* feat(agent-engine): add support for container and custom image specs - Add container_config to deployment_files. - Add image_spec with build_args to source_config. - Make agent_framework optional and document supported values. - Implement dynamic specs for container and source deployments. - Add examples and automated tests for new deployment types. * chore: update Google provider version to 7.28.0 across modules Mechanical update of versions.tf and versions.tofu files using tools/versions.py. * feat(agent-engine): refactor for container deployments and API alignment - Group deployment settings under 'deployment_config' (renamed from 'deployment_files'). - Support container-based deployments via 'container_config' and 'image_spec'. - Refactor 'source_files_config' (renamed from 'source_config') to include mutually exclusive 'python_spec' and 'image_spec'. - Support 'developer_connect_config' as a source code type. - Group engine settings (framework, env, secrets) under 'agent_engine_config'. - Add support for 'memory_bank_config' persistent memory. - Overhaul reasoning engine resources with dynamic blocks to match provider schema. - Update all documentation examples, add TOC, and refresh test inventories. * Update dynamic python_spec block and related example yamls * Ignore changes setting for developer_connect_source under lifecycle management * fixing review comments for `try` and default path for `source_path` --------- Co-authored-by: Hemanand <hemr@google.com> Co-authored-by: Julio Castillo <jccb@google.com>
Google Cloud Source Repository Module
This module allows managing a single Cloud Source Repository, including IAM bindings and basic Cloud Build triggers.
Examples
Repository with IAM
module "repo" {
source = "./fabric/modules/source-repository"
project_id = "my-project"
name = "my-repo"
iam = {
"roles/source.reader" = ["user:foo@example.com"]
}
iam_bindings_additive = {
am1-reader = {
member = "user:am1@example.com"
role = "roles/source.reader"
}
}
}
# tftest modules=1 resources=3 inventory=simple.yaml
Repository with Cloud Build trigger
module "repo" {
source = "./fabric/modules/source-repository"
project_id = "my-project"
name = "my-repo"
triggers = {
foo = {
filename = "ci/workflow-foo.yaml"
included_files = ["**/*tf"]
service_account = null
substitutions = {
BAR = 1
}
template = {
branch_name = "main"
project_id = null
tag_name = null
}
}
}
}
# tftest modules=1 resources=2 inventory=trigger.yaml
Files
| name | description | resources |
|---|---|---|
| iam.tf | IAM bindings. | google_sourcerepo_repository_iam_binding · google_sourcerepo_repository_iam_member |
| main.tf | Module-level locals and resources. | google_cloudbuild_trigger · google_sourcerepo_repository |
| outputs.tf | Module outputs. | |
| variables-iam.tf | None | |
| variables.tf | Module variables. | |
| versions.tf | Version pins. |
Variables
| name | description | type | required | default |
|---|---|---|---|---|
| name | Repository name. | string |
✓ | |
| project_id | Project used for resources. | string |
✓ | |
| iam | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) |
{} |
|
| iam_bindings | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) |
{} |
|
| iam_bindings_additive | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) |
{} |
|
| iam_by_principals | Authoritative IAM binding in {PRINCIPAL => [ROLES]} format. Principals need to be statically defined to avoid cycle errors. Merged internally with the iam variable. |
map(list(string)) |
{} |
|
| triggers | Cloud Build triggers. | map(object({…})) |
{} |
Outputs
| name | description | sensitive |
|---|---|---|
| id | Fully qualified repository id. | |
| name | Repository name. | |
| url | Repository URL. |