diff --git a/storage_ftp_server_external/backing_file.tf b/storage_ftp_server_external/backing_file.tf
new file mode 100644
index 00000000..c60b1199
--- /dev/null
+++ b/storage_ftp_server_external/backing_file.tf
@@ -0,0 +1,15 @@
+# This file has some scaffolding to make sure that names are unique and that
+# a region and zone are selected when you try to create your Terraform resources.
+
+locals {
+ name_suffix = "${random_pet.suffix.id}"
+}
+
+resource "random_pet" "suffix" {
+ length = 2
+}
+
+provider "google" {
+ region = "us-central1"
+ zone = "us-central1-c"
+}
diff --git a/storage_ftp_server_external/main.tf b/storage_ftp_server_external/main.tf
new file mode 100644
index 00000000..437adabc
--- /dev/null
+++ b/storage_ftp_server_external/main.tf
@@ -0,0 +1,13 @@
+resource "google_storage_ftp_server" "external_server" {
+ location = "us-west1"
+ server_id = "sftp-ext-${local.name_suffix}"
+ display_name = "My SFTP Server"
+ access_type = "EXTERNAL"
+
+ external_config {
+ allowed_cidr_blocks = [
+ "192.168.1.0/24",
+ "10.0.0.0/8"
+ ]
+ }
+}
diff --git a/storage_ftp_server_external/motd b/storage_ftp_server_external/motd
new file mode 100644
index 00000000..45a906e8
--- /dev/null
+++ b/storage_ftp_server_external/motd
@@ -0,0 +1,7 @@
+===
+
+These examples use real resources that will be billed to the
+Google Cloud Platform project you use - so make sure that you
+run "terraform destroy" before quitting!
+
+===
diff --git a/storage_ftp_server_external/tutorial.md b/storage_ftp_server_external/tutorial.md
new file mode 100644
index 00000000..8cf8e817
--- /dev/null
+++ b/storage_ftp_server_external/tutorial.md
@@ -0,0 +1,79 @@
+# Storage Ftp Server External - Terraform
+
+## Setup
+
+
+
+Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform.
+
+
+
+Terraform provisions real GCP resources, so anything you create in this session will be billed against this project.
+
+## Terraforming!
+
+Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command
+to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up
+the project name from the environment variable.
+
+```bash
+export GOOGLE_CLOUD_PROJECT={{project-id}}
+```
+
+After that, let's get Terraform started. Run the following to pull in the providers.
+
+```bash
+terraform init
+```
+
+With the providers downloaded and a project set, you're ready to use Terraform. Go ahead!
+
+```bash
+terraform apply
+```
+
+Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan.
+
+```bash
+yes
+```
+
+
+## Post-Apply
+
+### Editing your config
+
+Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed.
+
+```bash
+terraform plan
+```
+
+So let's make a change! Try editing a number, or appending a value to the name in the editor. Then,
+run a 'plan' again.
+
+```bash
+terraform plan
+```
+
+Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes
+at the 'yes' prompt.
+
+```bash
+terraform apply
+```
+
+```bash
+yes
+```
+
+## Cleanup
+
+Run the following to remove the resources Terraform provisioned:
+
+```bash
+terraform destroy
+```
+```bash
+yes
+```
diff --git a/storage_ftp_server_internal/backing_file.tf b/storage_ftp_server_internal/backing_file.tf
new file mode 100644
index 00000000..c60b1199
--- /dev/null
+++ b/storage_ftp_server_internal/backing_file.tf
@@ -0,0 +1,15 @@
+# This file has some scaffolding to make sure that names are unique and that
+# a region and zone are selected when you try to create your Terraform resources.
+
+locals {
+ name_suffix = "${random_pet.suffix.id}"
+}
+
+resource "random_pet" "suffix" {
+ length = 2
+}
+
+provider "google" {
+ region = "us-central1"
+ zone = "us-central1-c"
+}
diff --git a/storage_ftp_server_internal/main.tf b/storage_ftp_server_internal/main.tf
new file mode 100644
index 00000000..0b62fa31
--- /dev/null
+++ b/storage_ftp_server_internal/main.tf
@@ -0,0 +1,22 @@
+resource "google_storage_ftp_server" "internal_server" {
+ location = "us-west1"
+ server_id = "sftp-int-${local.name_suffix}"
+ display_name = "My SFTP Server"
+ access_type = "INTERNAL"
+
+ internal_config {
+ consumer_accept_list {
+ project = "projects/${data.google_project.project.project_id}"
+ connection_limit = 10
+ }
+ consumer_reject_list {
+ project = "projects/${data.google_project.project.number}"
+ }
+ consumer_reject_list {
+ project = "projects/920946329098"
+ }
+ }
+}
+
+data "google_project" "project" {
+}
diff --git a/storage_ftp_server_internal/motd b/storage_ftp_server_internal/motd
new file mode 100644
index 00000000..45a906e8
--- /dev/null
+++ b/storage_ftp_server_internal/motd
@@ -0,0 +1,7 @@
+===
+
+These examples use real resources that will be billed to the
+Google Cloud Platform project you use - so make sure that you
+run "terraform destroy" before quitting!
+
+===
diff --git a/storage_ftp_server_internal/tutorial.md b/storage_ftp_server_internal/tutorial.md
new file mode 100644
index 00000000..db5398e8
--- /dev/null
+++ b/storage_ftp_server_internal/tutorial.md
@@ -0,0 +1,79 @@
+# Storage Ftp Server Internal - Terraform
+
+## Setup
+
+
+
+Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform.
+
+
+
+Terraform provisions real GCP resources, so anything you create in this session will be billed against this project.
+
+## Terraforming!
+
+Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command
+to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up
+the project name from the environment variable.
+
+```bash
+export GOOGLE_CLOUD_PROJECT={{project-id}}
+```
+
+After that, let's get Terraform started. Run the following to pull in the providers.
+
+```bash
+terraform init
+```
+
+With the providers downloaded and a project set, you're ready to use Terraform. Go ahead!
+
+```bash
+terraform apply
+```
+
+Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan.
+
+```bash
+yes
+```
+
+
+## Post-Apply
+
+### Editing your config
+
+Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed.
+
+```bash
+terraform plan
+```
+
+So let's make a change! Try editing a number, or appending a value to the name in the editor. Then,
+run a 'plan' again.
+
+```bash
+terraform plan
+```
+
+Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes
+at the 'yes' prompt.
+
+```bash
+terraform apply
+```
+
+```bash
+yes
+```
+
+## Cleanup
+
+Run the following to remove the resources Terraform provisioned:
+
+```bash
+terraform destroy
+```
+```bash
+yes
+```
diff --git a/storage_ftp_user_basic/backing_file.tf b/storage_ftp_user_basic/backing_file.tf
new file mode 100644
index 00000000..c60b1199
--- /dev/null
+++ b/storage_ftp_user_basic/backing_file.tf
@@ -0,0 +1,15 @@
+# This file has some scaffolding to make sure that names are unique and that
+# a region and zone are selected when you try to create your Terraform resources.
+
+locals {
+ name_suffix = "${random_pet.suffix.id}"
+}
+
+resource "random_pet" "suffix" {
+ length = 2
+}
+
+provider "google" {
+ region = "us-central1"
+ zone = "us-central1-c"
+}
diff --git a/storage_ftp_user_basic/main.tf b/storage_ftp_user_basic/main.tf
new file mode 100644
index 00000000..3d300099
--- /dev/null
+++ b/storage_ftp_user_basic/main.tf
@@ -0,0 +1,50 @@
+resource "google_storage_bucket" "bucket" {
+ name = "sftp-bucket-${local.name_suffix}"
+ location = "US"
+ uniform_bucket_level_access = true
+}
+
+resource "google_service_account" "sa" {
+ account_id = "sftp-sa-${local.name_suffix}"
+ display_name = "Storage FTP Service Account"
+}
+
+resource "google_storage_ftp_server" "server" {
+ location = "us-west1"
+ server_id = "sftp-srv-${local.name_suffix}"
+ display_name = "My SFTP Server"
+ access_type = "EXTERNAL"
+
+ external_config {
+ allowed_cidr_blocks = [
+ "192.168.1.0/24",
+ "10.0.0.0/8"
+ ]
+ }
+}
+
+resource "google_storage_ftp_user" "user_ftp" {
+ location = "us-west1"
+ server_id = google_storage_ftp_server.server.server_id
+ user_id = "sftp-user-${local.name_suffix}"
+ customer_service_account = google_service_account.sa.email
+
+ storage_directory_mappings {
+ bucket = google_storage_bucket.bucket.name
+ bucket_prefix = "my-prefix-1"
+ directory = "/dir-1"
+ permission = "READ_ONLY"
+ }
+ storage_directory_mappings {
+ bucket = google_storage_bucket.bucket.name
+ bucket_prefix = "my-prefix-2"
+ directory = "/dir-2"
+ permission = "READ_ONLY"
+ }
+
+ user_credentials {
+ credential_name = "ssh-key-credential"
+ credential_type = "PUBLIC_KEY"
+ ssh_public_key_body = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPM4pxpbPpjuBocS6qlW0BHRYgH5xmv/yVrANZR9lc1N user@example.com"
+ }
+}
diff --git a/storage_ftp_user_basic/motd b/storage_ftp_user_basic/motd
new file mode 100644
index 00000000..45a906e8
--- /dev/null
+++ b/storage_ftp_user_basic/motd
@@ -0,0 +1,7 @@
+===
+
+These examples use real resources that will be billed to the
+Google Cloud Platform project you use - so make sure that you
+run "terraform destroy" before quitting!
+
+===
diff --git a/storage_ftp_user_basic/tutorial.md b/storage_ftp_user_basic/tutorial.md
new file mode 100644
index 00000000..5f7dab8c
--- /dev/null
+++ b/storage_ftp_user_basic/tutorial.md
@@ -0,0 +1,79 @@
+# Storage Ftp User Basic - Terraform
+
+## Setup
+
+
+
+Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform.
+
+
+
+Terraform provisions real GCP resources, so anything you create in this session will be billed against this project.
+
+## Terraforming!
+
+Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command
+to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up
+the project name from the environment variable.
+
+```bash
+export GOOGLE_CLOUD_PROJECT={{project-id}}
+```
+
+After that, let's get Terraform started. Run the following to pull in the providers.
+
+```bash
+terraform init
+```
+
+With the providers downloaded and a project set, you're ready to use Terraform. Go ahead!
+
+```bash
+terraform apply
+```
+
+Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan.
+
+```bash
+yes
+```
+
+
+## Post-Apply
+
+### Editing your config
+
+Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed.
+
+```bash
+terraform plan
+```
+
+So let's make a change! Try editing a number, or appending a value to the name in the editor. Then,
+run a 'plan' again.
+
+```bash
+terraform plan
+```
+
+Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes
+at the 'yes' prompt.
+
+```bash
+terraform apply
+```
+
+```bash
+yes
+```
+
+## Cleanup
+
+Run the following to remove the resources Terraform provisioned:
+
+```bash
+terraform destroy
+```
+```bash
+yes
+```