Skip to content

zero_trust_gateway_settings state upgraders#211

Merged
SirCortly merged 1 commit intomainfrom
cortlyons/cloudflare_zero_trust_gateway_settings-state-upgraders
Mar 4, 2026
Merged

zero_trust_gateway_settings state upgraders#211
SirCortly merged 1 commit intomainfrom
cortlyons/cloudflare_zero_trust_gateway_settings-state-upgraders

Conversation

@SirCortly
Copy link
Collaborator

@SirCortly SirCortly commented Feb 27, 2026

========================================
State Migration Methods for Specified Resources
========================================

Resources using provider's UpgradeState/MoveState:
  zero_trust_gateway_settings

Targeting specific resources: zero_trust_gateway_settings
Target arguments: -target=module.zero_trust_gateway_settings


========================================
E2E Migration Test
========================================

Step 0: Initializing test resources
Running tests with:
  User:       [email protected]
  Account ID: 4e0db82a94b7cc78653ac27dc4f653e9
  Zone ID:    28fea702d1075b10ba9c8620b86218ec
  Domain:     cort.terraform.cfapi.net
  Provider:   Local (../cloudflare-terraform-next)

Running init script...

========================================
Syncing Test Resources
========================================

Filtering to specific resources: zero_trust_gateway_settings
Syncing resource files from testdata...
  ✓ zero_trust_gateway_settings/zero_trust_gateway_settings.tf (from zero_trust_gateway_settings_e2e.tf)
  ✓ zero_trust_gateway_settings/versions.tf

  Total: 2 files synced

Configuring terraform variables...


✓ Saved configuration
    Account ID: 4e0db82a94b7cc78653ac27dc4f653e9
    Zone ID: 28fea702d1075b10ba9c8620b86218ec
    Domain: cort.terraform.cfapi.net
    File: v4/terraform.tfvars

Scanning for import annotations...

Updating main.tf with module references...
  ↻ Updated main.tf with 1 module references


========================================
✓ Sync Complete!
========================================

Summary:
  - Terraform v4 configs: /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/tf/v4
  - Modules: 1
  - Files synced: 2

Configuring remote backend...
✓ Backend configured

  ✓ Provider installation preserved
  ✓ Backend already configured

Next steps:
  cd tf/v4 && terraform apply

Note: Configuration is automatically loaded from terraform.tfvars
      State is managed remotely in R2

✓ Test resources initialized


========================================
Setting up local provider
========================================

Using provider from: ../cloudflare-terraform-next
Building provider...
  Building in: ../cloudflare-terraform-next
  Output: ../cloudflare-terraform-next/terraform-provider-cloudflare
✓ Provider built successfully: ../cloudflare-terraform-next/terraform-provider-cloudflare
✓ Created dev overrides config: /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/.terraformrc-tf-migrate
✓ Local provider will be used for v5 testing

Note: v4 tests will use the registry provider (v4.x)
      v5 tests will use the local provider with dev overrides

Step 1: Testing v4 configurations
Running terraform init in v4/...
Found local state file, backing up and using remote state...
✓ Terraform init successful (remote state loaded from R2)
Running terraform plan in v4/...
✓ Terraform plan successful
  Plan: 0 to add, 1 to change, 0 to destroy.

Detailed changes:

  # module.zero_trust_gateway_settings.cloudflare_teams_account.e2e_comprehensive will be updated in-place
  ~ resource "cloudflare_teams_account" "e2e_comprehensive" {
        id                                     = "4e0db82a94b7cc78653ac27dc4f653e9"
        # (6 unchanged attributes hidden)


Running terraform apply in v4/...
✓ Terraform apply successful
  Apply complete! Resources: 0 added, 1 changed, 0 destroyed.
Syncing state from remote...
✓ Local state file synced from R2
Capturing v4 state...
✓ Saved v4 state to tmp/v4-state.json


Step 2: Running migration
Running ./scripts/migrate...
Building tf-migrate binary...
✓ Binary built successfully

========================================
Running v4 to v5 Migration
========================================

Preparing output directory...
  ✓ Preserved v5 provider installation (.terraform/)
  ✓ Preserved v5 dependency lock file (.terraform.lock.hcl)
Copying only targeted resources: zero_trust_gateway_settings
    ✓ Copied root file: provider.tf
    ✓ Copied root file: terraform.tfvars
    ✓ Copied root file: terraform.tfstate

    ✓ Copied module: zero_trust_gateway_settings
Creating filtered main.tf...
✓ Copied targeted resources to migrated-v4_to_v5/
✓ Updated provider.tf to use ~> 5.0 and removed backend config
Filtering state file to only include targeted resources...
✓ Filtered state to 1 resources from targeted modules

Migrating configuration files...
Skipping state transformation - using provider's state upgrader
Cloudflare Terraform Provider Migration Tool
============================================

Configuration directory: /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/migrated-v4_to_v5
Output directory: in-place
✓ Using Cloudflare API credentials (API key + email)

Found 4 configuration files to migrate
[1/4] Processing main.tf... ✓
[2/4] Processing provider.tf... ✓
[3/4] Processing versions.tf... ✓
[4/4] Processing zero_trust_gateway_settings.tf... ✓
2026-02-27T15:56:00.007-0700 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*load_balancer_pools.V4ToV5Migrator"
2026-02-27T15:56:00.007-0700 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*zone_setting.V4ToV5Migrator"                        
2026-02-27T15:56:00.007-0700 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*queue.V4ToV5Migrator"                               
2026-02-27T15:56:00.007-0700 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*rulesets.V4ToV5Migrator"                            
2026-02-27T15:56:00.007-0700 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*zero_trust_split_tunnel.V4ToV5Migrator"             
2026-02-27T15:56:00.007-0700 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*zero_trust_gateway_certificate.V4ToV5Migrator"      
                                                                                                                                                                                                                  
Applying cross-file reference updates (29 updates across 4 files)...
✓ Updated cross-file references (29 updates applied)
✓ Migration complete (config transformed, state will be upgraded by provider)


========================================
✓ Migration Complete!
========================================

Results:
  Input (v4):  /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/tf/v4
  Output (v5): /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/migrated-v4_to_v5

Next steps:
  cd /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/migrated-v4_to_v5
  terraform init
  terraform plan

✓ Migration successful

Step 3: Testing v5 configurations
Running terraform init in migrated-v4_to_v5/...
Cleaning v5 .terraform directory for fresh init...
Removing .terraform.lock.hcl to allow dev_overrides...
✓ Terraform init successful
Running terraform plan in v5/...
⚠ Warning: Resource exemption in /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/drift-exemptions/zero_trust_gateway_settings.yaml specifies resource_types that don't match expected type cloudflare_zero_trust_gateway_settings                                                                                                                                                      
⚠ Warning: Resource exemption in /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/drift-exemptions/zero_trust_gateway_settings.yaml specifies resource_types that don't match expected type cloudflare_zero_trust_gateway_settings                                                                                                                                                      
✓ Terraform plan shows only computed value refreshes (ignored with --apply-exemptions)

Drift exemptions applied:
  - new_device_settings_resource: 1 change(s) exempted
  - new_logging_resource: 1 change(s) exempted
  - computed_value_refreshes: 5 change(s) exempted
  - block_page_api_default_fields: 6 change(s) exempted
Running terraform apply in v5/...
✓ Terraform apply successful
Capturing v5 state...
✓ Saved v5 state to tmp/v5-state.json

Step 4: Verifying stable state (v5 plan after apply)
Running terraform plan again to check for ongoing drift...
⚠ Warning: Resource exemption in /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/drift-exemptions/zero_trust_gateway_settings.yaml specifies resource_types that don't match expected type cloudflare_zero_trust_gateway_settings                                                                                                                                                      
⚠ Warning: Resource exemption in /Users/cortlyons/development/cloudflare/sdk-repos/internal/terraform-devstack/tf-migrate/e2e/drift-exemptions/zero_trust_gateway_settings.yaml specifies resource_types that don't match expected type cloudflare_zero_trust_gateway_settings                                                                                                                                                      
✓ Only computed value refreshes detected (ignored with --apply-exemptions) - migration achieved stable state!

Drift exemptions applied:
  - computed_value_refreshes: 5 change(s) exempted
  - block_page_api_default_fields: 6 change(s) exempted


========================================
Drift Report
========================================

✓ Exempted changes in v5 plan (before apply):
The following changes were detected but exempted by drift exemption rules:
  module.zero_trust_gateway_settings.cloudflare_zero_trust_device_settings.e2e_comprehensive_device_settings:
      # module.zero_trust_gateway_settings.cloudflare_zero_trust_device_settings.e2e_comprehensive_device_settings will be created [exempted: new_device_settings_resource]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_logging.e2e_comprehensive_logging:
      # module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_logging.e2e_comprehensive_logging will be created [exempted: new_logging_resource]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    ~ created_at = "2025-11-13T16:30:41Z" -> (known after apply) [exempted: computed_value_refreshes]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - mailto_subject   = "" -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    + read_only        = (known after apply) [exempted: computed_value_refreshes]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    ~ updated_at = "2026-02-27T22:55:54Z" -> (known after apply) [exempted: computed_value_refreshes]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - include_context  = false -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - mailto_address   = "" -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - mode             = "customized_block_page" -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    + source_account   = (known after apply) [exempted: computed_value_refreshes]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - suppress_footer  = false -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - target_uri       = "" -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    ~ version          = 22 -> (known after apply) [exempted: computed_value_refreshes]

✓ Exempted changes in v5 plan (after apply):
The following changes were detected but exempted by drift exemption rules:
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    + source_account   = (known after apply) [exempted: computed_value_refreshes]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - suppress_footer  = false -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - target_uri       = "" -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    ~ updated_at = "2026-02-27T22:56:06Z" -> (known after apply) [exempted: computed_value_refreshes]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - mailto_address   = "" -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - mailto_subject   = "" -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    ~ version          = 23 -> (known after apply) [exempted: computed_value_refreshes]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    ~ created_at = "2025-11-13T16:30:41Z" -> (known after apply) [exempted: computed_value_refreshes]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - include_context  = false -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    - mode             = "customized_block_page" -> null [exempted: block_page_api_default_fields]
  module.zero_trust_gateway_settings.cloudflare_zero_trust_gateway_settings.e2e_comprehensive:
    + read_only        = (known after apply) [exempted: computed_value_refreshes]



========================================
✓ E2E Test Complete!
========================================

Summary:

  Step 1: v4 terraform apply
    Status: ✓ SUCCESS

  Step 2: Migration (v4 → v5)
    Status: ✓ SUCCESS

  Step 3: v5 plan (before apply)
    Status: ⚠ Changes detected but all exempted
    Result: 0 real changes (13 exempted)
    Terraform: Plan: 2 to add, 1 to change, 0 to destroy.

  Step 4: v5 terraform apply
    Status: ✓ SUCCESS

  Step 5: v5 plan (after apply)
    Status: ✓ SUCCESS - Stable state achieved
    Result: No changes detected

@SirCortly SirCortly marked this pull request as ready for review February 27, 2026 23:04
@ssicard ssicard requested a review from a team March 2, 2026 17:25
@ssicard ssicard added this to the Phase 2 milestone Mar 2, 2026
}

testhelpers.RunStateTransformTests(t, testCases, migrator)
func TestStateTransformation_Removed(t *testing.T) {
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: I'd vote to remove this

@SirCortly SirCortly force-pushed the cortlyons/cloudflare_zero_trust_gateway_settings-state-upgraders branch from ccef18a to a6f5121 Compare March 4, 2026 18:29
@SirCortly SirCortly merged commit f6fa028 into main Mar 4, 2026
9 checks passed
@SirCortly SirCortly deleted the cortlyons/cloudflare_zero_trust_gateway_settings-state-upgraders branch March 4, 2026 18:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants