The most significant behavioral change in the 8.0 release affects google_compute_backend_service and google_compute_global_forwarding_rule resources. The default load_balancing_scheme has shifted from EXTERNAL to EXTERNAL_MANAGED, meaning configurations that do not explicitly set this field will now use Google Cloud's external Application Load Balancer instead of the Classic variant. Teams relying on Classic behavior must set load_balancing_scheme = "EXTERNAL" in their configurations to avoid unexpected plan changes to existing load balancers.
The update also removes several resources whose backing services have been shut down or replaced. Removed resources include google_iap_brand and google_iap_client (following the IAP OAuth Admin APIs shutdown), the three google_notebooks_* resources (users should migrate to google_workbench_instance), google_ml_engine_model, and the BeyondCorp app connection, connector, and gateway resources (with Security Gateway resources as the replacement). google_vertex_ai_schedule is replaced by google_colab_schedule. Configurations referencing any of these must be updated before upgrading.
On schema behavior, attributes where ordering carries no meaning have been changed from lists to sets. This applies to fields in Compute Service Attachments, GKE logging and monitoring configuration, and Cloud Security Compliance Frameworks. HashiCorp says this prevents perpetual diffs when an API returns values in a different order than the configuration. Validation is now stricter for some Google Cloud APIs: source_contents is required for google_workflows_workflow, and claim_mapping is needed when creating Workforce Identity Pool Provider SCIM tenants. Some state changes, such as integer-to-string conversions, migrate automatically, but others require configuration edits.
Version 8.0 also builds on capabilities introduced in the 7.x line, including support for Terraform list resources that work with the terraform query workflow, allowing users to search for existing infrastructure outside of the state and optionally create resource and import configurations. Coverage spans Compute Engine, IAM, BigQuery, Pub/Sub, Secret Manager, Migration Center, and Network Services.