Skip to content

Add Terraform for Cloud Run, Cloud Run functions and Cloudflare Workers - #5

Merged
O6lvl4 merged 1 commit into
mainfrom
feat/terraform-google-cloudflare
Oct 4, 2026
Merged

O6lvl4 merged 1 commit into
mainfrom
feat/terraform-google-cloudflare

Conversation

@O6lvl4

@O6lvl4 O6lvl4 commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • providers/google-cloud-run/terraform: repository, runtime identity with no project roles, private /notes bucket, and the service with internal ingress, the invoker check, concurrency 1 and the same probes. Two applies, because the repository must exist before the image is pushed.
  • providers/google-cloud-functions/terraform: the staged package via google_cloudfunctions2_function (Node 24, internal-only ingress, build and runtime identities, /notes bucket).
  • providers/cloudflare-workers/terraform: KV namespace, Worker, a version with worker.js plus only the imported Wasm module and the NOTES binding, and a deployment. Unlike wrangler delete, destroy also removes the KV namespace.
  • Static tests guard the private shapes. check:workers now clears its output so a stale Wasm module can't be uploaded.

Test plan

  • Cloudflare: apply (4) → 18 cases + /notes 29/29 from the edge, KV verified → plan shows no changes → destroy (4)
  • Cloud Run: apply (8, then 2) → from in-VPC VM 18/18 + /notes 11/11, bucket verified, internet 404 / no token 403 → plan shows no changes → destroy (10)
  • Cloud Run functions: apply (16) → after invoker propagation, 18/18 octet-stream, the 3 known JSON rejections, /notes 11/11 → plan shows no changes → destroy (16). Cloud Functions' own gcf-v2-sources-* bucket and gcf-artifacts repo remain; documented
  • npm test 158/158, terraform fmt -check on all configs
  • GitHub Actions

🤖 Generated with Claude Code

Each configuration reproduces the CLI deployment's settings: internal
ingress, the invoker IAM check and invoker members only as given, runtime
identities with no project roles, private /notes buckets with a
bucket-scoped objectUser grant, and a Worker version with only the
imported Wasm module and the NOTES KV binding. Static tests guard those
shapes. check:workers now clears its output directory so a stale Wasm
module is never uploaded.

All three were applied, passed the 18 cases and the /notes scenario,
planned again with no changes, and were destroyed; the run, including
IAM propagation and resources Terraform does not manage, is recorded.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@O6lvl4
O6lvl4 merged commit e73081a into main Oct 4, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant