From 0a6bb2bec7b686172e5757fc0e02f23563870456 Mon Sep 17 00:00:00 2001 From: Modular Magician Date: Tue, 1 Sep 2026 16:13:26 +0000 Subject: [PATCH] feat: (storageftp) added new resource google_storage_ftp_user (#18497) Co-authored-by: Chris Hawk [upstream:03cd99b76f3f76f295dcd7f4d503d5c4e151b45f] Signed-off-by: Modular Magician --- storage_ftp_server_external/backing_file.tf | 15 ++++ storage_ftp_server_external/main.tf | 13 ++++ storage_ftp_server_external/motd | 7 ++ storage_ftp_server_external/tutorial.md | 79 +++++++++++++++++++++ storage_ftp_server_internal/backing_file.tf | 15 ++++ storage_ftp_server_internal/main.tf | 22 ++++++ storage_ftp_server_internal/motd | 7 ++ storage_ftp_server_internal/tutorial.md | 79 +++++++++++++++++++++ storage_ftp_user_basic/backing_file.tf | 15 ++++ storage_ftp_user_basic/main.tf | 50 +++++++++++++ storage_ftp_user_basic/motd | 7 ++ storage_ftp_user_basic/tutorial.md | 79 +++++++++++++++++++++ 12 files changed, 388 insertions(+) create mode 100644 storage_ftp_server_external/backing_file.tf create mode 100644 storage_ftp_server_external/main.tf create mode 100644 storage_ftp_server_external/motd create mode 100644 storage_ftp_server_external/tutorial.md create mode 100644 storage_ftp_server_internal/backing_file.tf create mode 100644 storage_ftp_server_internal/main.tf create mode 100644 storage_ftp_server_internal/motd create mode 100644 storage_ftp_server_internal/tutorial.md create mode 100644 storage_ftp_user_basic/backing_file.tf create mode 100644 storage_ftp_user_basic/main.tf create mode 100644 storage_ftp_user_basic/motd create mode 100644 storage_ftp_user_basic/tutorial.md diff --git a/storage_ftp_server_external/backing_file.tf b/storage_ftp_server_external/backing_file.tf new file mode 100644 index 000000000..c60b11997 --- /dev/null +++ b/storage_ftp_server_external/backing_file.tf @@ -0,0 +1,15 @@ +# This file has some scaffolding to make sure that names are unique and that +# a region and zone are selected when you try to create your Terraform resources. + +locals { + name_suffix = "${random_pet.suffix.id}" +} + +resource "random_pet" "suffix" { + length = 2 +} + +provider "google" { + region = "us-central1" + zone = "us-central1-c" +} diff --git a/storage_ftp_server_external/main.tf b/storage_ftp_server_external/main.tf new file mode 100644 index 000000000..437adabc8 --- /dev/null +++ b/storage_ftp_server_external/main.tf @@ -0,0 +1,13 @@ +resource "google_storage_ftp_server" "external_server" { + location = "us-west1" + server_id = "sftp-ext-${local.name_suffix}" + display_name = "My SFTP Server" + access_type = "EXTERNAL" + + external_config { + allowed_cidr_blocks = [ + "192.168.1.0/24", + "10.0.0.0/8" + ] + } +} diff --git a/storage_ftp_server_external/motd b/storage_ftp_server_external/motd new file mode 100644 index 000000000..45a906e81 --- /dev/null +++ b/storage_ftp_server_external/motd @@ -0,0 +1,7 @@ +=== + +These examples use real resources that will be billed to the +Google Cloud Platform project you use - so make sure that you +run "terraform destroy" before quitting! + +=== diff --git a/storage_ftp_server_external/tutorial.md b/storage_ftp_server_external/tutorial.md new file mode 100644 index 000000000..8cf8e817e --- /dev/null +++ b/storage_ftp_server_external/tutorial.md @@ -0,0 +1,79 @@ +# Storage Ftp Server External - Terraform + +## Setup + + + +Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform. + + + +Terraform provisions real GCP resources, so anything you create in this session will be billed against this project. + +## Terraforming! + +Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command +to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up +the project name from the environment variable. + +```bash +export GOOGLE_CLOUD_PROJECT={{project-id}} +``` + +After that, let's get Terraform started. Run the following to pull in the providers. + +```bash +terraform init +``` + +With the providers downloaded and a project set, you're ready to use Terraform. Go ahead! + +```bash +terraform apply +``` + +Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan. + +```bash +yes +``` + + +## Post-Apply + +### Editing your config + +Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed. + +```bash +terraform plan +``` + +So let's make a change! Try editing a number, or appending a value to the name in the editor. Then, +run a 'plan' again. + +```bash +terraform plan +``` + +Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes +at the 'yes' prompt. + +```bash +terraform apply +``` + +```bash +yes +``` + +## Cleanup + +Run the following to remove the resources Terraform provisioned: + +```bash +terraform destroy +``` +```bash +yes +``` diff --git a/storage_ftp_server_internal/backing_file.tf b/storage_ftp_server_internal/backing_file.tf new file mode 100644 index 000000000..c60b11997 --- /dev/null +++ b/storage_ftp_server_internal/backing_file.tf @@ -0,0 +1,15 @@ +# This file has some scaffolding to make sure that names are unique and that +# a region and zone are selected when you try to create your Terraform resources. + +locals { + name_suffix = "${random_pet.suffix.id}" +} + +resource "random_pet" "suffix" { + length = 2 +} + +provider "google" { + region = "us-central1" + zone = "us-central1-c" +} diff --git a/storage_ftp_server_internal/main.tf b/storage_ftp_server_internal/main.tf new file mode 100644 index 000000000..0b62fa310 --- /dev/null +++ b/storage_ftp_server_internal/main.tf @@ -0,0 +1,22 @@ +resource "google_storage_ftp_server" "internal_server" { + location = "us-west1" + server_id = "sftp-int-${local.name_suffix}" + display_name = "My SFTP Server" + access_type = "INTERNAL" + + internal_config { + consumer_accept_list { + project = "projects/${data.google_project.project.project_id}" + connection_limit = 10 + } + consumer_reject_list { + project = "projects/${data.google_project.project.number}" + } + consumer_reject_list { + project = "projects/920946329098" + } + } +} + +data "google_project" "project" { +} diff --git a/storage_ftp_server_internal/motd b/storage_ftp_server_internal/motd new file mode 100644 index 000000000..45a906e81 --- /dev/null +++ b/storage_ftp_server_internal/motd @@ -0,0 +1,7 @@ +=== + +These examples use real resources that will be billed to the +Google Cloud Platform project you use - so make sure that you +run "terraform destroy" before quitting! + +=== diff --git a/storage_ftp_server_internal/tutorial.md b/storage_ftp_server_internal/tutorial.md new file mode 100644 index 000000000..db5398e87 --- /dev/null +++ b/storage_ftp_server_internal/tutorial.md @@ -0,0 +1,79 @@ +# Storage Ftp Server Internal - Terraform + +## Setup + + + +Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform. + + + +Terraform provisions real GCP resources, so anything you create in this session will be billed against this project. + +## Terraforming! + +Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command +to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up +the project name from the environment variable. + +```bash +export GOOGLE_CLOUD_PROJECT={{project-id}} +``` + +After that, let's get Terraform started. Run the following to pull in the providers. + +```bash +terraform init +``` + +With the providers downloaded and a project set, you're ready to use Terraform. Go ahead! + +```bash +terraform apply +``` + +Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan. + +```bash +yes +``` + + +## Post-Apply + +### Editing your config + +Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed. + +```bash +terraform plan +``` + +So let's make a change! Try editing a number, or appending a value to the name in the editor. Then, +run a 'plan' again. + +```bash +terraform plan +``` + +Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes +at the 'yes' prompt. + +```bash +terraform apply +``` + +```bash +yes +``` + +## Cleanup + +Run the following to remove the resources Terraform provisioned: + +```bash +terraform destroy +``` +```bash +yes +``` diff --git a/storage_ftp_user_basic/backing_file.tf