Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

HashiCorp announced general availability of Terraform’s Google Cloud provider 8.0 on September 22, 2026. Treat it as a breaking major upgrade: the default load-balancing scheme changes, and resources for retired or replaced Google Cloud services are removed. Before upgrading, check the official migration guide against your configuration and state, then review the plan for unexpected replacements or destroys.

What changes in Google Cloud provider 8.0?

HashiCorp describes 8.0 as a release that updates provider defaults, removes support for retired or replaced services, and improves consistency between Terraform configuration and Google Cloud APIs. The release also follows 7.x work on infrastructure discovery: list resources and terraform query can help find existing resources outside Terraform state and, where supported, generate resource and import configuration. Support introduced during the 7.x cycle spans services including Compute Engine, IAM, BigQuery, Pub/Sub, Secret Manager, Migration Center, and Network Services.

Across the 7.x cycle, the provider also added write-only attribute support for some sensitive values, including certificate private keys, AlloyDB passwords, and IAP credentials. A write-only attribute lets a value be sent to an API without storing that value in Terraform state; this support does not apply to every sensitive field.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Will the load-balancer default change affect your configuration?

In provider 8.0, the default for load_balancing_scheme changes from EXTERNAL to EXTERNAL_MANAGED on google_compute_backend_service and google_compute_global_forwarding_rule. HashiCorp’s stated default applies to those resource types; check your actual resources and plan rather than assuming every load-balancer resource is affected.

If a configuration must retain Classic Application Load Balancer behavior, set the scheme explicitly:

load_balancing_scheme = "EXTERNAL"

Otherwise, the new default can change the intended configuration when you move to 8.0. Review any resulting plan carefully before applying it.

Which resources and services were removed?

Provider 8.0 removes resources and data sources associated with retired or replaced Google Cloud services. The examples below are not an exhaustive list; consult the version 8.0 upgrade guide and v8.0.0 release notes for the full set of removed resources, fields, and arguments.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Removed resource or group Migration direction identified by HashiCorp
google_iap_brand and google_iap_client Associated with the retired IAP OAuth Admin API; review the guide for the appropriate migration for your use case.
Notebooks environments, instances, and runtimes Move to Workbench where it fits the workloads and service behavior you manage.
google_ml_engine_model Machine-learning deployments are moving to Vertex AI.
BeyondCorp app connection, connector, and gateway resources Security Gateway resources are identified as the replacement direction.
google_vertex_ai_schedule Use google_colab_schedule as the replacement resource.

A replacement is not necessarily a drop-in substitute. Compare the replacement service with the behavior you need, update configuration, and follow resource-specific state guidance before applying changes.

What schema, validation, and state changes should you check?

  • List-to-set changes: Some unordered attributes change from lists to sets. Review configuration that depends on ordering or produces diffs for those attributes.
  • Stricter validation: Some fields required by the underlying Google Cloud API are now validated more strictly. Correct incomplete configurations before applying.
  • Integer-to-string migrations: State migrations are included for some integer-to-string changes. Check the upgrade guide for affected fields and resource-specific instructions.

HashiCorp says these changes are intended to prevent perpetual diffs and catch configuration problems during planning; that is the vendor’s stated aim, not a measured guarantee for every configuration.

How to upgrade to provider 8.0 safely

  1. Start on the latest 7.x release. Upgrade first and resolve existing deprecation warnings, as HashiCorp recommends.
  2. Check the migration guidance. Review the provider 8.0 upgrade guide and release notes for removals, validation changes, state migrations, and resource-specific steps. Match those changes to the resources and fields in your own configuration.
  3. Update the version constraint and initialize. Set the provider constraint to allow the version you intend to test, then run terraform init. HashiCorp documents terraform init -upgrade for selecting a newer version allowed by the configured constraints and updating the dependency lock file; it does not override a constraint that excludes that version. See provider version configuration.
  4. Set Classic load balancing explicitly where required. Add load_balancing_scheme = "EXTERNAL" to affected backend-service or global-forwarding-rule resources that must keep Classic Application Load Balancer behavior.
  5. Test outside production and inspect the plan. Run terraform plan in a non-production environment. Investigate planned destroys and replacements, along with changes to load-balancer behavior, removed resources, and state-sensitive fields. Do not apply until the planned changes are understood.

What happens if you need to downgrade?

The upgrade guide says that running only terraform init or terraform plan does not modify state. If you have run terraform refresh or terraform apply, downgrading may require refreshing state or restoring a prior version from a versioned remote backend. Resources created in the meantime may need to be deleted manually or imported. Check the guide and your backend’s recovery options before changing provider versions.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Is 8.0 the latest provider version?

No: the provider repository’s releases page showed v8.1.0 and later 8.x releases after v8.0.0 when checked on October 9, 2026. The September 22 announcement is about 8.0’s general availability, not a claim that 8.0 remains the latest point release. Check the provider releases page and the version constraint in your configuration when selecting a version.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.