

UG FIXES:

  • compute: fix permadiff regression when iap is omitted from google_compute_backend_service (#29156)

7.46.0 (August 25th, 2026)

DEPRECATIONS:

  • beyondcorp: deprecated google_beyondcorp_app_connection, google_beyondcorp_app_connector, and google_beyondcorp_app_gateway resources and data sources. Use google_beyondcorp_security_gateway and google_beyondcorp_security_gateway_application instead. (#28976)

FEATURES:

  • New Data Source: google_memorystore_acl_policy (#28984)
  • New Data Source: google_redis_cluster_acl_policy (#28985)
  • New List Resource: google_migration_center_assets_export_job (#28904)
  • New List Resource: google_migration_center_discovery_client (#28904)
  • New List Resource: google_migration_center_group (#28904)
  • New List Resource: google_migration_center_import_job (#28904)
  • New List Resource: google_migration_center_preference_set (#28904)
  • New List Resource: google_migration_center_report_config (#28904)
  • New List Resource: google_migration_center_source (#28904)
  • New List Resource: google_network_services_authz_extension (#28978)
  • New List Resource: google_network_services_multicast_consumer_association (#28978)
  • New List Resource: google_network_services_multicast_domain_activation (#28978)
  • New List Resource: google_network_services_multicast_domain_group (#28978)
  • New List Resource: google_network_services_multicast_domain (#28978)
  • New List Resource: google_network_services_multicast_group_consumer_activation (#28978)
  • New List Resource: google_network_services_multicast_group_producer_activation (#28978)
  • New List Resource: google_network_services_multicast_group_range_activation (#28978)
  • New List Resource: google_network_services_multicast_group_range (#28978)
  • New List Resource: google_network_services_multicast_producer_association (#28978)
  • New Resource: google_memorystore_acl_policy (#28984)
  • New Resource: google_redis_cluster_acl_policy (#28985)

IMPROVEMENTS:

  • biglake: added serde_info field to google_biglake_table resource (#28990)
  • ces: added connector_toolset and timeout fields to google_ces_toolset resource (#28903)
  • compute: added write-only arguments for IAP oauth2_client_id and oauth2_client_secret to google_compute_backend_service resource (#28809)
  • discoveryengine: made google_discovery_engine_search_engine search_engine_config.required_subscription_tier updatable (#28991)
  • securesourcemanager: added PULL_REQUEST_COMMENT enum to events field in google_secure_source_manager_hook (#28907)
  • sql: added replication_lag_max_seconds to google_sql_database_instance (#28813)

BUG FIXES:

  • compute: fixed truncation of results at 500 images in google_compute_images data source (#28909)
  • container: fixed a permadiff on enable_private_endpoint and master_global_access_config.enabled in google_container_cluster when control_plane_endpoints_config.ip_endpoints_config.enabled is set to false (#28981)
  • sql: fixed google_sql_user returning Missing Resource Identity After Read when the parent Cloud SQL instance is stopped (#28977)

7.45.0 (August 18, 2026)

FEATURES:

  • New Data Source: google_iam_workload_identity_pool_openid_config (#28790)
  • New Resource: google_agentic_applications_analyst_agent_persona (#28777)
  • New Resource: google_firestore_change_stream (#28800)

IMPROVEMENTS:

  • accesscontextmanager: added dry_run_access_levels and principal fields to google_access_context_manager_gcp_user_access_binding resource (#28767)
  • accesscontextmanager: updated group_key to be optional and conflict with principal on google_access_context_manager_gcp_user_access_binding resource (#28767)
  • bigqueryreservation: added labels field to google_bigquery_reservation resource (#28711)
  • certificatemanager: enabled write-only support for pem_private_key on google_certificate_manager_certificate resource (#28794)
  • ces: added snippets_config field to data_store_tool.modality_configs and service_directory_config field to python_function in google_ces_tool (#28759)
  • chronicle: added schedule_customizations field to google_chronicle_rule_deployment resource (#28715)
  • cloudrunv2: added templates.sandboxes field to google_cloud_run_v2_service resource (#28749)
  • colab: added custom_environment_spec.shielded_instance_config and workbench_runtime.vm_image fields to google_colab_notebook_execution resource (#28774)
  • compute: added custom_error_response_policy and default_error_response_policy fields to google_compute_url_map resource (#18511)
  • compute: promoted max_run_duration and on_instance_stop_action fields on google_compute_instance, google_compute_instance_template, and google_compute_instance_from_machine_image resources (#18623)
  • dataplex: added sql_assertion field to google_dataplex_datascan resource (#18559)
  • netapp: added zone and replica_zone fields to google_netapp_storage_pool resource (#18609)
  • securityscanner: added static_ip_scan field to google_security_scanner_scan_config resource (#28786)
  • vertexai: added spec.container_spec.port field to google_vertex_ai_reasoning_engine resource (#28762)
  • workbench: added compute_instance_id field to google_workbench_instance resource (#28773)

BUG FIXES:

  • alloydb: fixed an issue where updateMask URL parameter was dropped during cluster updates (e.g. database_version upgrade) due to variable shadowing (#28801)
  • appengine: fixed permadiff in google_app_engine_standard_app_version (#28745)
  • bigquery: fixed an issue where updating google_bigquery_dataset overwrote fine-grained IAM permissions (#28775)
  • cloudsecuritycompliance: fixed state drift on supported_enforcement_modes in google_cloud_security_compliance_framework resource (#28676)
  • colab: fixed drift detection on direct_notebook_source.content field in google_colab_notebook_execution resource (#28774)
  • compute: fixed a panic in google_compute_shared_vpc_service_project during terraform plan/refresh when the shared VPC link had been removed outside of Terraform (#28750)
  • compute: fixed permadiff on adaptive_protection_config.layer_7_ddos_defense_config.enable in google_compute_security_policy when field is not set in config (#28751)
  • compute: fixed permadiffs for google_compute_disk on Fedora CoreOS images (#28712)
  • networksecurity: fixed google_network_security_gateway_security_policy to force replacement when name or location is modified (#28776)

7.44.0 (August 11, 2026)

FEATURES:

  • New List Resource: google_bigquery_dataset_iam_member (#28578)
  • New List Resource: google_bigquery_table (#28576)
  • New Resource: google_chronicle_custom_list (#28618)
  • New Resource: google_chronicle_soar_network (#28649)
  • New Resource: google_dataform_repository (#28642)
  • New Resource: google_dataform_repository_iam_binding (#28642)
  • New Resource: google_dataform_repository_iam_member (#28642)
  • New Resource: google_dataform_repository_iam_policy (#28642)
  • New Resource: google_iam_folder_access_policy (#28664)
  • New Resource: google_iam_organization_access_policy (#28664)
  • New Resource: google_iam_project_access_policy (#28664)
  • New Resource: google_vertex_ai_evaluation_metric (#28665)

IMPROVEMENTS:

  • bigquery: added resource identity support to google_bigquery_table (#28574)
  • compute: promoted host_error_timeout_seconds field in google_compute_instance, google_compute_instance_template and google_compute_region_instance_template to GA (#28671)
  • container: added high_scale_checkpointing_config block to addons_config in google_container_cluster (#28669)
  • dataproc: added attached_disk_config to disk_config to support attached disks in the google_dataproc_cluster resource (#28590)
  • memorystore: documented TOKEN_AUTH as a google-beta-only value for authorization_mode field on google_memorystore_instance resource (#28584)
  • networkservices: added allow_global_access field to google_network_services_gateway (#28589)
  • oracledatabase: added identity_connector to google_oracle_database_exadb_vm_cluster for CMEK support (#28615)
  • securesourcemanager: added service_account and scan_config fields to google_secure_source_manager_repository (#28662)
  • sql: added password_secret_version and user fields into google_sql_provision_script resource (#28619)
  • sql: removed ForceNew config from disk_type field in google_sql_database_instance, allowing it to change in future without requiring the database instance to be destroyed and recreated (#28616)

BUG FIXES:

  • backupdr: fixed issue where google_backup_dr_restore_workload dropped resource_manager_tags during restore requests, causing tags shown in plan to not be applied to restored resources (#28586)
  • biglakeiceberg: fixed a permadiff in google_biglake_iceberg_table by suppressing diffs on location when the API-returned path contains a suffix folder (#28577)
  • biglakeiceberg: fixed permadiff on write.parquet.compression-codec in google_biglake_iceberg_table (#28650)
  • bigquery: fixed a provider panic when reading incomplete IAM conditions on google_bigquery_dataset_iam_member (#28617)
  • cloudrunv2: fixed permadiff by setting template.scaling.max_instance_count to computed in google_cloud_run_v2_service (#28644)
  • cloudrunv2: fixed permadiff in template.containers.resources.limits block in google_cloud_run_v2_service resource (#28670)
  • cloudsecuritycompliance: fixed state drift on supported_enforcement_modes in google_cloud_security_compliance_framework resource (#28676)
  • container: fixed a permadiff where ignore_node_count_changes was not persisted in google_container_cluster.node_pool (#28573)
  • container: fixed an issue where google_container_node_pool and google_container_cluster failed to invalidate their Instance Group Manager cache when a resize occurred or when ignore_node_count_changes was active (#28585)
  • networkconnectivity: made network field in google_network_connectivity_transport optional (#28639)
  • recaptchaenterprise: fixed updates to google_recaptcha_enterprise_key so existing challenge_settings.action_settings entries are preserved when the action map changes (#28673)
  • servicenetworking: fixed google_service_networking_connection ignoring the configured delete timeout, which used the create timeout instead (#28641)

7.43.0 (August 4, 2026)

NOTES:

  • docs(workflows): added warning to source_contents field on google_workflows_workflow noting that it will become required in version 8.0.0 (#28524)
  • firestore: clarified which resource to use for which kind of index in Standard and Enterprise editions (#28529)

FEATURES:

  • New List Resource: google_compute_instance (#28548)
  • New List Resource: google_discovery_engine_assistant (#28525)
  • New List Resource: google_discovery_engine_chat_engine (#28525)
  • New List Resource: google_discovery_engine_cmek_config (#28525)
  • New List Resource: google_discovery_engine_control (#28525)
  • New List Resource: google_discovery_engine_data_store (#28525)
  • New List Resource: google_discovery_engine_license_config (#28525)
  • New List Resource: google_discovery_engine_recommendation_engine (#28525)
  • New List Resource: google_discovery_engine_schema (#28525)
  • New List Resource: google_discovery_engine_search_engine (#28525)
  • New List Resource: google_discovery_engine_serving_config (#28525)
  • New List Resource: google_discovery_engine_sitemap (#28525)
  • New List Resource: google_discovery_engine_target_site (#28525)
  • New List Resource: google_discovery_engine_user_store (#28525)
  • New List Resource: google_project_iam_custom_role (#28526)
  • New List Resource: google_pubsub_subscription_iam_member (#28549)
  • New List Resource: google_service_account_iam_member (#28553)
  • New Resource: google_cloud_support_support_event_subscription (#28517)
  • New Resource: google_compute_region_network_policy_traffic_classification_rule (#28504)
  • New Resource: google_netapp_trial (#28503)
  • New Resource: google_network_connectivity_gateway_advertised_route GA promotion (#28471)

IMPROVEMENTS:

  • apigee: added service_account field to google_apigee_api_deployment resource (#28552)
  • apihub: added source_project_id field to google_apihub_plugin_instance resource (#28530)
  • artifactregistry: added no_cache field to google_artifact_registry_repository.remote_repository_config (#28506)
  • bigquery: added data_governance_tags_info field to google_bigquery_table resource (#28532)
  • bigqueryanalyticshub: added proposer field to google_bigquery_analytics_hub_query_template (#28518)
  • bigqueryanalyticshub: promoted google_bigquery_analytics_hub_query_template to GA (#28518)
  • bigquerydatapolicyv2: added data_governance_tag field to google_bigquery_datapolicyv2_data_policy resource (#28463)
  • bigqueryreservation: added principal field to google_bigquery_reservation_assignment resource (#28508)
  • cloudrunv: added sandbox_launcher field to the containers of google_cloud_run_service resource (#28521)
  • cloudrunv2: added sandbox_launcher field to the containers of google_cloud_run_v2_service resource (#28521)
  • compute: promoted ncc_gateway field in google_compute_router to GA (#28471)
  • discoveryengine: added acl_enabled field to google_discovery_engine_data_store resource (#28465)
  • networkconnectivity: promoted gateway field in google_network_connectivity_spoke to GA (#28471)
  • privateca: made config.subject_config.subject.organization optional in google_privateca_certificate (#28464)
  • vertexai: added traffic_config field and live traffic split update support to google_vertex_ai_reasoning_engine (#28473)

BUG FIXES:

  • apigee: fixed continue_on_error argument being dropped in google_apigee_flowhook, aligning provider behavior with the Apigee API (#28554)
  • compute: fixed panic when setting scheduling attributes in google_compute_region_instance_template (ga) (#28467)
  • gkehub2: made field spec.workloadidentity.scopeTenancyPool in resource google_gke_hub_feature not required. (#28472)

7.42.0 (July 28, 2026)

NOTES:

  • compute: migrated google_compute_region_instance_template resource to use direct HTTP rather than a client library (#28431)

DEPRECATIONS:

  • vertexai: deprecated google_vertex_ai_schedule, an accidentally-added duplicate resource; use google_colab_schedule instead. (#28406)

FEATURES:

  • New Data Source: google_cloud_quotas_quota_adjuster_settings (#28383)
  • New List Resource: google_service_account_key (#28430)
  • New Resource: google_agent_identity_auth_provider (#28447)
  • New Resource: google_apihub_runtime_project_attachment (#28449)
  • New Resource: google_chronicle_big_query_export (#28403)
  • New Resource: google_compute_global_vm_extension_policy (#28445)
  • New Resource: google_compute_rollout_plan (#28445)
  • New Resource: google_vector_search_data_object (#28434)
  • New Resource: google_vertex_ai_persistent_resource (#28435)

IMPROVEMENTS:

  • bigquery: added table_type field to google_bigquery_routine resource (#28446)
  • cloudrunv2: added start_execution_token and run_execution_token fields to google_cloud_run_v2_jobresource (#28384)
  • colab: added catch_up, create_pipeline_job_request, create_time, last_pause_time, last_resume_time, last_scheduled_run_response, max_concurrent_active_run_count, next_run_time, started_run_count, and update_time fields, and sub-fields under create_notebook_execution_job_request.notebook_execution_job (create_time, custom_environment_spec, encryption_spec, job_state, kernel_name, labels, name, schedule_resource_name, workbench_runtime) and under create_notebook_execution_job_request (notebook_execution_job_id, parent) to google_colab_schedule resource (#28406)
  • compute: added effective_location field to google_compute_interconnect resource (#28416)
  • compute: added request_headers and response_headers fields to log_config on google_compute_backend_service and google_compute_region_backend_service resources (#28421)
  • compute: added identity support to google_compute_instance, allowing resource import using an identity block (#28433)
  • compute: changed location field to mutable for google_compute_interconnect resource (#28416)
  • container: added addons_config.node_readiness_config field to google_container_cluster resource (#28417)
  • container: added rollback_safe_upgrade, desired_emulated_version, and emulated_version fields to google_container_cluster resource (#28442)
  • container: increased default timeout to 2 hours for google_container_node_poolresource (#28382)
  • dataproc: added confidential_instance_type field to google_dataproc_cluster resource (#28371)
  • gkehub: added min_control_plane_version, min_node_version, target_control_plane_version, target_node_version, and operational_state fields to google_gke_hub_rollout_sequence resource (#28429)
  • hypercomputecluster: increased default timeouts for google_hypercomputecluster_cluster to 120 minutes (#28448)
  • modelarmor: added field template_metadata.filter_version_selector to google_model_armor_template resource (#28402)
  • sql: added identity support to google_sql_user for terraform query support (#28428)

BUG FIXES:

  • bigtable: fixed an issue where bigtable_custom_endpoint and universe_domain were ignored when creating Bigtable resources (#28404)
  • compute: fixed an issue where diffs in google_compute_security_policy were not detected (#28420)
  • gkehub: fixed rollout_creation_scope and upgrade_types fields in google_gke_hub_rollout_sequence resource (#28429)
  • osconfig: added client-side validation to ensure resource_hierarchy_selector and location_selector are not set at the same time in google_os_config_v2_policy_orchestrator, google_os_config_v2_policy_orchestrator_for_folder, and google_os_config_v2_policy_orchestrator_for_organization (#28407)
  • secretmanager: fixed an issue where google_secret_manager_secret_version would fail at apply time if neither secret_data nor secret_data_wo was set (#28419)
  • sql: fixed issue where updates to settings.ip_configuration.psc_config.allowed_consumer_projects in google_sql_database_instance were silently ignored on in-place updates (#28444)
  • vertexai: fixed google_vertex_ai_endpoint_with_model_garden_deployment destroying and recreating the endpoint when min_replica_count, max_replica_count, required_replica_count, or autoscaling_metric_specs changed (#28401)

7.41.0 (July 17, 2026)

FEATURES:

  • New Resource: google_chronicle_environment_group (#28338)
  • New Resource: google_compute_router_named_set (#28326)
  • New List Resource: google_compute_backend_bucket_signed_url_key (#28357)
  • New List Resource: google_compute_backend_service_signed_url_key (#28357)
  • New List Resource: google_compute_network_firewall_policy (#28357)
  • New List Resource: google_compute_network_firewall_policy_association (#28357)
  • New List Resource: google_compute_network_firewall_policy_packet_mirroring_rule (#28357)
  • New List Resource: google_compute_preview_feature (#28357)
  • New List Resource: google_compute_public_advertised_prefix (#28357)
  • New List Resource: google_compute_region_backend_bucket (#28357)
  • New List Resource: google_compute_region_network_firewall_policy (#28357)

IMPROVEMENTS:

  • accesscontextmanager: added allowed_service_patterns and service_patterns_enforcement_scopes fields to google_access_context_manager_service_perimeter to support VPC Service Controls for non-GCP APIs. (#28349)
  • accesscontextmanager: added pscEndpoint to sources in ingress_from and egress_from under resources google_access_context_manager_service_perimeter and variants (#28307)
  • backupdr: added backup_blocked_by_vault_access_restriction to data.google_backup_dr_data_source resource (#28361)
  • backupdr: added force_update_access_restriction to google_backup_dr_backup_vault resource (#28361)
  • backupdr: added update support for access_restriction to google_backup_dr_backup_vault resource (#28361)
  • certificatemanager: added in-place update support for the self_managed certificate data (pem_certificate / pem_private_key) on google_certificate_manager_certificate; changing the certificate data is now applied via update instead of forcing recreation (#28337)
  • cloudrunv2: added tags field to google_cloud_run_v2_service and google_cloud_run_v2_job resources to allow setting tags for services and jobs at creation time. (#28328)
  • cloudsql: added max_custom_on_demand_retention_days to create backup_plan example for sqladmin (#28343)
  • compute: added 3500GB and 7000GB SSD partition size to google_compute_instance_template resource (#28352)
  • compute: added FLEX_START and RESERVATION_BOUND support to google_compute_instance, google_compute_instance_template, and google_compute_region_instance_template resources (#28365)
  • container: added the support for updating node_image_config and image_type fields at the same time (#28283)
  • dataproc: added confidential_instance_type to google_dataproc_cluster resource (#28371)
  • dataproc: added instance_selection.disk_config field to google_dataproc_cluster resource (#28339)
  • discoveryengine: added enable_llm_layout_parsing and enable_get_processed_document fields to google_discovery_engine_data_store resource (#28284)
  • sql: added instance_auto_dns_status and write_endpoint_auto_dns_status output fields to psc_auto_connections block in google_sql_database_instance resource (#28331)
  • sql: added include_replicas_for_major_version_upgrade field to google_sql_database_instance resource (#28345)
  • sql: added switch_transaction_logs_to_cloud_storage_enabled field to google_sql_database_instance resource (#28318)
  • vertexai: promoted google_vertex_ai_semantic_governance_policy_engine resource to GA (#28347)
  • workbench: added enable_deletion_protection field to google_workbench_instance resource (#28355)
  • workbench: added resource_policies field to google_workbench_instance resource (#28354)
  • workbench: added support for min_cpu_platform in google_workbench_instance resource (#28369)
  • workstations: added instance_metadata field to google_workstations_workstation_config resource (#28342)

BUG FIXES:

  • compute: fixed bug where a permadiff on google_compute_reservation_region_commitment.existing_reservations would persist after upgrading (#28353)
  • compute: fixed permadiff on keepalive_interval for google_compute_router bgp block when set to default value (#28285)
  • resourcemanager: fixed validation of target_service_account and delegates in the google_service_account_access_token, google_service_account_id_token, and google_service_account_jwt data sources, and of name in the google_service_account_key data source, to reject identifiers that contain path separators (#28308)
  • securityposture: fixed a bug where the enforce field in google_securityposture_posture was always set, causing failures for list constraints. (#28359)
  • vmwareengine: added correct update_mask value to google_vmwareengine_private_cloud updates (#28360)

7.40.0 (July 14, 2026)

DEPRECATIONS:

  • storage: the admit-on-second-miss value for google_storage_anywhere_cache.admission_policy is deprecated and will be removed in a future major release. The backend will ignore this attribute and treat it as admit-on-first-miss. (#28210)

NOTES:

  • compute: migrated google_compute_instance code related to advanced machine features to use direct HTTP rather than a client library (#28160)

FEATURES:

  • New Data Source: google_data_catalog_taxonomy (#28237)
  • New Data Source: google_oracle_database_exascale_db_storage_vault (#28260)
  • New List Resource: 'google_project' (#28041)
  • New List Resource: google_compute_instant_snapshot (#28256)
  • New List Resource: google_compute_region_instant_snapshot (#28256)
  • New List Resource: google_compute_region_target_http_proxy (#28256)
  • New List Resource: google_compute_region_target_tcp_proxy (#28256)
  • New List Resource: google_compute_region_url_map (#28256)
  • New List Resource: google_compute_rollout_plan (#28256)
  • New List Resource: google_compute_target_grpc_proxy (#28256)
  • New List Resource: google_compute_target_http_proxy (#28256)
  • New List Resource: google_compute_target_ssl_proxy (#28256)
  • New List Resource: google_compute_target_tcp_proxy (#28256)
  • New List Resource: google_dns_managed_zone (#28257)
  • New List Resource: google_oracle_database_exascale_db_storage_vaults (#28260)
  • New Resource: google_chronicle_findings_refinement_deployment (#28240)
  • New Resource: google_chronicle_soar_domain (#28214)
  • New Resource: google_iap_agent_registry_agent_iam_binding (#28231)
  • New Resource: google_iap_agent_registry_agent_iam_member (#28231)
  • New Resource: google_iap_agent_registry_agent_iam_policy (#28231)
  • New Resource: google_iap_agent_registry_endpoint_iam_binding (#28231)
  • New Resource: google_iap_agent_registry_endpoint_iam_member (#28231)
  • New Resource: google_iap_agent_registry_endpoint_iam_policy (#28231)
  • New Resource: google_iap_agent_registry_mcp_server_iam_binding (#28231)
  • New Resource: google_iap_agent_registry_mcp_server_iam_member (#28231)
  • New Resource: google_iap_agent_registry_mcp_server_iam_policy (#28231)
  • New Resource: google_tags_tag_binding_collection (#28180)
  • New Resource: google_vector_search_index (#28238)
  • New Resource: google_chronicle_environment (#28206)
  • New Resource: google_chronicle_data_export (#28239)

IMPROVEMENTS:

  • agentregistry: added name field to google_agent_registry_binding resource (#28207)
  • agentregistry: added name field to google_agent_registry_service resource (#28207)
  • appengine: added app_engine_bundled_services field to google_app_engine_standard_app_version resource (#28213)
  • biglakeiceberg: add support for CATALOG_TYPE_FEDERATED with federated_catalog_options to google_biglake_iceberg_catalog (#28241)
  • compute: added target_type and target_forwarding_rules to google_compute_region_network_firewall_policy_with_rules resource (#28061)
  • compute: added workload_identity_config fields to google_compute_instance and google_compute_instance_template resources (#28266)
  • compute: added instance_lifecycle_policy.on_repair.allow_changing_zone field to google_compute_instance_group_manager and google_compute_instance_region_group_manager. (#28174)
  • container: added ANY_RESERVATION_THEN_FAIL option to consume_reservation_type field in google_container_cluster and google_container_node_pool resources (#28060)
  • container: added custom_node_init configuration block to node_config (supporting Cloud Storage and Secret Manager) for both google_container_cluster and google_container_node_pool resources. (#28262)
  • container: added maintenance_policy field to google_container_node_pool resource (#28217)
  • container: added recurring_maintenance_window field to google_container_cluster resource (#28227)
  • dataplex: added catalog_publishing_enabled field to google_dataplex_datascan resource (#28232)
  • dlp: added inspect_config.min_likelihood_per_info_type to google_data_loss_prevention_inspect_template (#28236)
  • firestore: added skip_wait field to google_firestore_field resource, skipping the wait for index creation (#28222)
  • oracledatabase: added support for configuring Exascale-based VM clusters on top of dedicated storage vaults via the exascale_db_storage_vault parameter and storage_management_type to determine if VM Cluster is ASM or EXASCALE in google_oracle_database_cloud_vm_cluster (#28197)
  • oracledatabase: added exadata_infrastructure field to google_oracle_database_exascale_db_storage_vault resource (#28177)
  • oracledatabase: added exascale_db_storage_vault and storage_management_type fields to google_oracle_database_cloud_vm_clusters data source (#28260)
  • sql: added enforce_new_sql_network_architecture field to google_sql_database_instance resource (#28233)
  • sql: added psc_auto_connection_policy_enabled field and output-only service_connection_policy and service_connection_policy_creation_result fields to google_sql_database_instance resource (#28225)
  • storagetransfer: added private_network_service to resource google_storage_transfer_job (#28178)

BUG FIXES:

  • bigtable: fixed a bug where row_affinity updates did not persist on google_bigtable_app_profile (#28215)
  • bug: fixed labels diff in google_project (#28229)
  • chronicle: suppressed a permadiff on google_chronicle_rule.text caused by the Chronicle API appending a trailing newline to every stored rule body (#28216)
  • cloudscheudler: added retries for "409: sync mutate calls cannot be queued" error for google_cloud_scheduler_job (#28164)
  • compute: fixed an issue where preview = false updates for google_compute_organization_security_policy_rule were omitted from API requests. (#28223)
  • compute: fixed bug where it wasn't possible to disable enable_proxy_protocol on google_compute_service_attachment resource (#28264)
  • datastream: fixed a bug in update functionality in google_datastream_connection_profile mongodb_profile.additional_options (#28254)
  • eventarc: fixed a type mismatch when an google_eventarc_trigger resource returns non-empty conditions. (#28226)
  • filestore: aligned google_filestore_instance resource timeouts with the Filestore service instance operations TTLs (#28208)
  • gemini: fixed truncated timeouts in google_gemini_code_tools_setting, google_gemini_data_sharing_with_google_setting_binding, google_gemini_gemini_gcp_enablement_setting_binding, and google_gemini_release_channel_setting_binding (#28220)
  • hypercomputecluster: fixed 20-minute timeout limit during google_hypercomputecluster_cluster resource creation (#28182)
  • logging: fixed an issue where errors on update would not be propagated in google_logging_project_bucket_config (#28055)
  • observability: fixed unintentionally long timeouts in google_observability_folder_settings, google_observability_organization_settings, and google_observability_project_settings (#28220)
  • oracledatabase: fixed early client-side timeouts and aligned default schema timeouts with backend async polling limits on google_oracle_database_exadb_vm_cluster, google_oracle_database_odb_network, google_oracle_database_odb_subnet, google_oracle_database_goldengate_connection, google_oracle_database_goldengate_deployment, and google_oracle_database_goldengate_connection_assignment. (#28228)
  • oracledatabase: fixed truncated timeouts in google_oracle_database_exadb_vm_cluster, google_oracle_database_goldengate_connection, and google_oracle_database_odb_subnet (#28220)
  • privilegedaccessmanager: fixed a permadiff on google_privileged_access_manager_entitlement for entitlements created without an approval workflow (#28224)
  • provider: fixed validation of external_credentials.identity_token to reject malformed JWTs containing empty segments (#28258)

7.39.0 (June 30, 2026)

NOTES:

  • compute: migrated google_compute_instance_template resource partially to use direct HTTP rather than a client library (#28010)
  • compute: migrated google_compute_network_peering resource to use direct HTTP rather than a client library (#28021)
  • compute: migrated metadata handling to use direct HTTP rather than a client library (#27968)

FEATURES:

  • New Data Source: google_agent_registry_agent (#28028)
  • New Data Source: google_agent_registry_endpoint (#28028)
  • New Data Source: google_agent_registry_mcp_server (#28028)
  • New Data Source: google_compute_instance_groups (#27981)
  • New Data Source: google_storage_control_folder_intelligence_findings_summary (#28019)
  • New Data Source: google_storage_control_organization_intelligence_findings_summary (#28019)
  • New Data Source: google_storage_control_project_intelligence_findings_summary (#28019)
  • New Resource: google_agent_registry_binding (#28028)
  • New Resource: google_agent_registry_service (#28028)
  • New Resource: google_artifact_registry_project_config (#28009)
  • New Resource: google_chronicle_findings_refinement (#28035)
  • New Resource: google_compute_bulk_per_instance_config (#28031)
  • New Resource: google_compute_firewall_policy_iam_binding (#27978)
  • New Resource: google_compute_firewall_policy_iam_member (#27978)
  • New Resource: google_compute_firewall_policy_iam_policy (#27978)
  • New Resource: google_compute_network_firewall_policy_iam_binding (#27978)
  • New Resource: google_compute_network_firewall_policy_iam_member (#27978)
  • New Resource: google_compute_network_firewall_policy_iam_policy (#27978)
  • New Resource: google_compute_region_network_firewall_policy_iam_binding (#27978)
  • New Resource: google_compute_region_network_firewall_policy_iam_member (#27978)
  • New Resource: google_compute_region_network_firewall_policy_iam_policy (#27978)
  • New Resource: google_compute_region_resize_request (#27984)
  • New Resource: google_compute_zone_vm_extension_policy (#28034)
  • New Resource: google_gke_hub_rollout_sequence (#28007)
  • New Resource: google_iap_agent_registry_iam_binding (#28032)
  • New Resource: google_iap_agent_registry_iam_member (#28032)
  • New Resource: google_iap_agent_registry_iam_policy (#28032)
  • New Resource: google_iap_location_web_iam_binding (#28032)
  • New Resource: google_iap_location_web_iam_member (#28032)
  • New Resource: google_iap_location_web_iam_policy (#28032)
  • New Resource: google_oracle_database_cloud_exadata_infrastructure_exascale_config (#28033)
  • New List Resource: google_bigquery_dataset (#28005)
  • New List Resource: google_compute_cross_site_network (#28018)
  • New List Resource: google_compute_external_vpn_gateway (#28018)
  • New List Resource: google_compute_global_network_endpoint_group (#28018)
  • New List Resource: google_compute_ha_vpn_gateway (#28018)
  • New List Resource: google_compute_interconnect_attachment_group (#28018)
  • New List Resource: google_compute_interconnect_group (#28018)
  • New List Resource: google_compute_public_delegated_prefix (#28018)
  • New List Resource: google_compute_region_commitment (#28018)
  • New List Resource: google_compute_region_network_endpoint_group (#28018)
  • New List Resource: google_compute_vpn_gateway (#28018)
  • New List Resource: google_compute_wire_group (#28018)
  • New List Resource: google_folder_iam_member (#27993)
  • New List Resource: google_kms_crypto_key_version (#28006)
  • New List Resource: google_project (#28041)
  • New List Resource: google_project_service (#27989)

IMPROVEMENTS:

  • bigquery: added external_runtime_options.container_request_concurrency field to google_bigquery_routine resource (#28029)
  • compute: added instance_lifecycle_policy.on_failed_health_check field in resources google_compute_instance_group_manager and google_compute_region_instance_group_manager (ga) (#27992)
  • container: added new fields shutdown_grace_period_seconds and shutdown_grace_period_critical_pods_seconds to node_kubelet_config block. (#28015)
  • container: promoted agent_sandbox_config addon field under addons_config in google_container_cluster to GA (#28017)
  • dataplex: added icon field to google_dataplex_data_product resource (#27986)
  • dataplex: added name field to google_dataplex_data_product_data_asset resource (#28020)
  • dlp: added allow_limited_availability_info_types to google_data_loss_prevention_inspect_template (#28024)
  • networkservices: added forward_attributes field to google_network_services_lb_edge_extension, google_network_services_lb_route_extension, and google_network_services_lb_traffic_extension resources (#28012)

BUG FIXES:

  • compute: fixed a panic in google_compute_project_metadata and google_compute_project_metadata_item when project common instance metadata items contain null/empty values. (#28008)
  • compute: fixed a validation error on google_compute_instance (Provisioned IOPS cannot be specified with disk type pd-balanced) that occurred during updates on instances with Hyperdisk Balanced boot disks. (#27975)
  • dataproc: fixed a bug where changing policy_id on google_dataproc_autoscaling_policy planned an in-place update and failed; it now correctly forces resource replacement (destroy and recreate). (#28036)
  • firestore: added retries on 409 errors in google_firestore_user_creds resource (#27972)
  • iam: fixed ephemeral google_service_account_key producing a 404 due to duplicate /keys in the URL when fetch_key = true and name is provided (#27980)

7.38.0 (June 23, 2026)

NOTES:

  • bigquery: migrated google_bigquery_table resource to use direct HTTP rather than a client library (#27909)
  • compute: migrated resource_compute_instance_template_test.go.tmpl resource to use direct HTTP rather than a client library (#27859)
  • compute: migrated google_compute_resource_compute_instance to use direct HTTP rather than a client library (#27925)
  • compute: migrated parts of google_compute_instance and shared instance functions to use direct HTTP (#27815)

FEATURES:

  • New Data Source: google_storage_control_project_intelligence_finding_revision (#27912)
  • New Data Source: google_storage_control_project_intelligence_finding_revisions (#27912)
  • New Resource: google_biglake_hive_catalog (#27892)
  • New Resource: google_chronicle_feed (#27860)
  • New Resource: google_chronicle_parser_extension (#27906)
  • New Resource: google_dataplex_metadata_feed (#27934)
  • New Resource: google_network_services_agent_gateway (#27803)
  • New Resource: google_vertex_ai_schedule (#27895)
  • New Resource: google_vertex_ai_tensorboard_run (#27913)
  • New List Resource: google_compute_address (#27917)
  • New List Resource: google_compute_cross_site_network (#27864)
  • New List Resource: google_compute_https_health_check (#27917)
  • New List Resource: google_compute_node_template (#27917)
  • New List Resource: google_compute_packet_mirroring (#27917)
  • New List Resource: google_compute_region_autoscaler (#27917)
  • New List Resource: google_compute_region_composite_health_check (#27917)
  • New List Resource: google_compute_region_health_aggregation_policy (#27917)
  • New List Resource: google_compute_region_health_source (#27917)
  • New List Resource: google_project_iam_member (#27905)
  • New List Resource: google_pubsub_topic (#27914)
  • New List Resource: google_secret_manager_secret (#27910)

IMPROVEMENTS:

  • apigee: added consumer_key and consumer_secret fields to google_apigee_developer_app to allow specifying a static credential (#27820)
  • artifactregistry: added update support for upstream_credentials to google_artifact_registry_repository (#27819)
  • biglakeiceberg: added CATALOG_TYPE_BIGLAKE enum to catalog_type field and added restricted_locations_config.restricted_locations field in google_biglake_iceberg_catalog resource (#27930)
  • biglakeiceberg: added sort_order field to google_biglake_iceberg_table resource (#27865)
  • ces: added timeout and tool_fake_config fields to google_ces_tool and google_ces_toolset resource (#27907)
  • compute: added params.resource_manager_tags field to google_compute_snapshot resource (#27869)
  • compute: made network_endpoints.ip_address optional in google_compute_network_endpoints resource to support attaching endpoints to a network endpoint group of type GCE_VM_IP_DEDICATED_BACKEND (#27870)
  • container: added dataplane_optimization_mode in google_container_cluster (#27861)
  • container: added ignore_node_count_changes field to google_container_cluster and google_container_node_pool resources. When set to true, the provider ignores drift via external node count changes and skips related IGM API queries, resolving long plan times on clusters with a large number of instance groups. (#27896)
  • container: added skip_node_pool_refresh field to google_container_cluster resource. When set to true, the google_container_cluster skips refreshing and setting node_pools from the API, resolving long plan times on clusters with a large number of node pools. Note that this results in node_pools being set to an empty list in state (#27896)
  • container: added taint_config block to google_container_cluster and google_container_node_pool (#27884)
  • container: improved GKE node pool read performance by caching instance group metadata longer (#27896)
  • datastream: added additional_options field to google_datastream_connection_profile resource (#27915)
  • iamworkforcepool: write-only support for oidc.client_secret in google_iam_workforce_pool_provider (#27867)
  • kms: added resource identity support for google_kms_crypto_key_version resource (#27883)
  • networkservices: added dns_peering_config field to google_network_services_agent_gateway resource (#27813)
  • sql: added mode, dns_servers, admin_credential_secret_name, and organizational_unit fields to active_directory_config block in google_sql_database_instance resource for SQL Server instances (#27862)
  • storage: added lifecycle_rule.condition.size_above_bytes and lifecycle_rule.condition.size_below_bytes fields to google_storage_bucket resource (#27857)

BUG FIXES:

  • apigee: google_apigee_developer_app now updates api_products and scopes on the existing credential instead of creating a new credential (consumer key) on update (#27929)
  • biglake: allow location to be set on google_biglake_iceberg_namespace (#27814)
  • biglake: fixed creation failure of google_biglake_iceberg_table resource when the referenced google_biglake_iceberg_catalog has credential_mode set to CREDENTIAL_MODE_VENDED_CREDENTIALS due to a missing X-Iceberg-Access-Delegation header (#27903)
  • compute: fixed broken import of share_settings on google_compute_reservation (#27916)
  • datastream: fixed a positional diff when adding objects to the salesforce_source_config.include_objects field in google_datastream_stream resource (#27926)
  • iamworkforcepool: marked sensitive and ignore_read as true for security_token in google_iam_workforce_pool_provider_scim_token resource (#27812)
  • networkconnectivity: fixed google_network_connectivity_regional_endpoint being recreated on every apply when address is set to a resource URI (#27923)
  • networkservices: fixed name field expansion for google_network_services_agent_gateway resources so that short names are automatically expanded to full resource names, preventing API validation errors on create and update. (#27902)

7.37.0 (June 16, 2026)

NOTES:

  • compute: migrated EnableDisplay fields in google_compute_instance resources to use direct HTTP rather than a client library (#27778)
  • compute: migrated desired_status block and startInstanceOperation in resource_compute_instance.go.tmpl to use direct HTTP rather than a client library (#27755)
  • compute: migrated getInstance, getDisk, Delete and the setMetadata update block in resource_compute_instance.go.tmpl to use direct HTTP rather than a client library (#27716)
  • compute: migrated part of google_compute_instance to use direct HTTP rather than a client library (#27788)

DEPRECATIONS:

  • cloudrunv2: deprecated http_get.http_headers.port field in container startup probe and liveness probe in google_cloud_run_v2_worker_pool resource because it is not supported in Cloud Run API. This field will be removed in a future major release. (#27800)
  • cloudsecuritycompliance: deprecated the organization field on google_cloud_security_compliance_cloud_control, google_cloud_security_compliance_framework, and google_cloud_security_compliance_framework_deployment. Use parent instead (#27769)
  • networkservices: deprecated protocols on google_network_services_agent_gateway (#27802)

FEATURES:

  • New Data Source: google_oracle_database_goldengate_deployment_versions (#27771)
  • New Data Source: google_storage_control_project_intelligence_finding (#27764)
  • New Data Source: google_storage_control_project_intelligence_findings (#27764)
  • New Resource: google_chronicle_parser (#27801)
  • New Resource: google_migration_center_import_data_file (#27721)
  • New Resource: google_network_services_agent_gateway (#27803)
  • New Resource: google_vertex_ai_tensorboard_experiment (#27796)
  • New List Resource: google_bigquery_dataset_access (#27758)
  • New List Resource: google_cloud_scheduler_job (#27758)
  • New List Resource: google_dns_record_set (#27792)
  • New List Resource: google_monitoring_alert_policy (#27758)
  • New List Resource: google_pubsub_subscription (#27758)

IMPROVEMENTS:

  • apigee: added new resource google_apigee_environment_debugmask for managing Apigee environment debug masks (#27719)
  • backupdr: added support for use_project_service_account flag in google_backup_dr_restore_workload disk and compute restores (#27797)
  • cloudrunv2: added http_get.http_headers.name field to container startup probe and liveness probe in google_cloud_run_v2_worker_pool resource (#27800)
  • cloudrunv2: added template.client and template.client_version fields to google_cloud_run_v2_worker_pool resource (#27757)
  • cloudsecuritycompliance: added support for project parent to google_cloud_security_compliance_cloud_control, google_cloud_security_compliance_framework, and google_cloud_security_compliance_framework_deployment via the new parent field. The organization field has been deprecated. (#27769)
  • compute: added params.resource_manager_tags field to google_compute_reservation resource (#27770)
  • compute: added data sources for google_compute_target_http_proxy, google_compute_target_https_proxy, google_compute_region_target_http_proxy, and google_compute_region_target_https_proxy (#27767)
  • container: added addons_config.slurm_operator_config field to google_container_cluster resource (#27765)
  • container: added node_image_config field to google_container_node_pool and google_container_cluster resources (#27794)
  • databasemigrationservice: added state and stop_on_warnings fields to google_database_migration_service_migration_job resource (#27731)
  • dns: added resource identity support for google_dns_record_set resource (#27792)
  • networksecurity: added network_rules field on google_network_security_authz_policy resource (#27821)
  • pubsub: added first_revision_id and last_revision_id fields to google_pubsub_topic resource (#27718)
  • sql: added settings.ip_configuration.psc_config.psc_auto_dns_enabled and settings.ip_configuration.psc_config.psc_write_endpoint_dns_enabled fields to google_sql_database_instance resource (#27776)

BUG FIXES:

  • apigee: fixed google_apigee_api not detecting local bundle changes due to a missing default on detect_md5hash, and fixed the test sweeper's list URL (#27791)
  • apigee: fixed google_apigee_security_action update failure by enabling PATCH-based updates now that the Apigee Security Actions API supports mutations (#27768)
  • apigee: fixed a perma-diff for api_products and scopes fields in google_apigee_developer_app resource when updating them with multiple items (#27789)
  • apigee: fixed an issue where the resource would attempt recreation if the key_expires_in field was set in google_apigee_developer_app resource (#27779)
  • ces: fixed persistent diff in google_ces_guardrail when llm_prompt_security is configured with default_settings (#27766)
  • cloudrun: fixed a permadiff for the run.googleapis.com/gpu-zonal-redundancy-disabled annotation in google_cloud_run_service (#27787)
  • cloudrunv2: fixed bug where only one http_get.http_headers block could be specified in container startup probe and liveness probe in google_cloud_run_v2_worker_pool resource (#27800)
  • compute: fixed an issue in google_compute_subnetwork where secondary_ip_range entries linked to an internal_range could not be removed and adding new ranges would sometimes fail due to positional shifts (#27175) (#27720)
  • compute: fixed diff when using existing_reservations field in google_region_commitment (#27775)
  • compute: fixed rules in google_compute_security_policy being unnecessarily recreated due to TypeSet hash instability (#27754)
  • sql: fixed inconsistent result after apply error when adding users of type CLOUD_IAM_GROUP with capitalized domain names for MySQL (#27784)
  • storage: fixed OOM issue for google_storage_bucket force_destroy by limiting the number of outstanding tasks to 2000 (#27777)

7.36.0 (June 9, 2026)

FEATURES:

  • New Data Source: google_apigee_instance (#27683)
  • New Data Source: google_oracle_database_goldengate_deployment_types (#27634)
  • New Resource: google_apigee_datastore (#27607)
  • New Resource: google_discovery_engine_search_engine_iam_binding (#27703)
  • New Resource: google_license_manager_configuration (#27707)
  • New Resource: google_migration_center_import_job (#27599)
  • New List Resource: google_compute_disk (#27608)
  • New List Resource: google_compute_image (#27608)
  • New List Resource: google_compute_snapshot (#27608)
  • New List Resource: google_storage_hmac_key (#27637)

IMPROVEMENTS:

  • accesscontextmanager: added in-place update for egress_from and egress_to fields in google_access_context_manager_service_perimeter_egress_policy resource (#27690)
  • accesscontextmanager: added in-place update for egress_from and egress_to fields in google_access_context_manager_service_perimeter_ingress_policy resource (#27690)
  • bigquery: added IAM support (google_bigquery_routine_iam_policy, google_bigquery_routine_iam_binding, google_bigquery_routine_iam_member) for google_bigquery_routine resource (#27704)
  • bigtable: added automated_backup_policy.locations field in google_bigtable_table resource (#27646)
  • ces: added agent_tool, file_search_tool, and widget_tool fields to the google_ces_tool resource (#27681)
  • ces: added google_search_tool.prompt_config and data_store_tool.data_store_source fields to the google_ces_tool resource (#27681)
  • ces: exposed remote_agent_tool, connector_tool, and mcp_tool as read-only (output-only) attributes in google_ces_tool (#27681)
  • container: added node_creation_config field to google_container_cluster resource (#27702)
  • container: added node_drain_config.pdb_timeout_duration and node_drain_config.grace_termination_duration fields to google_container_node_pool and google_container_cluster resources (#27694)
  • data_catalog: added RICHTEXT to allowed values of primitive_type on google_data_catalog_tag_template fields. (#27672)
  • dataplex: added IAM support for google_dataplex_data_product resource (iam_policy, iam_binding, iam_member) (#27652)
  • dataplex: added access_approval_config field to google_dataplex_data_product resource (#27652)
  • hypercomputecluster: marked network_resources field as required in google_hypercomputecluster_cluster resource to align with API validation (#27655)
  • networksecurity: google_network_security_ull_mirroring_engine, google_network_security_ull_mirroring_collector, and google_network_security_ull_mirroring_collector_rule resources promoted to GA (#27710)
  • securesourcemanager: added psc_allowed_projects field to google_secure_source_manager_instance resource (#27695)
  • workbench: added NVIDIA_RTX6000 to the supported gce_setup.accelerator_configs.type values on google_workbench_instance resource(#27709)

BUG FIXES:

  • apigee: send zero values for ip_header_index in google_apigee_environment resource (#27670)
  • backupdr: fixed an issue where google_backup_dr_restore_workload did not use the correct API JSON names for networking/reservation fields (#27680)
  • compute: fixed an issue where updating connection_limit in the consumer_accept_lists block of google_compute_service_attachment would not trigger a resource update. (#27688)
  • compute: fixed regional backend reference in google_compute_regional_url_map resource (#27705)
  • dlp: fixed error when reading google_data_loss_prevention_discovery_config caused by nested error details (#27669)
  • sql: fixed permadiff on connection_pool_config when connection_pooling_enabled is set to false (#27711)
  • tags: fixed google_tags_location_tag_binding failing with Operation location does not match service location 'global' during creation (#27668)
  • vertexai: fixed terraform import of google_vertex_ai_index_endpoint_deployed_index failing with "Cannot determine region" when provider-level region/zone is unset (#27692)

7.35.0 (June 2, 2026)

FEATURES:

  • New Data Source: google_oracle_database_goldengate_connection_types (#27567)
  • New Resource: google_chronicle_findings_refinement (#27591)
  • New Resource: google_dataplex_data_product (#27588)
  • New Resource: google_dataplex_data_product_data_asset (#27588)
  • New Resource: google_migration_center_discovery_client (#27572)
  • New Resource: google_migration_center_report (#27548)
  • New Resource: google_oracle_database_goldengate_connection_assignment (#27566)
  • New Resource: google_oracle_database_goldengate_connection (#27587)
  • New Resource: google_oracle_database_goldengate_deployment (#27575)
  • New List Resource: google_compute_firewall (#27549)
  • New List Resource: google_compute_global_address (#27549)
  • New List Resource: google_compute_subnetwork (#27549)
  • New List Resource: google_sql_database (#27552)

IMPROVEMENTS:

  • compute: added target_type and target_forwarding_rules fields to google_compute_network_firewall_policy_rule resource (#27538)
  • container: added crash_loop_back_off.max_container_restart_period field to google_container_node_pool and google_container_cluster resources (#27574)
  • container: added additional value KCP_VPA for logging_config.enable_components field to google_container_cluster resource (#27546)
  • dataplex: added service_account support to google_dataplex_data_product access group principals (#27588)
  • firestore: added ttl_config.expiration_offset field to google_firestore_field resource (#27589)
  • netapp: added ontap_source field to google_netapp_backup resource (#27584)
  • networkmanagement: added gke_pod and network_type fields to google_network_management_connectivity_test resource (#27585)

BUG FIXES:

  • resourcemanager: fixed a bug where ephemeral google_service_account_key failed on deletion if the parent service account had already been deleted (#27541)
  • storage: fixed missing identity error when updating values in google_storage_bucket (#27605)

7.34.0 (May 27, 2026)

NOTES:

  • compute: migrated google_compute_region_instance_template to use direct HTTP rather than a client library (#27471)
  • compute: migrated google_compute_instance_group_manager resource to use direct HTTP rather than a client library (#27441)

FEATURES:

  • New Data Source: google_compute_service_attachment (#27526)
  • New Data Source: google_oracle_database_goldengate_deployment_environments (#27499)
  • New Resource: google_config_deployment (#27438)
  • New Resource: google_dialogflow_sip_trunk (#27468)
  • New Resource: google_migration_center_assets_export_job (#27466)
  • New Resource: google_migration_center_report_config (#27395)
  • New Resource: google_migration_center_settings (#27465)
  • New Resource: google_migration_center_source (#27496)

IMPROVEMENTS:

  • bigtable: added edition field to google_bigtable_instance resource (#27507)
  • ces: added fail_open field to llm_prompt_security block in google_ces_guardrail resource (#27497)
  • ces: added read-only fail_open field to llm_prompt_security block in google_ces_app_version resource (#27497)
  • compute: added ip_version and ip_collection fields to secondary_ip_range field in google_compute_subnetwork resource (#27432)
  • compute: added post_quantum_key_exchange field to google_compute_ssl_policy and google_compute_region_ssl_policy resources (#27479)
  • compute: added support in the google_compute_network datasource for looking up a network by self_link in addition to name (#27509)
  • container: added agent_sandbox_config field to google_container_cluster resource (#27482)
  • container: added node_config.gpudirect_strategy and node_pool.node_config.gpudirect_strategy to cluster resource, added node_config.gpudirect_strategy to node_pool resource (#27495)
  • dataflow: Added create_ignore_already_exists field to google_dataflow_flex_template_job resource to handle 409 conflicts (#27476)
  • datafusion: added maintenance_policy field to google_data_fusion_instance resource (#27470)
  • iam: add resource identity support for iam_member resources (#27383)
  • networkconnectivity: google_network_connectivity_transport resource promoted to GA (#27440)
  • oracledatabase: added identity_connector to google_oracle_database_cloud_vm_cluster for CMEK support (#27435)
  • project: added Resource Identity support to google_project_iam_binding (#27502)
  • project: added Resource Identity support to google_project_iam_policy (#27503)
  • sql: promoted Hyperdisk fields, data_disk_provisioned_iops and data_disk_provisioned_throughput to GA (#27437)

BUG FIXES:

  • bigtable: fixed an issue where bigtable_custom_endpoint and universe_domain were ignored when creating Bigtable resources. (#27515)
  • compute: fixed an issue in google_compute_subnetwork where secondary_ip_range entries linked to an internal_range could not be removed and adding new ranges would sometimes fail due to positional shifts (#27175) (#27512)
  • compute: marked encryption keys as immutable and sensitive across compute and backupdr resources (#27508)
  • dialogflow: corrected AUDIOENCODING_SPEEX_WITH_HEADER_BYTE enum value to AUDIO_ENCODING_SPEEX_WITH_HEADER_BYTE for audio_encoding field in google_dialogflow_conversation_profile resource (#27459)
  • resourcemanager: resolved a one-time diff for deletion_policy that would occur on existing and imported google_project_service resources following upgrading to v7.32.0 (#27484)

7.33.0 (May 19, 2026)

NOTES:

  • compute: migrated google_compute_target_pool resource to use direct HTTP rather than a client library (#12212)
  • compute: migrated google_compute_instance_group_manager resource to use direct HTTP rather than a client library (#12206)
  • compute: migrated google_compute_project_default_network_tier resource to use direct HTTP rather than a client library (#12201)
  • compute: migrated google_compute_router_status data source to use direct HTTP rather than a client library (#12174)
  • compute: migrated google_compute_instance_group_manager resource to use direct HTTP rather than a client library (#12216)
  • compute: partially migrated google_compute_instance resource to use direct HTTP rather then a client library (#12205)

FEATURES:

  • New Data Source: google_logging_log_view (#12226)
  • New Resource: google_apigee_data_collector (#12190)
  • New Resource: google_chronicle_native_dashboard (ga) (#12188)
  • New Resource: google_contact_center_insights_encryption_spec (#12225)

IMPROVEMENTS:

  • backupdr: added guest_flush field to google_backup_dr_backup_plan resource and google_backup_dr_backup data source. (#12229)
  • backupdr: added guest_flush field to google_backup_dr_backup_plan resource and google_backup_dr_backup data source. (#12230)
  • ces: added security_settings field to google_ces_deployment resource (#12227)
  • ces: added tool_execution_mode field to google_ces_app resource (#12221)
  • compute: added stabilization_period field to google_compute_autoscaler and google_compute_region_autoscaler resources (#12232)
  • compute: added support for "ARP_BROADCAST_PRIMARY_RANGE" values to the resolve_subnet_mask field in google_compute_subnetwork resource (#12176)
  • compute: added support for "GCE_VM_IP_DEDICATED_BACKEND" to the network_endpoint_type field in google_compute_network_endpoint_group resource (#12176)
  • compute: migrated data_source_google_compute_regions to use direct HTTP rather than a client library (#12202)
  • container: added pod_snapshot_config field to google_container_cluster resource (GA) (#12196)
  • container: added secret_sync_config field to google_container_cluster resource (ga) (#12215)
  • databasemigrationservice: added database and private_connectivity fields to google_database_migration_service_connection_profile resource (#12203)
  • databasemigrationservice: added postgres_homogeneous_config field to google_database_migration_service_migration_job resource (#12203)
  • databasemigrationservice: added psc_interface_config field to google_database_migration_service_private_connection resource (#12184)
  • hypercomputecluster: added terminal_storage_class and per_unit_storage_throughput fields to the google_hypercomputecluster_cluster resource (#12234)
  • netapp: added ontap_source field to google_netapp_backup resource (beta) (#12231)
  • provider: support for a deletion_policy field has been added to almost all resources in the provider. Details on its usage can be found within individual resource documentation if supported. (#12183)
  • storagebatchoperations: added description field to google_storage_batch_operations_job resource (#12207)
  • workstations: added workstation_authorization_url and workstation_launch_url fields to the google_workstations_workstation_cluster resource. (#12185)

BUG FIXES:

  • apigee: fixed forced replacement when importing google_apigee_sharedflow_deployment resource, where service_account read as null (#12228)
  • bigqueryconnection: fixed an issue where configuration.authentication.username_password.password.secret_type is not populated and a diff on configuration.authentication.username_password.username after import in google_bigquery_connection resource (#12179)
  • bigqueryreservation: Fixed google_bigquery_reservation_assignment returning a confusing 404 error when reservation is a bare name and location is not set (#12210)
  • ces: updated supported values for channel_type, modality, and theme in google_ces_deployment (#12227)
  • compute: updated google_compute_forwarding_rule resource to properly prompt for resource recreation when updating the target field between different "serviceAttachments", rather than having an in-place update blocked by an API error. (#12214)
  • modelarmor: fixed permadiff and REQUEST_FIELD_MISSING error when template_metadata is omitted from google_model_armor_template (#12222)
  • networkconnectivity: fixed an issue where google_network_connectivity_destination was not recognizing the name field as mapping to an API value (#12224)
  • networkconnectivity: fixed an issue where google_network_connectivity_multicloud_data_transfer_config was not recognizing the name field as mapping to an API value (#12224)
  • resourcemanager: added verification polling to google_service_account updates to ensure the resource is consistent before succeeding (#12217)

7.32.0 (May 12, 2026)

NOTES:

  • compute: migrated google_compute_instance_from_machine resource to use direct HTTP rather than a client library (#27260)
  • compute: migrated google_compute_instance_group_manager resource to use direct HTTP rather than a client library (#27259)
  • compute: migrated google_compute_zones data source to use direct HTTP rather than a client library (#27261)
  • compute: migrated google_compute_project_metadata_item resource to use direct HTTP rather than a client library (#27200)

FEATURES:

  • New Data Source: google_compute_region_instant_snapshot_iam_policy (#27281)
  • New Resource: google_chronicle_dashboard_chart (#27275)
  • New Resource: google_compute_region_instant_snapshot_iam_binding (#27281)
  • New Resource: google_compute_region_instant_snapshot_iam_member (#27281)
  • New Resource: google_compute_region_instant_snapshot_iam_policy (#27281)
  • New Resource: google_compute_region_instant_snapshot (#27281)

IMPROVEMENTS:

  • compute: added IDPF value to nic_type in resource_compute_instance_template (#27244)
  • compute: added IDPF value to nic_type in resource_compute_instance (#27244)
  • compute: added IDPF value to nic_type in resource_compute_region_instance_template (#27244)
  • compute: added address_id field to google_compute_address resource (#27216)
  • compute: added advanced_options_config field on google_compute_organization_security_policy resource (#27255)
  • compute: added connection_tracking_policy field to google_compute_region_backend_service resource (#27217)
  • compute: added image, source_image_encryption_key, and source_image_id fields to google_compute_region_disk resource. This field is currently behind an allowlist. (#27243)
  • compute: added replica_zones field to google_compute_instance resource (#27258)
  • compute: added request_body field on google_compute_security_policy_rule resource (#27252)
  • compute: added update support for ip_collection field to google_compute_subnetwork resource (#27265)
  • discoveryengine: added config_id attribute to google_discovery_engine_widget_config (#27278)
  • networksecurity: added support for project parent values to google_network_security_firewall_endpoint (#27222)
  • recaptchaenterprise: added POLICY_BASED_CHALLENGE value to integration_type field and added new challenge_settings field to google_recaptcha_enterprise_key (#27221)
  • redis: added new node types supported in google_redis_cluster. (#27242)
  • resourcemanager: add private_key and private_key_type fields to ephemeral google_service_account_key resource (#27279)
  • storage: added ingest_on_write field for google_storage_anywhere_cache resource (#27271)
  • workstations: added gce_hd field to google_workstations_workstation_config resource (#27201)

BUG FIXES:

  • cloudfunctions2: fixed bug where all_traffic_on_latest_revision = false was ignored in google_cloudfunctions2_function (#27256)
  • compute: fixed permadiff when removing preconfigured_waf_config from a google_compute_security_policy rule (#27276)

7.31.0 (May 5, 2026)

NOTES:

  • compute: migrated google_compute_instance.network_interface field to use direct HTTP rather than a client library (#27104)
  • compute: migrated google_compute_image datasource to use direct HTTP rather then a client library (#27179)
  • compute: migrated partner_metadata field on google_compute_instance, google_compute_instance_template, and google_compute_region_instance_template to use direct HTTP rather than a client library (#27131)
  • compute: migrated google_compute_node_types data source to use direct HTTP rather than a client library (#27184)
  • compute: migrated google_compute_region_instance_group data source to use direct HTTP rather than a client library (#27178)
  • compute: migrated google_compute_subnetwork data source to use direct HTTP rather than a client library (#27167)
  • compute: migrated google_compute_vpn_gateway data source to use direct HTTP rather than a client library (#27168)

FEATURES:

  • New Data Source: google_artifact_registry_file (#27183)
  • New Resource: google_ces_app_root_agent_association (#27123)
  • New Resource: google_contact_center_insights_qa_question (#27169)
  • New Resource: google_contact_center_insights_qa_scorecard_revision (#27169)
  • New Resource: google_contact_center_insights_qa_scorecard (#27169)
  • New Resource: google_firebase_app_check_resource_policy (#27185)

IMPROVEMENTS:

  • clouddeploy: added default_pool and private_pool fields to google_clouddeploy_target resource (#27187)
  • clouddeploy: added tasks and analysis fields to google_clouddeploy_delivery_pipeline resource (#27187)
  • compute: added params.resource_manager_tags field to google_compute_image (#27107)
  • compute: added params.resource_manager_tags field to google_compute_region_commitment resource (#27181)
  • compute: added resource_policies.workload_policy to google_compute_region_instance_group_manager resource (#27170)
  • compute: marked csek disk encryption key fields as sensitive in compute resources (#27193)
  • container: added node_pool.network_config.accelerator_network_profile to google_container_cluster resource and network_config.accelerator_network_profile to google_container_node_pool resource (#27171)
  • databasemigrationservice: added objects_config field to google_database_migration_service_migration_job resource (#27180)
  • dataplex: added attributes, template_reference, enable_catalog_basedRules, and filter fields to google_dataplex_datascan resource (#27130)
  • firestore: added search_config field to google_firestore_index resource (#27108)
  • oracle_database: added pluggable_database_id, pluggable_database_name fields to google_oracle_database_db_system resource (#27127)

BUG FIXES:

  • provider: fixed a bad timeouts diff across a number of resources that had resource identity support added in 7.29.0 (#27189)
  • assuredworkloads: made assuredworkloads resources use GA endpoint instead of beta (#27122)
  • bigquery: fixed ignore_auto_generated_schema evaluation for google_bigquery_table external tables which caused spurious replacement (#27188)
  • cloudscheduler: fixed perpetual diff on google_cloud_scheduler_job.http_target.headers when oidc_token or oauth_token is set (#27173)
  • servicenetworking: fixed a permadiff issue of reserved_peering_ranges in google_service_networking_connection (#27132)
  • storage: fix inconsistent plan issue for google_storage_notification.custom_attributes field (#27129)

7.30.0 (Apr 28, 2026)

BREAKING CHANGES:

  • apigee: fixed google_apigee_env_keystore to require the name field which is mandatory in the Apigee API (#27006)

FEATURES:

  • New Data Source: google_data_lineage_config (#27098)
  • New Resource: google_artifact_registry_rule (#27049)
  • New Resource: google_data_lineage_config (#27098)
  • New Resource: google_document_ai_schema (#27102)
  • New Resource: google_firebase_remote_config_remote_config (#27050)

IMPROVEMENTS:

  • provider: added support for prefer_global_endpoints and prefer_regional_endpoints to the provider configuration. Support for regional endpoints will be rolled out on a per-product level (#27014)
  • artifactregistry: added support for regionalized endpoints (#27014)
  • assuredworkloads: added SPAIN_DATA_BOUNDARY_BY_TELEFONICA value to partner field on google_assured_workloads_workload resource (#27027)
  • bigqueryconnection: added configuration block to google_bigquery_connection resource to support AlloyDB and other connector types via the BigQuery Connector framework (#27029)
  • bigtable: added support for tags to google_bigtable_instance (#27060)
  • cloudrunv2: added DISK fields to google_cloud_run_v2_job resource (#27052)
  • cloudrunv2: added DISK fields to google_cloud_run_v2_worker_pool resource (#27048)
  • compute: add params.resourceManagerTags field to the google_compute_storage_pool (#27051)
  • compute: added cache_policy field to google_compute_url_map (#27011)
  • compute: added params.resource_manager_tags field to google_compute_instant_snapshot resource (#27087)
  • compute: added resource_manager_tags field to google_compute_machine_image resource (#27075)
  • container: added node_config.linux_node_config.accurate_time_config field to google_container_node_pool resource (#27064)
  • container: added node_pool.node_config.linux_node_config.accurate_time_config and node_config.linux_node_config.accurate_time_config fields to google_container_cluster resource (#27064)
  • container: added node_pool.node_config.linux_node_config.swap_config field to google_container_node_pool resource (#26982)
  • container: increased default timeout for google_container_cluster to 90 minutes (from 40/60 depending on operation) and google_container_node_pool to 60 minutes (from 30) (#27101)
  • discoveryengine: added destionation_configs.destionations.port and destionation_configs.params fields to google_discovery_engine_data_connector resource (#27058)
  • dns: added support for IAM conditions to google_dns_managed_zone resource (#27010)
  • datastream: added deletion_policy field to control whether child routes are force-deleted to google_datastream_private_connection (#27033)
  • networkconnectivity: added support for IAM conditions to google_network_connectivity_hub resource (#27005)
  • networksecurity: added parent field to google_network_security_address_groups data source (#27082)
  • workbench: added support for new disk types and accelerators to google_workbench_instance (#27061)

BUG FIXES:

  • alloydb: fixed google_alloydb_cluster so that maintenance_update_policy.maintenance_windows.start_time.hours can be set to 0 (midnight) (#26981)
  • ces: fixed type mismatch in google_ces_app variable default value (#27084)
  • compute: fixed an issue where an erroneous error could occur for having an unset zone field in google_compute_instance_template (#27076)
  • compute: fixed permadiff for iap.oauth2_client_id in google_compute_backend_service and google_compute_region_backend_service when the API returns a single space (#26975)
  • container: fixed a permadiff in google_container_cluster where database_encryption.state returning ALL_OBJECTS_ENCRYPTION_ENABLED instead of the configured ENCRYPTED caused unintended reapplies (#27040)
  • dataplex: fixed acceptance test failure for one time scans (#27095)
  • dialogflowcx: fixed a perma-diff in google_dialogflow_cx_test_case when session_parameters was omitted from the configuration (#26985)
  • hypercomputecluster: fixed a permadiff in google_hypercomputecluster_cluster when count, static_node_count, or max_dynamic_node_count were explicitly set to 0. (#27073)
  • identityplatform: fixed a premadiff on multi_tenant in google_identity_platform_config resource. Removing the value from config will now preserve the existing settings instead of removing them. (#26986)
  • memorystore: fixed an issue preventing updating multiple properties at once for google_redis_cluster (#27077)

NOTES:

  • compute: Migrate resource_compute_instance_group.go.tmpl resource to use direct HTTP rather then a client library (#27080)
  • compute: migrated compute-operation resource to use direct HTTP rather then a client library (#27053)
  • compute: migrated compute_backend_bucket_security_policy resource to use direct HTTP rather than a client library (#27012)
  • compute: migrated compute_instance_network_interface_helpers resource to use direct HTTP rather than a client library (#27104)
  • compute: migrated data_source_google_compute_addresses.go.tmpl data source to use direct HTTP rather then a client library (#27016)
  • compute: migrated data_source_google_compute_machine_types datasource to use direct HTTP rather than a client library (#27017)
  • compute: migrated google_disk_test to use direct HTTP rather than a client library (#27079)
  • compute: migrated resource_compute_disk_async_replication resource to use direct HTTP rather then a client library (#27028)
  • compute: migrated resource_compute_http_health_check_test.go.tmpl resource to use direct HTTP rather then a client library (#27057)

7.29.0 (Apr 21, 2026)

NOTES:

  • provider: List resources are now supported in both google and google-beta providers with the introduction of google_service_account list resource - more info can be found here (#26938)

FEATURES:

  • New Data Source: google_firebase_admin_sdk_config (#26901)
  • New Resource: google_chronicle_datatable_row (#26960)
  • New Resource: google_chronicle_datatable (#26895)
  • New Resource: google_dataform_folder (#26881)
  • New Resource: google_dataform_team_folder (#26881)
  • New Resource: google_firebase_storage_default_bucket (#26965)

IMPROVEMENTS:

  • alloydb: added track_client_address field to google_alloydb_instance resource (#26964)
  • clouddeploy: added tasks field to google_clouddeploy_custom_target_type resource (#26941)
  • compute: added header_action and redirect_options fields to google_compute_organization_security_policy_rule resource (#26942)
  • dataplex: added execution_identity field to google_dataplex_datascan resource (#26924)
  • dataproc: added cluster_config.engine field to google_dataproc_cluster resource (#26962)
  • iambeta: added trust_default_shared_ca field to `go...

Don't miss a new terraform-provider-google release

NewReleases is sending notifications on new releases.