b/storage_ftp_user_basic/backing_file.tf new file mode 100644 index 000000000..c60b11997 --- /dev/null +++ b/storage_ftp_user_basic/backing_file.tf @@ -0,0 +1,15 @@ +# This file has some scaffolding to make sure that names are unique and that +# a region and zone are selected when you try to create your Terraform resources. + +locals { + name_suffix = "${random_pet.suffix.id}" +} + +resource "random_pet" "suffix" { + length = 2 +} + +provider "google" { + region = "us-central1" + zone = "us-central1-c" +} diff --git a/storage_ftp_user_basic/main.tf b/storage_ftp_user_basic/main.tf new file mode 100644 index 000000000..3d300099d --- /dev/null +++ b/storage_ftp_user_basic/main.tf @@ -0,0 +1,50 @@ +resource "google_storage_bucket" "bucket" { + name = "sftp-bucket-${local.name_suffix}" + location = "US" + uniform_bucket_level_access = true +} + +resource "google_service_account" "sa" { + account_id = "sftp-sa-${local.name_suffix}" + display_name = "Storage FTP Service Account" +} + +resource "google_storage_ftp_server" "server" { + location = "us-west1" + server_id = "sftp-srv-${local.name_suffix}" + display_name = "My SFTP Server" + access_type = "EXTERNAL" + + external_config { + allowed_cidr_blocks = [ + "192.168.1.0/24", + "10.0.0.0/8" + ] + } +} + +resource "google_storage_ftp_user" "user_ftp" { + location = "us-west1" + server_id = google_storage_ftp_server.server.server_id + user_id = "sftp-user-${local.name_suffix}" + customer_service_account = google_service_account.sa.email + + storage_directory_mappings { + bucket = google_storage_bucket.bucket.name + bucket_prefix = "my-prefix-1" + directory = "/dir-1" + permission = "READ_ONLY" + } + storage_directory_mappings { + bucket = google_storage_bucket.bucket.name + bucket_prefix = "my-prefix-2" + directory = "/dir-2" + permission = "READ_ONLY" + } + + user_credentials { + credential_name = "ssh-key-credential" + credential_type = "PUBLIC_KEY" + ssh_public_key_body = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPM4pxpbPpjuBocS6qlW0BHRYgH5xmv/yVrANZR9lc1N user@example.com" + } +} diff --git a/storage_ftp_user_basic/motd b/storage_ftp_user_basic/motd new file mode 100644 index 000000000..45a906e81 --- /dev/null +++ b/storage_ftp_user_basic/motd @@ -0,0 +1,7 @@ +=== + +These examples use real resources that will be billed to the +Google Cloud Platform project you use - so make sure that you +run "terraform destroy" before quitting! + +=== diff --git a/storage_ftp_user_basic/tutorial.md b/storage_ftp_user_basic/tutorial.md new file mode 100644 index 000000000..5f7dab8c0 --- /dev/null +++ b/storage_ftp_user_basic/tutorial.md @@ -0,0 +1,79 @@ +# Storage Ftp User Basic - Terraform + +## Setup + + + +Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform. + + + +Terraform provisions real GCP resources, so anything you create in this session will be billed against this project. + +## Terraforming! + +Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command +to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up +the project name from the environment variable. + +```bash +export GOOGLE_CLOUD_PROJECT={{project-id}} +``` + +After that, let's get Terraform started. Run the following to pull in the providers. + +```bash +terraform init +``` + +With the providers downloaded and a project set, you're ready to use Terraform. Go ahead! + +```bash +terraform apply +``` + +Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan. + +```bash +yes +``` + + +## Post-Apply + +### Editing your config + +Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed. + +```bash +terraform plan +``` + +So let's make a change! Try editing a number, or appending a value to the name in the editor. Then, +run a 'plan' again. + +```bash +terraform plan +``` + +Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes +at the 'yes' prompt. + +```bash +terraform apply +``` + +```bash +yes +``` + +## Cleanup + +Run the following to remove the resources Terraform provisioned: + +```bash +terraform destroy +``` +```bash +yes +```