Add Terraform for Cloud Run, Cloud Run functions and Cloudflare Workers - #5
Merged
Merged
Conversation
Each configuration reproduces the CLI deployment's settings: internal ingress, the invoker IAM check and invoker members only as given, runtime identities with no project roles, private /notes buckets with a bucket-scoped objectUser grant, and a Worker version with only the imported Wasm module and the NOTES KV binding. Static tests guard those shapes. check:workers now clears its output directory so a stale Wasm module is never uploaded. All three were applied, passed the 18 cases and the /notes scenario, planned again with no changes, and were destroyed; the run, including IAM propagation and resources Terraform does not manage, is recorded. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
providers/google-cloud-run/terraform: repository, runtime identity with no project roles, private/notesbucket, and the service with internal ingress, the invoker check, concurrency 1 and the same probes. Two applies, because the repository must exist before the image is pushed.providers/google-cloud-functions/terraform: the staged package viagoogle_cloudfunctions2_function(Node 24, internal-only ingress, build and runtime identities,/notesbucket).providers/cloudflare-workers/terraform: KV namespace, Worker, a version withworker.jsplus only the imported Wasm module and theNOTESbinding, and a deployment. Unlikewrangler delete,destroyalso removes the KV namespace.check:workersnow clears its output so a stale Wasm module can't be uploaded.Test plan
/notes29/29 from the edge, KV verified → plan shows no changes → destroy (4)/notes11/11, bucket verified, internet 404 / no token 403 → plan shows no changes → destroy (10)/notes11/11 → plan shows no changes → destroy (16). Cloud Functions' owngcf-v2-sources-*bucket andgcf-artifactsrepo remain; documentednpm test158/158,terraform fmt -checkon all configs🤖 Generated with Claude Code