Terraform Google Cloud Provider 8.0 arrives with major breaking changes

Default load balancing shifts to EXTERNAL_MANAGED, retired services support removed

By LineZotpaper
Published
Read Time2 min
HashiCorp has released version 8.0 of its Terraform provider for Google Cloud in general availability, introducing breaking changes including a new default load balancing scheme and removal of resources tied to retired Google Cloud services. The company recommends users upgrade to the latest 7.x release first and clear all deprecation warnings before migrating.

The most significant behavioral change in the 8.0 release affects google_compute_backend_service and google_compute_global_forwarding_rule resources. The default load_balancing_scheme has shifted from EXTERNAL to EXTERNAL_MANAGED, meaning configurations that do not explicitly set this field will now use Google Cloud's external Application Load Balancer instead of the Classic variant. Teams relying on Classic behavior must set load_balancing_scheme = "EXTERNAL" in their configurations to avoid unexpected plan changes to existing load balancers.

The update also removes several resources whose backing services have been shut down or replaced. Removed resources include google_iap_brand and google_iap_client (following the IAP OAuth Admin APIs shutdown), the three google_notebooks_* resources (users should migrate to google_workbench_instance), google_ml_engine_model, and the BeyondCorp app connection, connector, and gateway resources (with Security Gateway resources as the replacement). google_vertex_ai_schedule is replaced by google_colab_schedule. Configurations referencing any of these must be updated before upgrading.

On schema behavior, attributes where ordering carries no meaning have been changed from lists to sets. This applies to fields in Compute Service Attachments, GKE logging and monitoring configuration, and Cloud Security Compliance Frameworks. HashiCorp says this prevents perpetual diffs when an API returns values in a different order than the configuration. Validation is now stricter for some Google Cloud APIs: source_contents is required for google_workflows_workflow, and claim_mapping is needed when creating Workforce Identity Pool Provider SCIM tenants. Some state changes, such as integer-to-string conversions, migrate automatically, but others require configuration edits.

Version 8.0 also builds on capabilities introduced in the 7.x line, including support for Terraform list resources that work with the terraform query workflow, allowing users to search for existing infrastructure outside of the state and optionally create resource and import configurations. Coverage spans Compute Engine, IAM, BigQuery, Pub/Sub, Secret Manager, Migration Center, and Network Services.

§

Analysis

Why This Matters

  • Teams using Terraform to manage Google Cloud infrastructure must plan for migration, as upgrading to 8.0 without preparation may cause unintended changes to load balancers and require configuration edits.
  • The removal of resources for retired services pushes users to adopt newer Google Cloud equivalents, which may involve architectural changes.
  • The shift from lists to sets eliminates a common source of spurious plan diffs, improving the reliability of infrastructure-as-code workflows.

Background

Terraform is an infrastructure-as-code tool that allows users to define and provision cloud resources using declarative configuration files. Providers are plugins that translate Terraform's generic API into specific resource types for each cloud platform. Version 8.0 is a major release of the Google Cloud provider, meaning it introduces breaking changes that require users to update their configurations before upgrading.

Key Perspectives

HashiCorp: The company positions the update as necessary to align with Google Cloud's evolving service portfolio and to improve the user experience by preventing perpetual diffs. The recommendation to clear deprecation warnings before upgrading signals a focus on smooth migration. Terraform users managing GCP resources: Users face a trade-off between adopting new capabilities and dealing with migration effort. Those with large codebases referencing removed resources or relying on the old load balancing default will need to invest time in updates.

What to Watch

  • Adoption rate of the new provider version and reports of migration issues from the community.
  • Whether Google Cloud announces further service retirements that could trigger additional resource removals in future provider versions.
  • How HashiCorp handles deprecation communication and tooling to assist users in identifying affected configurations.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe