Google Cloud global external Application Load Balancer Terraform Code Generation Guidelines
This reference document details how to generate syntactically perfect, production-grade Terraform HCL code for Google Cloud global external Application Load Balancer architectures (incorporating Cloud CDN and Cloud Armor WAF) based on a design spec.
Core Directives - Behavioral Rules
- Deterministic Output: You must strictly follow the Workload Profile Map below. If a user selects a workload type, you MUST apply the corresponding HCL properties. Do not deviate or get "creative" with the code.
- Schema Enforcement: You expect a "Design Spec" containing: Architecture Name, Project, Region, Protocols, Origins (with associated Workload Types), and Routing Rules.
- Cross-Resource Linking: Ensure all Terraform resources are correctly linked using reference syntax (e.g.,
service = google_compute_backend_service.example.id) rather than hardcoding names. - Directory Isolation: Always generate HCL code inside a dedicated, isolated subdirectory named after the architecture (e.g.,
/gfe/deployments/{architecture_name}/) to avoid stale state or resource name pollution. - Resource Prefixing: Ensure all Google Cloud resource names in the generated HCL are dynamically prefixed with the Architecture Name (either via input variables or string interpolation) to guarantee global uniqueness and prevent 409 resource conflicts.
- Lowercase Naming Only: Infrastructure Manager and Google Cloud APIs are strict on resource naming. The architecture name, deployment IDs, and all generated resource names MUST be strictly lowercase and match
^[a-z](?:[-a-z0-9]{0,61}[a-z0-9])?$. If the user provides a name with uppercase characters, convert it to lowercase automatically before using it in the configuration.
Terraform Syntax & Google Cloud API Constraints
To prevent validation and deployment errors, always adhere to the following Google Cloud provider constraints:
- Cloud Armor (
google_compute_security_policy):- Default Action: Do NOT use
default_rule_action = "..."at the top level. You must explicitly define the default action as aruleblock with priority2147483647and actionallow(ordeny). - Rate Limiting Action: Use
action = "throttle"instead ofrate-based-banfor rate limit rules. This ensures compatibility across different API/provider versions. - Cloud Armor Edge Constraints:
type = "CLOUD_ARMOR_EDGE"policies (required for Backend Buckets) DO NOT supportrate_limit_options. Only use standardallowordenyrules. Do not generate rate limiting configurations for backend buckets.
- Default Action: Do NOT use
- Backend Buckets (
google_compute_backend_bucket):- Cache Key Policy: Do NOT include a
cache_key_policyblock (e.g., trying to setinclude_query_string = false). Backend buckets do not support these arguments; query strings are automatically ignored by default when usingCACHE_ALL_STATIC. - Default TTL Limits: The
cdn_policy.default_ttlcannot be greater than themax_ttl. If you setdefault_ttlto a value larger than the default86400(e.g., the recommended2592000/ 30 days for static objects), you MUST explicitly setmax_ttlto a value equal to or larger thandefault_ttl(e.g.,31536000/ 365 days).
- Cache Key Policy: Do NOT include a
- Backend Services (
google_compute_backend_service):- Origin Header TTLs: If using
cache_mode = "USE_ORIGIN_HEADERS", you MUST omitdefault_ttlandclient_ttlfrom thecdn_policyblock. Specifying them will cause validation errors. - Request Coalescing: Avoid using
request_coalescing = trueinside thecdn_policyof backend services unless verified to be supported by the active provider version.
- Origin Header TTLs: If using
- Provider Version:
- Always configure the
required_providersblock to use the Google provider version~> 5.0(or newer) to ensure rate-limiting features are correctly supported.
- Always configure the
Workload Profile Map (The Source of Truth)
| Workload Type | enable_cdn |
cdn_policy.cache_mode |
default_ttl |
max_ttl |
Cache Key Policy | WAF Protection (Cloud Armor) |
|---|---|---|---|---|---|---|
| Static Images / Objects | true |
CACHE_ALL_STATIC |
2592000 (30d) |
31536000 (365d) |
Host + Protocol + Path (Ignore Query Strings) | None (Rate Limiting unsupported on CLOUD_ARMOR_EDGE) |
| Cacheable API | true |
USE_ORIGIN_HEADERS |
Omitted (Managed by Origin) | Omitted | Include Query Strings | OWASP (SQLi/XSS/LFI) + Rate Limit (100 RPM) |
| Uncacheable API / Transactions | false |
N/A | N/A | N/A | N/A | OWASP (SQLi/XSS/RCE/Session Fixation) + Strict Rate Limit (30 RPM) + Bot Management |
| Dynamic Web (SSR) | true |
USE_ORIGIN_HEADERS |
Omitted (Managed by Origin) | Omitted | Host + Protocol + Path (Bypass on session cookie) | OWASP (SQLi/XSS/CSRF/Shellshock) + Rate Limit (120 RPM) |
The Generation Workflow
- Consume Spec: Read the provided Design Spec carefully.
- Prepare Directory Structure: Create the dedicated subdirectory
/gfe/deployments/{architecture_name}/. - Assemble HCL:
- Generate a
variables.tfandterraform.tfvarsdefining the input variables (architecture_name,project_id,region, etc.) to dynamically parameterize the blueprint. - Generate the
terraformandproviderblocks inmain.tf. - For each origin, create the appropriate backend resource (
backend_bucket,backend_service, orregion_network_endpoint_group), dynamically prefixing thenamefield using the architecture name prefix, and injecting properties from the Workload Profile Map. - Create the
google_compute_security_policyresources for each backend using the WAF rules defined in the map, with dynamic prefixing. - Create the
google_compute_url_mapusing the provided path and header-based routing rules. - Create the frontend resources (
target_http_proxy/target_https_proxywithssl_certificates, andglobal_forwarding_rule), with dynamic prefixing.
- Generate a
- Output Code: Provide the complete, finalized
main.tf,variables.tf, andterraform.tfvarsfiles to the user. Do not include conversational filler; focus on the technical integrity of the code. - Hand-off: Once the code is output, state the next action (Download Files or Deploy Configuration) and transition to
references/managed-deployment.md(specifically Phase 2 Option A) to guide the user through deployment pre-checks and execution.