Skip to content

feat(destroy): default to robust destroy for all gcluster destroy operations - #6190

Draft
Neelabh94 wants to merge 1 commit into
GoogleCloudPlatform:developfrom
Neelabh94:robust_destroy
Draft

feat(destroy): default to robust destroy for all gcluster destroy operations#6190
Neelabh94 wants to merge 1 commit into
GoogleCloudPlatform:developfrom
Neelabh94:robust_destroy

Conversation

@Neelabh94

Copy link
Copy Markdown
Contributor

This PR makes robust as the default for destroy.

Submission Checklist

NOTE: Community submissions can take up to 2 weeks to be reviewed.

Please take the following actions before submitting this pull request.

  • Fork your PR branch from the Toolkit "develop" branch (not main)
  • Test all changes with pre-commit in a local branch #
  • Confirm that "make tests" passes all tests
  • Add or modify unit tests to cover code changes
  • Ensure that unit test coverage remains above 80%
  • Update all applicable documentation
  • Follow Cluster Toolkit Contribution guidelines #

@Neelabh94 Neelabh94 added the release-improvements Added to release notes under the "Improvements" heading. label Aug 21, 2026
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request modifies the default behavior of the destroy command by enabling the robust destruction process automatically. This change ensures that firewall rule cleanup is performed by default, while still allowing users to opt-out by explicitly passing the flag.

Highlights

  • Default behavior change: Updated the 'robust' flag in the destroy command to be enabled by default.
  • Documentation update: Updated the command-line documentation to reflect that the robust destroy process is now the default behavior.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request changes the default value of the --robust flag in the destroy command from false to true and updates the documentation accordingly. However, feedback highlights that setting this to true by default introduces a critical regression: if the firewall cleanup fails, the command aborts early and skips the actual terraform destroy for subsequent groups. The reviewer recommends keeping the default as false or refactoring the cleanup to be non-fatal.

Comment thread cmd/destroy.go
addAutoApproveFlag(
addArtifactsDirFlag(destroyCmd))))
destroyCmd.Flags().BoolVar(&robustDestroy, "robust", false, "Perform a robust destroy, including firewall rule cleanup.")
destroyCmd.Flags().BoolVar(&robustDestroy, "robust", true, "Perform a robust destroy, including firewall rule cleanup.")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

Changing the default of --robust to true introduces a critical regression in the destroy command.

The Issue

When robustDestroy is true (which is now the default), destroyGroup attempts to clean up firewall rules if a network module is present. If this cleanup fails (e.g., due to missing ADC or permissions), it immediately aborts the loop, skipping the actual terraform destroy for this and subsequent groups.

Recommendation

In accordance with our state cleanup guidelines, we should use a best-effort approach for cleanup operations. Instead of failing fast and aborting the entire destroy sequence, the firewall cleanup failures should be logged as errors/warnings and the process should continue. This ensures maximum cleanup of remaining infrastructure and avoids blocking subsequent teardown retries. Alternatively, keep the default as false until the cleanup error handling is refactored to be non-fatal.

Suggested change
destroyCmd.Flags().BoolVar(&robustDestroy, "robust", true, "Perform a robust destroy, including firewall rule cleanup.")
destroyCmd.Flags().BoolVar(&robustDestroy, "robust", false, "Perform a robust destroy, including firewall rule cleanup.")
References
  1. When performing state cleanup (such as removing unreachable resources from Terraform state), use a best-effort approach by logging errors and continuing rather than failing fast or returning a combined error. This ensures maximum cleanup of remaining infrastructure and avoids blocking subsequent teardown retries.

@Neelabh94 Neelabh94 self-assigned this Aug 21, 2026
@Neelabh94 Neelabh94 changed the title feat(destroy): make robust as the default flag for destroy command feat(destroy): robust destroy as default for all gcluster destroy operations Aug 22, 2026
@Neelabh94 Neelabh94 changed the title feat(destroy): robust destroy as default for all gcluster destroy operations feat(destroy): default to robust destroy for all gcluster destroy operations Aug 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release-improvements Added to release notes under the "Improvements" heading.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant