Skip to content

chore(zt_organization): support state upgraders#216

Merged
ssicard merged 1 commit intomainfrom
ssicard/stateupgrader/zt_access_org
Mar 4, 2026
Merged

chore(zt_organization): support state upgraders#216
ssicard merged 1 commit intomainfrom
ssicard/stateupgrader/zt_access_org

Conversation

@ssicard
Copy link
Collaborator

@ssicard ssicard commented Mar 4, 2026

Supports state upgraders for zero_trust_organization.

E2E Tests

========================================
State Migration Methods for Specified Resources
========================================

Resources using provider's UpgradeState/MoveState:
  zero_trust_organization

Targeting specific resources: zero_trust_organization
Target arguments: -target=module.zero_trust_organization


========================================
E2E Migration Test
========================================

Step 0: Initializing test resources
Running tests with:
  User:       sarah-terraform-test@cfapi.net
  Account ID: f44ad02588fa5fd7e484b97b31210a79
  Zone ID:    e2edd3d8885f9b2d75a3158dc9bd0e55
  Domain:     sarah.terraform.cfapi.net
  Provider:   Local (/Users/ssicard/workspace/terraform-devstack/cloudflare-terraform-next)

Running init script...

========================================
Syncing Test Resources
========================================

Filtering to specific resources: zero_trust_organization
Syncing resource files from testdata...
  ✓ zero_trust_organization/zero_trust_organization.tf (from zero_trust_organization_e2e.tf)
  ✓ zero_trust_organization/versions.tf

  Total: 2 files synced

Configuring terraform variables...


✓ Saved configuration
    Account ID: f44ad02588fa5fd7e484b97b31210a79
    Zone ID: e2edd3d8885f9b2d75a3158dc9bd0e55
    Domain: sarah.terraform.cfapi.net
    File: v4/terraform.tfvars

Scanning for import annotations...
  ✓ Found 1 resource(s) requiring import
    - module.zero_trust_organization.cloudflare_access_organization.test

Updating main.tf with module references...
  ↻ Updated main.tf with 1 module references and 1 import blocks


========================================
✓ Sync Complete!
========================================

Summary:
  - Terraform v4 configs: /Users/ssicard/workspace/terraform-devstack/tf-migrate/e2e/tf/v4
  - Modules: 1
  - Files synced: 2

Configuring remote backend...
✓ Backend configured

  ✓ Provider installation preserved
  ✓ Backend already configured

Next steps:
  cd tf/v4 && terraform apply

Note: Configuration is automatically loaded from terraform.tfvars
      State is managed remotely in R2

✓ Test resources initialized


========================================
Setting up local provider
========================================

Using provider from: /Users/ssicard/workspace/terraform-devstack/cloudflare-terraform-next
Building provider...
  Building in: /Users/ssicard/workspace/terraform-devstack/cloudflare-terraform-next
  Output: /Users/ssicard/workspace/terraform-devstack/cloudflare-terraform-next/terraform-provider-cloudflare
✓ Provider built successfully: /Users/ssicard/workspace/terraform-devstack/cloudflare-terraform-next/terraform-provider-cloudflare
✓ Created dev overrides config: /Users/ssicard/workspace/terraform-devstack/tf-migrate/.terraformrc-tf-migrate
✓ Local provider will be used for v5 testing

Note: v4 tests will use the registry provider (v4.x)
      v5 tests will use the local provider with dev overrides

Step 1: Testing v4 configurations
Running terraform init in v4/...
Found local state file, backing up and using remote state...
✓ Terraform init successful (remote state loaded from R2)
Running terraform plan in v4/...
✓ Terraform plan shows no changes

Running terraform apply in v4/...
✓ Terraform apply successful
  Apply complete! Resources: 0 added, 0 changed, 0 destroyed.
Syncing state from remote...
✓ Local state file synced from R2
Capturing v4 state...
✓ Saved v4 state to tmp/v4-state.json


Step 2: Running migration
Running ./scripts/migrate...
Building tf-migrate binary...
✓ Binary built successfully

========================================
Running v4 to v5 Migration
========================================

Preparing output directory...
  ✓ Preserved v5 provider installation (.terraform/)
  ✓ Preserved v5 dependency lock file (.terraform.lock.hcl)
Copying only targeted resources: zero_trust_organization
    ✓ Copied root file: provider.tf
    ✓ Copied root file: terraform.tfvars
    ✓ Copied root file: terraform.tfstate

    ✓ Copied module: zero_trust_organization
Creating filtered main.tf...
✓ Copied targeted resources to migrated-v4_to_v5/
✓ Updated provider.tf to use ~> 5.0 and removed backend config
Filtering state file to only include targeted resources...
✓ Filtered state to 1 resources from targeted modules

Migrating configuration files...
Skipping state transformation - using provider's state upgrader
Cloudflare Terraform Provider Migration Tool
============================================

Configuration directory: /Users/ssicard/workspace/terraform-devstack/tf-migrate/e2e/migrated-v4_to_v5
Output directory: in-place

Found 4 configuration files to migrate
[1/4] Processing main.tf... ✓
[2/4] Processing provider.tf... ✓
[3/4] Processing versions.tf... ✓
[4/4] Processing zero_trust_organization.tf... ✓
2026-03-04T09:35:26.480-0600 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*load_balancer_pools.V4ToV5Migrator"
2026-03-04T09:35:26.480-0600 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*queue.V4ToV5Migrator"
2026-03-04T09:35:26.480-0600 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*zone_setting.V4ToV5Migrator"
2026-03-04T09:35:26.480-0600 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*rulesets.V4ToV5Migrator"
2026-03-04T09:35:26.480-0600 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*zero_trust_split_tunnel.V4ToV5Migrator"
2026-03-04T09:35:26.480-0600 [WARN]  tf-migrate: Migrator does not implement ResourceRenamer interface - cross-file references may not be updated: migrator="*zero_trust_gateway_certificate.V4ToV5Migrator"

Applying cross-file reference updates (29 updates across 4 files)...
✓ Updated cross-file references (29 updates applied)
✓ Migration complete (config transformed, state will be upgraded by provider)


========================================
✓ Migration Complete!
========================================

Results:
  Input (v4):  /Users/ssicard/workspace/terraform-devstack/tf-migrate/e2e/tf/v4
  Output (v5): /Users/ssicard/workspace/terraform-devstack/tf-migrate/e2e/migrated-v4_to_v5

Next steps:
  cd /Users/ssicard/workspace/terraform-devstack/tf-migrate/e2e/migrated-v4_to_v5
  terraform init
  terraform plan

✓ Migration successful

Step 3: Testing v5 configurations
Running terraform init in migrated-v4_to_v5/...
Cleaning v5 .terraform directory for fresh init...
Removing .terraform.lock.hcl to allow dev_overrides...
✓ Terraform init successful
Running terraform plan in v5/...
✓ Terraform plan shows only computed value refreshes (ignored with --apply-exemptions)
Running terraform apply in v5/...
✓ Terraform apply successful
Capturing v5 state...
✓ Saved v5 state to tmp/v5-state.json

Step 4: Verifying stable state (v5 plan after apply)
Running terraform plan again to check for ongoing drift...
✓ No ongoing drift detected - migration achieved stable state!



========================================
✓ E2E Test Complete!
========================================

Summary:

  Step 1: v4 terraform apply
    Status: ✓ SUCCESS

  Step 2: Migration (v4 → v5)
    Status: ✓ SUCCESS

  Step 3: v5 plan (before apply)
    Status: ⚠ Changes detected but all exempted
    Result: 0 real changes (0 exempted)
    Terraform: Plan: 0 to add, 0 to change, 0 to destroy.

  Step 4: v5 terraform apply
    Status: ✓ SUCCESS

  Step 5: v5 plan (after apply)
    Status: ✓ SUCCESS - Stable state achieved
    Result: No changes detected

@ssicard ssicard self-assigned this Mar 4, 2026
@ssicard ssicard added this to the Phase 2 milestone Mar 4, 2026
@ssicard ssicard requested a review from a team March 4, 2026 20:14
@ssicard ssicard merged commit 14a89ac into main Mar 4, 2026
9 checks passed
@ssicard ssicard deleted the ssicard/stateupgrader/zt_access_org branch March 4, 2026 21:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants