Claude code GCP compute instance example
(Redirected from Claude code compute instance example)
Jump to navigation
Jump to search
# main.tf resource "terraform_data" "network_validation" { lifecycle { precondition { condition = !(var.network != "" && var.subnetwork != "") error_message = "Only one of network or subnetwork should be specified, not both." } } }
resource "google_compute_resource_policy" "snapshot" {
count = var.enable_snapshots ? 1 : 0
name = "${var.name}-snapshot-policy"
project = var.project_id
region = var.region
snapshot_schedule_policy {
schedule {
daily_schedule {
days_in_cycle = var.snapshot_days_in_cycle
start_time = var.snapshot_start_time
}
}
retention_policy {
max_retention_days = var.retention_days
}
snapshot_properties {
guest_flush = var.guest_flush
# empty list defaults to the disk's region
storage_locations = var.storage_locations
}
}
}
resource "google_compute_address" "static_ip" {
count = var.static_ip_name != null ? 1 : 0
name = var.static_ip_name
project = var.project_id
region = var.region
network_tier = var.network_tier
}
module "instance_template" {
source = "terraform-google-modules/vm/google//modules/instance_template"
version = "~> 13.0"
project_id = var.project_id machine_type = var.machine_type region = var.region network = var.network subnetwork = var.subnetwork subnetwork_project = var.subnetwork_project
disk_size_gb = var.disk_size_gb disk_type = var.disk_type source_image = var.boot_image
disk_resource_policies = var.enable_snapshots ? [
google_compute_resource_policy.snapshot[0].id
] : []
service_account = var.service_account_email != null ? {
email = var.service_account_email
scopes = var.service_account_scopes
} : null
tags = var.tags labels = var.labels startup_script = var.startup_script metadata = var.metadata
shielded_instance_config = {
enable_secure_boot = var.enable_secure_boot
enable_vtpm = var.enable_vtpm
enable_integrity_monitoring = var.enable_integrity_monitoring
}
}
module "compute_instance" { source = "terraform-google-modules/vm/google//modules/compute_instance" version = "~> 13.0"
project_id = var.project_id region = var.region zone = var.zone subnetwork = var.subnetwork # self_link_unique recommended over self_link for correct rolling update behaviour instance_template = module.instance_template.self_link_unique hostname = var.name num_instances = 1 deletion_protection = var.deletion_protection
access_config = var.static_ip_name != null ? [{
nat_ip = google_compute_address.static_ip[0].address
network_tier = var.network_tier
}] : []
}
# variables.tf variable "project_id" { description = "GCP project ID" type = string }
variable "region" {
description = "GCP region"
type = string
}
variable "zone" {
description = "GCP zone"
type = string
}
variable "name" {
description = "Instance name. Must start with a lowercase letter, contain
only lowercase letters, numbers, and hyphens, and be at most 63
characters."
type = string
validation {
condition = can(regex("^[a-z][a-z0-9-]{0,62}$", var.name))
error_message = "name must start with a lowercase letter, contain only
lowercase letters, numbers, and hyphens, and be at most 63 characters."
}
}
variable "machine_type" {
description = "GCP machine type (e.g. n2-standard-2)"
type = string
}
variable "network" {
description = "VPC network name. Only one of network or subnetwork should
be specified."
type = string
default = ""
}
variable "subnetwork" {
description = "Subnetwork name or full self-link. Use full self-link for
shared VPC: projects/HOST_PROJECT/regions/REGION/subnetworks/NAME. Only one
of network or subnetwork should be specified."
type = string
default = ""
}
variable "subnetwork_project" {
description = "Project of the subnetwork for shared VPC. Only used by
instance_template — for compute_instance pass the full subnetwork self-link
instead."
type = string
default = ""
}
variable "boot_image" {
description = "Boot disk image (e.g. debian-cloud/debian-12)"
type = string
}
variable "disk_size_gb" {
description = "Boot disk size in GB"
type = number
default = 50
validation {
condition = var.disk_size_gb >= 10
error_message = "disk_size_gb must be at least 10 GB."
}
}
variable "disk_type" {
description = "Boot disk type"
type = string
default = "pd-ssd"
validation {
condition = contains(["pd-ssd", "pd-standard", "pd-balanced",
"pd-extreme"], var.disk_type)
error_message = "disk_type must be pd-ssd, pd-standard, pd-balanced, or
pd-extreme."
}
}
variable "service_account_email" {
description = "Service account email to attach. If null, no service
account is attached."
type = string
default = null
}
variable "service_account_scopes" {
description = "Scopes for the service account. Narrow this in production
— cloud-platform grants full API access."
type = set(string)
default = ["cloud-platform"]
}
variable "static_ip_name" {
description = "Name for a static external IP. If null, no external IP is
allocated."
type = string
default = null
}
variable "network_tier" {
description = "Network tier for the static IP and access config"
type = string
default = "PREMIUM"
validation {
condition = contains(["PREMIUM", "STANDARD"], var.network_tier)
error_message = "network_tier must be PREMIUM or STANDARD."
}
}
variable "deletion_protection" {
description = "Prevent accidental deletion of the instance"
type = bool
default = false
}
variable "tags" {
description = "Network tags to apply to the instance"
type = list(string)
default = []
}
variable "labels" {
description = "Labels to apply to the instance"
type = map(string)
default = {}
}
variable "metadata" {
description = "Metadata key/value pairs to apply to the instance"
type = map(string)
default = {}
}
variable "startup_script" {
description = "Startup script content. If null, defaults to apt
update/upgrade."
type = string
default = null
}
variable "enable_secure_boot" {
description = "Enable Shielded VM secure boot"
type = bool
default = true
}
variable "enable_vtpm" {
description = "Enable Shielded VM vTPM"
type = bool
default = true
}
variable "enable_integrity_monitoring" {
description = "Enable Shielded VM integrity monitoring"
type = bool
default = true
}
variable "enable_snapshots" {
description = "Enable automated daily disk snapshots"
type = bool
default = true
}
variable "retention_days" {
description = "Number of days to retain snapshots"
type = number
default = 10
validation {
condition = var.retention_days >= 1 && var.retention_days <= 365
error_message = "retention_days must be between 1 and 365."
}
}
variable "snapshot_days_in_cycle" {
description = "Snapshot frequency in days (1 = daily, 7 = weekly)"
type = number
default = 1
validation {
condition = var.snapshot_days_in_cycle >= 1 &&
var.snapshot_days_in_cycle <= 7
error_message = "snapshot_days_in_cycle must be between 1 and 7."
}
}
variable "snapshot_start_time" {
description = "Snapshot start time in HH:00 format (UTC). GCP requires
on-the-hour scheduling."
type = string
default = "23:00"
validation {
condition = can(regex("^([01]\\d|2[0-3]):00$",
var.snapshot_start_time))
error_message = "snapshot_start_time must be in HH:00 format (on the
hour, UTC), e.g. 23:00."
}
}
variable "guest_flush" {
description = "Enable guest-aware (application-consistent) snapshots"
type = bool
default = false
}
variable "storage_locations" {
description = "Storage locations for snapshots. Empty list defaults to
the disk's region."
type = list(string)
default = []
}
# outputs.tf
output "instance_name" {
description = "Name of the compute instance"
value = module.compute_instance.instance_name
}
output "instance_self_link" {
description = "Self-link of the compute instance"
value = module.compute_instance.instances_self_links[0]
}
output "internal_ip" {
description = "Internal IP address of the instance"
value = nonsensitive(module.compute_instance.instances_details[0].n
etwork_interface[0].network_ip)
}
output "external_ip" {
description = "External IP address of the instance. Null if no static IP
was allocated."
value = var.static_ip_name != null ?
google_compute_address.static_ip[0].address : null
}
output "service_account_email" {
description = "Service account email attached to the instance"
value = module.compute_instance.service_account_email
}
# versions.tf
terraform {
required_version = ">= 1.4"
required_providers {
google = {
source = "hashicorp/google"
version = "~> 6.0"
}
}
}
See also[edit]
Advertising: