From a3f7faf7d428f085d343b00920750ab9da746101 Mon Sep 17 00:00:00 2001 From: Ludovico Magnocavallo Date: Mon, 1 Sep 2025 14:45:42 +0200 Subject: [PATCH] Fix boot disk source/params in compute vm module (#3292) --- modules/compute-vm/README.md | 62 ++++++++++++++++----------------- modules/compute-vm/main.tf | 2 ++ modules/compute-vm/variables.tf | 7 ++-- 3 files changed, 35 insertions(+), 36 deletions(-) diff --git a/modules/compute-vm/README.md b/modules/compute-vm/README.md index 81b0d8839..fe6f3fae8 100644 --- a/modules/compute-vm/README.md +++ b/modules/compute-vm/README.md @@ -941,39 +941,39 @@ module "sole-tenancy" { | name | description | type | required | default | |---|---|:---:|:---:|:---:| -| [name](variables.tf#L273) | Instance name. | string | ✓ | | -| [network_interfaces](variables.tf#L285) | Network interfaces configuration. Use self links for Shared VPC, set addresses to null if not needed. | list(object({…})) | ✓ | | -| [project_id](variables.tf#L370) | Project id. | string | ✓ | | -| [zone](variables.tf#L483) | Compute zone. | string | ✓ | | +| [name](variables.tf#L270) | Instance name. | string | ✓ | | +| [network_interfaces](variables.tf#L282) | Network interfaces configuration. Use self links for Shared VPC, set addresses to null if not needed. | list(object({…})) | ✓ | | +| [project_id](variables.tf#L367) | Project id. | string | ✓ | | +| [zone](variables.tf#L480) | Compute zone. | string | ✓ | | | [attached_disk_defaults](variables.tf#L17) | Defaults for attached disks options. | object({…}) | | {…} | | [attached_disks](variables.tf#L37) | Additional disks, if options is null defaults will be used in its place. Source type is one of 'image' (zonal disks in vms and template), 'snapshot' (vm), 'existing', and null. | list(object({…})) | | [] | -| [boot_disk](variables.tf#L82) | Boot disk properties. | object({…}) | | {…} | -| [can_ip_forward](variables.tf#L116) | Enable IP forwarding. | bool | | false | -| [confidential_compute](variables.tf#L122) | Enable Confidential Compute for these instances. | bool | | false | -| [create_template](variables.tf#L128) | Create instance template instead of instances. Defaults to a global template. | object({…}) | | null | -| [description](variables.tf#L137) | Description of a Compute Instance. | string | | "Managed by the compute-vm Terraform module." | -| [enable_display](variables.tf#L143) | Enable virtual display on the instances. | bool | | false | -| [encryption](variables.tf#L149) | Encryption options. Only one of kms_key_self_link and disk_encryption_key_raw may be set. If needed, you can specify to encrypt or not the boot disk. | object({…}) | | null | -| [gpu](variables.tf#L159) | GPU information. Based on https://cloud.google.com/compute/docs/gpus. | object({…}) | | null | -| [group](variables.tf#L194) | Define this variable to create an instance group for instances. Disabled for template use. | object({…}) | | null | -| [hostname](variables.tf#L202) | Instance FQDN name. | string | | null | -| [iam](variables.tf#L208) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | -| [instance_schedule](variables.tf#L214) | Assign or create and assign an instance schedule policy. Either resource policy id or create_config must be specified if not null. Set active to null to dtach a policy from vm before destroying. | object({…}) | | null | -| [instance_type](variables.tf#L249) | Instance type. | string | | "f1-micro" | -| [labels](variables.tf#L255) | Instance labels. | map(string) | | {} | -| [metadata](variables.tf#L261) | Instance metadata. | map(string) | | {} | -| [min_cpu_platform](variables.tf#L267) | Minimum CPU platform. | string | | null | -| [network_attached_interfaces](variables.tf#L278) | Network interfaces using network attachments. | list(string) | | [] | -| [network_tag_bindings](variables.tf#L306) | Resource manager tag bindings in arbitrary key => tag key or value id format. Set on both the instance only for networking purposes, and modifiable without impacting the main resource lifecycle. | map(string) | | {} | -| [options](variables.tf#L313) | Instance options. | object({…}) | | {…} | -| [project_number](variables.tf#L375) | Project number. Used in tag bindings to avoid a permadiff. | string | | null | -| [scratch_disks](variables.tf#L381) | Scratch disks configuration. | object({…}) | | {…} | -| [service_account](variables.tf#L393) | Service account email and scopes. If email is null, the default Compute service account will be used unless auto_create is true, in which case a service account will be created. Set the variable to null to avoid attaching a service account. | object({…}) | | {} | -| [shielded_config](variables.tf#L403) | Shielded VM configuration of the instances. | object({…}) | | null | -| [snapshot_schedules](variables.tf#L413) | Snapshot schedule resource policies that can be attached to disks. | map(object({…})) | | {} | -| [tag_bindings](variables.tf#L456) | Resource manager tag bindings in arbitrary key => tag key or value id format. Set on both the instance and zonal disks, and modifiable without impacting the main resource lifecycle. | map(string) | | {} | -| [tag_bindings_immutable](variables.tf#L463) | Immutable resource manager tag bindings, in tagKeys/id => tagValues/id format. These are set on the instance or instance template at creation time, and trigger recreation if changed. | map(string) | | null | -| [tags](variables.tf#L477) | Instance network tags for firewall rule targets. | list(string) | | [] | +| [boot_disk](variables.tf#L82) | Boot disk properties. Initialize params are ignored when source is set. | object({…}) | | {…} | +| [can_ip_forward](variables.tf#L113) | Enable IP forwarding. | bool | | false | +| [confidential_compute](variables.tf#L119) | Enable Confidential Compute for these instances. | bool | | false | +| [create_template](variables.tf#L125) | Create instance template instead of instances. Defaults to a global template. | object({…}) | | null | +| [description](variables.tf#L134) | Description of a Compute Instance. | string | | "Managed by the compute-vm Terraform module." | +| [enable_display](variables.tf#L140) | Enable virtual display on the instances. | bool | | false | +| [encryption](variables.tf#L146) | Encryption options. Only one of kms_key_self_link and disk_encryption_key_raw may be set. If needed, you can specify to encrypt or not the boot disk. | object({…}) | | null | +| [gpu](variables.tf#L156) | GPU information. Based on https://cloud.google.com/compute/docs/gpus. | object({…}) | | null | +| [group](variables.tf#L191) | Define this variable to create an instance group for instances. Disabled for template use. | object({…}) | | null | +| [hostname](variables.tf#L199) | Instance FQDN name. | string | | null | +| [iam](variables.tf#L205) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | +| [instance_schedule](variables.tf#L211) | Assign or create and assign an instance schedule policy. Either resource policy id or create_config must be specified if not null. Set active to null to dtach a policy from vm before destroying. | object({…}) | | null | +| [instance_type](variables.tf#L246) | Instance type. | string | | "f1-micro" | +| [labels](variables.tf#L252) | Instance labels. | map(string) | | {} | +| [metadata](variables.tf#L258) | Instance metadata. | map(string) | | {} | +| [min_cpu_platform](variables.tf#L264) | Minimum CPU platform. | string | | null | +| [network_attached_interfaces](variables.tf#L275) | Network interfaces using network attachments. | list(string) | | [] | +| [network_tag_bindings](variables.tf#L303) | Resource manager tag bindings in arbitrary key => tag key or value id format. Set on both the instance only for networking purposes, and modifiable without impacting the main resource lifecycle. | map(string) | | {} | +| [options](variables.tf#L310) | Instance options. | object({…}) | | {…} | +| [project_number](variables.tf#L372) | Project number. Used in tag bindings to avoid a permadiff. | string | | null | +| [scratch_disks](variables.tf#L378) | Scratch disks configuration. | object({…}) | | {…} | +| [service_account](variables.tf#L390) | Service account email and scopes. If email is null, the default Compute service account will be used unless auto_create is true, in which case a service account will be created. Set the variable to null to avoid attaching a service account. | object({…}) | | {} | +| [shielded_config](variables.tf#L400) | Shielded VM configuration of the instances. | object({…}) | | null | +| [snapshot_schedules](variables.tf#L410) | Snapshot schedule resource policies that can be attached to disks. | map(object({…})) | | {} | +| [tag_bindings](variables.tf#L453) | Resource manager tag bindings in arbitrary key => tag key or value id format. Set on both the instance and zonal disks, and modifiable without impacting the main resource lifecycle. | map(string) | | {} | +| [tag_bindings_immutable](variables.tf#L460) | Immutable resource manager tag bindings, in tagKeys/id => tagValues/id format. These are set on the instance or instance template at creation time, and trigger recreation if changed. | map(string) | | null | +| [tags](variables.tf#L474) | Instance network tags for firewall rule targets. | list(string) | | [] | ## Outputs diff --git a/modules/compute-vm/main.tf b/modules/compute-vm/main.tf index 38c75f0a9..f2c0faf35 100644 --- a/modules/compute-vm/main.tf +++ b/modules/compute-vm/main.tf @@ -230,6 +230,8 @@ resource "google_compute_instance" "default" { var.boot_disk.initialize_params == null || var.boot_disk.use_independent_disk + || + var.boot_disk.source != null ? [] : [""] ) diff --git a/modules/compute-vm/variables.tf b/modules/compute-vm/variables.tf index 7ac8ef67b..cafb63b99 100644 --- a/modules/compute-vm/variables.tf +++ b/modules/compute-vm/variables.tf @@ -80,7 +80,7 @@ variable "attached_disks" { } variable "boot_disk" { - description = "Boot disk properties." + description = "Boot disk properties. Initialize params are ignored when source is set." type = object({ auto_delete = optional(bool, true) snapshot_schedule = optional(list(string)) @@ -97,10 +97,7 @@ variable "boot_disk" { } nullable = false validation { - condition = ( - (var.boot_disk.source == null ? 0 : 1) + - (var.boot_disk.initialize_params == null ? 0 : 1) < 2 - ) + condition = var.boot_disk.source != null || var.boot_disk.initialize_params != null error_message = "You can only have one of boot disk source or initialize params." } validation {