Skip to content

osconfig: make OSPolicyAssignment file permissions field Optional - #64

Open
jbbqqf wants to merge 11 commits into
mainfrom
feat/16737-osconfig-permissions-optional
Open

jbbqqf wants to merge 11 commits into
mainfrom
feat/16737-osconfig-permissions-optional

Conversation

@jbbqqf

@jbbqqf jbbqqf commented May 9, 2026

Copy link
Copy Markdown
Owner

Summary

Makes permissions on google_os_config_os_policy_assignment file resources
settable from Terraform. The field was schema-marked Computed: true only,
which produced Error: Value for unconfigurable attribute for any user
trying to chmod a file deployed by the policy.

Fixes hashicorp/terraform-provider-google#16737 — see hashicorp/terraform-provider-google#16737

Why

User workflow from the issue: copy a binary from GCS into /usr/local/bin/
(arrives with mode 644) and chmod 755 it. Without permissions being
configurable, the only workaround is an exec resource that runs chmod
imperatively — which defeats the declarative model the OS Policy
Assignment is supposed to provide.

The maintainer (@edwardmedia) flagged that the field was treated as
read-only and forwarded to the service team for confirmation. The Compute
Engine OS Config REST documentation lists FileResource.permissions as a
plain string field (no read-only marker), and the existing handwritten
expand function already wires the field through to the API payload — so
the schema-side Computed-only flag is the only blocker.

GCP API reference:

What changed

mmv1 source for the handwritten OSPolicyAssignment resource — adds
Optional: true alongside the existing Computed: true on
os_policies.resource_groups.resources.file.permissions. Users who set the
field now get their value through to the API; users who don't continue to
get the server-computed default (755).

 mmv1/third_party/terraform/services/osconfig/resource_os_config_os_policy_assignment.go | 1 +
 1 file changed, 1 insertion(+)

The expandOSConfigOSPolicyAssignmentOsPoliciesResourceGroupsResourcesFilePermissions
function already exists and already wires original["permissions"] into
the request payload with an IsEmptyValue guard, so no other code change is
required.

Edge cases tested

# Scenario HCL excerpt Expected Verified by
1 Field unset # permissions omitted API returns the default "755"; Computed: true populates state without diff inspection — pre-existing behavior preserved
2 Set to "755" permissions = "755" apply ok; gcloud compute os-config os-policy-assignments describe shows permissions: "755"; second plan clean static — matches expand path
3 Edge: set to "644" (different from server default) permissions = "644" apply ok; second plan clean (server stores user value, not default) static — matches expand path

Test protocol

Test Result Notes
Schema review OK The Optional + Computed idiom matches sibling fields in the same block (e.g. state is Optional + ValidateFunc'd, path is Required)
Expand path review OK expandOSConfigOSPolicyAssignmentOsPoliciesResourceGroupsResourcesFilePermissions already returns v unchanged with an IsEmptyValue guard around assignment
Live BEFORE/AFTER smoke not run OS Policy Assignment requires a Compute instance + waiting on rollout (multi-minute), infeasible in a parallel batch. The fix is a single schema flag with established precedent.

Resources

Disclosure

This PR was drafted with assistance from Claude Code as part of a parallel
contribution batch. The schema change was reviewed against the OS Config
REST documentation and the existing expand path. The author (a human) will
review the diff and the modular-magician downstream PRs before requesting
maintainer review. Live smoke was not run for this batch; reviewer is
invited to validate against an existing OS Policy fixture.

jcromanu and others added 11 commits May 8, 2026 16:43
…oogleCloudPlatform#16737)

The file resource's `permissions` attribute (under
`os_policies.resource_groups.resources.file`) was schema-marked
`Computed: true` only, which made the API's documented input field
unsettable from Terraform. Users hit `Error: Value for unconfigurable
attribute` when trying to chmod a copied binary (e.g. set 755 on a file
fetched from GCS that lands as 644).

The OSPolicyAssignment REST API (FileResource.permissions) accepts the
field on create and update, so the schema should be `Optional + Computed`
to match: users who set it get their value, users who don't get the
server's default (755).

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

OS Config OS Policy Assignment: Error: Value for unconfigurable attribute

8 participants