


resource "google_compute_instance" "dev_machine" {
name = "dev-machine-${var.tag}"
deletion_protection = true
machine_type = "e2-standard-2"
boot_disk {
initialize_params {
image = "ubuntu-os-pro-cloud/ubuntu-pro-2004-lts"
size = 200
network_interface {
network = var.vpc.name
subnetwork = var.subnet.name
access_config {

tags = ["dev-vm-${var.tag}"]

resource "google_compute_instance" "dev_machine-minor" {
name = "dev-machine-minor-${var.tag}"
deletion_protection = true

machine_type = "n1-standard-1"
boot_disk {
initialize_params {
image = "ubuntu-os-pro-cloud/ubuntu-pro-2004-lts"
size = 30
network_interface {
network = var.vpc.name
subnetwork = var.subnet.name
access_config {

tags = ["dev-vm-${var.tag}"]
resource "google_compute_firewall" "ssh_access" {
name = "allow-ssh-access-${var.tag}"
network = var.vpc.name
allow {
protocol = "tcp"
ports = ["22"]
source_ranges = [ "" ]
target_tags = ["dev-vm-${var.tag}"]


variable "vpc" {
description = "vpc to deploy instance"
variable "subnet" {
description = "subnet to deploy the subnet"

variable "tag" {
description = "general project tag"

当我运行命令"terraform apply"时,一切都如预期的那样工作,但是如果我再次运行它,它总是声明必须替换实例,即使我没有对代码进行任何更改。当我通过ssh连接到实例时,我注意到所有内容都被删除了。

这是'terraform plan'未更改代码的输出:

An execution plan has been generated and is shown below.
Resource actions are indicated with the following symbols:
-/+ destroy and then create replacement
Terraform will perform the following actions:
# module.dev_environment.google_compute_instance.dev_machine must be replaced
-/+ resource "google_compute_instance" "dev_machine" {
~ cpu_platform         = "Intel Broadwell" -> (known after apply)
~ current_status       = "RUNNING" -> (known after apply)
~ deletion_protection  = false -> true
- enable_display       = false -> null
~ guest_accelerator    = [] -> (known after apply)
~ id                   = "<id with project>" -> (known after apply)
~ instance_id          = "<instance id>" -> (known after apply)
~ label_fingerprint    = "<label fingerprint>" -> (known after apply)
- labels               = {} -> null
- metadata             = {} -> null
~ metadata_fingerprint = "<metadata fingerprint>=" -> (known after apply)
+ min_cpu_platform     = (known after apply)
name                 = "dev-machine-pweather"
~ project              = "<project id>" -> (known after apply)
- resource_policies    = [] -> null
~ self_link            = "<project id url>/instances/dev-machine-pweather" -> (known after apply)
tags                 = [
~ tags_fingerprint     = "<tag fingerprint>" -> (known after apply)
~ zone                 = "us-east4-a" -> (known after apply)
# (2 unchanged attributes hidden)
~ boot_disk {
~ device_name                = "persistent-disk-0" -> (known after apply)
+ disk_encryption_key_sha256 = (known after apply)
+ kms_key_self_link          = (known after apply)
~ source                     = "<project id url>/us-east4-a/disks/dev-machine-pweather" -> (known after apply)
# (2 unchanged attributes hidden)
~ initialize_params {
~ image  = "https://www.googleapis.com/compute/v1/projects/ubuntu-os-pro-cloud/global/images/ubuntu-pro-2004-focal-v20210720" -> "ubuntu-os-pro-cloud/ubuntu-pro-2004-lts" # forces replacement
~ labels = {} -> (known after apply)
~ type   = "pd-standard" -> (known after apply)
# (1 unchanged attribute hidden)
+ confidential_instance_config {
+ enable_confidential_compute = (known after apply)
~ network_interface {
~ name               = "nic0" -> (known after apply)
~ network            = "<project id url>/global/networks/pweather-vpc" -> "pweather-vpc"
~ network_ip         = "" -> (known after apply)
~ subnetwork         = "<project id url>/subnetworks/pweather-subnet" -> "pweather-subnet"
~ subnetwork_project = "<project>" -> (known after apply)
~ access_config {
~ nat_ip       = "<NAT IP> -> (known after apply)
~ network_tier = "PREMIUM" -> (known after apply)
+ reservation_affinity {
+ type = (known after apply)
+ specific_reservation {
+ key    = (known after apply)
+ values = (known after apply)
~ scheduling {
~ automatic_restart   = true -> (known after apply)
~ min_node_cpus       = 0 -> (known after apply)
~ on_host_maintenance = "MIGRATE" -> (known after apply)
~ preemptible         = false -> (known after apply)
+ node_affinities {
+ key      = (known after apply)
+ operator = (known after apply)
+ values   = (known after apply)
- shielded_instance_config {
- enable_integrity_monitoring = true -> null
- enable_secure_boot          = false -> null
- enable_vtpm                 = true -> null
# module.dev_environment.google_compute_instance.dev_machine-minor must be replaced
-/+ resource "google_compute_instance" "dev_machine-minor" {
~ cpu_platform         = "Intel Broadwell" -> (known after apply)
~ current_status       = "RUNNING" -> (known after apply)
~ deletion_protection  = false -> true
- enable_display       = false -> null
~ guest_accelerator    = [] -> (known after apply)
~ id                   = "<project id url>/instances/dev-machine-minor-pweather" -> (known after apply)
~ instance_id          = "<instance id>" -> (known after apply)
~ label_fingerprint    = "<label fingerprint>" -> (known after apply)
- labels               = {} -> null
- metadata             = {} -> null
~ metadata_fingerprint = "udK04sf2kcQ=" -> (known after apply)
+ min_cpu_platform     = (known after apply)
name                 = "dev-machine-minor-pweather"
~ project              = "<project name>" -> (known after apply)
- resource_policies    = [] -> null
~ self_link            = "<project id url>/us-east4-a/instances/dev-machine-minor-pweather" -> (known after apply)
tags                 = [
~ tags_fingerprint     = "<tag fingerprint>" -> (known after apply)
~ zone                 = "us-east4-a" -> (known after apply)
# (2 unchanged attributes hidden)
~ boot_disk {
~ device_name                = "persistent-disk-0" -> (known after apply)
+ disk_encryption_key_sha256 = (known after apply)
+ kms_key_self_link          = (known after apply)
~ source                     = "<project id url>/us-east4-a/disks/dev-machine-minor-pweather" -> (known after apply)
# (2 unchanged attributes hidden)
~ initialize_params {
~ image  = "https://www.googleapis.com/compute/v1/projects/ubuntu-os-pro-cloud/global/images/ubuntu-pro-2004-focal-v20210720" -> "ubuntu-os-pro-cloud/ubuntu-pro-2004-lts" # forces replacement
~ labels = {} -> (known after apply)
~ type   = "pd-standard" -> (known after apply)
# (1 unchanged attribute hidden)
+ confidential_instance_config {
+ enable_confidential_compute = (known after apply)
~ network_interface {
~ name               = "nic0" -> (known after apply)
~ network            = "<project id url>>/global/networks/pweather-vpc" -> "pweather-vpc"
~ network_ip         = "" -> (known after apply)
~ subnetwork         = "<project id url>/us-east4/subnetworks/pweather-subnet" -> "pweather-subnet"
~ subnetwork_project = "<project>" -> (known after apply)
~ access_config {
~ nat_ip       = "<NAT IP>" -> (known after apply)
~ network_tier = "PREMIUM" -> (known after apply)
+ reservation_affinity {
+ type = (known after apply)
+ specific_reservation {
+ key    = (known after apply)
+ values = (known after apply)
~ scheduling {
~ automatic_restart   = true -> (known after apply)
~ min_node_cpus       = 0 -> (known after apply)
~ on_host_maintenance = "MIGRATE" -> (known after apply)
~ preemptible         = false -> (known after apply)
+ node_affinities {
+ key      = (known after apply)
+ operator = (known after apply)
+ values   = (known after apply)
- shielded_instance_config {
- enable_integrity_monitoring = true -> null
- enable_secure_boot          = false -> null
- enable_vtpm                 = true -> null
Plan: 2 to add, 0 to change, 2 to destroy.
Changes to Outputs:
~ vm_ip = "<VM IP>" -> (known after apply)
Note: You didn't specify an "-out" parameter to save this plan, so Terraform
can't guarantee that exactly these actions will be performed if
"terraform apply" is subsequently run.


编辑1:增加了'terraform plan'命令的输出。

补充Matt Schuchard的回答:



lifecycle {
ignore_changes = [ boot_disk ]


~ boot_disk {
~ initialize_params {
~ image  = "https://www.googleapis.com/compute/v1/projects/ubuntu-os-pro-cloud/global/images/ubuntu-pro-2004-focal-v20210720" -> "ubuntu-os-pro-cloud/ubuntu-pro-2004-lts" # forces replacement


