Deploys a Vertex AI Vector Search Index onto an Index Endpoint for online nearest-neighbor query serving, targeting
hashicorp/google ~> 7.0.
- Creates exactly one
google_vertex_ai_index_endpoint_deployed_indexresource β this module performs the actual deployment stepterraform-google-vertex-ai-index-endpoint's own README explicitly said was out of scope. - This is the first module in this catalog with TWO required parent-scoping cross-module
inputs (
index+index_endpoint) β every other Vertex AI module so far has had at most one. - No
labelsfield exists on this resource at all β the first module in this domain's slice to genuinely lack labels support. - Confirmed timeout asymmetry:
create/updatedefault to 45 minutes,deleteto 20 minutes β longer than this domain's usual uniform 20-minute pattern, reflecting genuinely slow deployment operations. enable_access_loggingdefaults totrueβ a newly-documented extension of this suite's general audit-logging secure-default row to this Vertex AI module.
π‘ Why it matters: Building an Index and an Index Endpoint doesn't serve any queries on its own β this module is the missing link that actually puts an Index online for nearest-neighbor lookups.
If these Terraform modules have been helpful to you or your organization, I'd appreciate your support in any of the following ways:
- β Star this repository to help others discover this Terraform module.
- π€ Connect with me on LinkedIn: linkedin.com/in/microsoftexpert
- β Buy me a coffee: buymeacoffee.com/microsoftexpert
Whether it's a star, a professional connection, or a coffee, every gesture helps keep these modules actively maintained and continually improving. Thank you for being part of the community!
flowchart LR
IDX["terraform-google-vertex-ai-index"]:::keystone
IEP["terraform-google-vertex-ai-index-endpoint"]:::keystone
THIS["terraform-google-vertex-ai-index-endpoint-deployed-index<br/>(this module)"]:::thismodule
GA["terraform-google-global-address<br/>(optional)"]:::external
SA["terraform-google-service-account<br/>(optional)"]:::external
IDX -->|"id -> index (required)"| THIS
IEP -->|"id -> index_endpoint (required)"| THIS
GA -.->|"name -> reserved_ip_ranges (optional)"| THIS
SA -.->|"email -> deployed_index_auth_config.auth_provider.allowed_issuers (optional)"| THIS
classDef thismodule fill:#4285F4,color:#FFFFFF,stroke:#174EA6,stroke-width:1px;
classDef keystone fill:#174EA6,color:#FFFFFF,stroke:#174EA6,stroke-width:1px;
classDef external fill:#E8EAED,color:#202124,stroke:#9AA0A6,stroke-width:1px,stroke-dasharray: 3 3;
Validated via the Mermaid Chart MCP (valid: true). Part of the existing data-ml subgraph. Both
terraform-google-vertex-ai-index and terraform-google-vertex-ai-index-endpoint are equally required
upstream keystones β neither is more load-bearing than the other.
flowchart TB
subgraph Inputs
DEPID["var.deployed_index_id"]
IDX["var.index"]
IEP["var.index_endpoint"]
AUTOR["var.automatic_resources"]
DEDR["var.dedicated_resources"]
end
KEYSTONE["google_vertex_ai_index_endpoint_deployed_index.this<br/>(two required parents)"]:::keystone
subgraph Outputs
ID["id"]
NM["name"]
CT["create_time"]
end
DEPID --> KEYSTONE
IDX --> KEYSTONE
IEP --> KEYSTONE
AUTOR --> KEYSTONE
DEDR --> KEYSTONE
KEYSTONE --> ID
KEYSTONE --> NM
KEYSTONE --> CT
classDef keystone fill:#174EA6,color:#FFFFFF,stroke:#174EA6,stroke-width:1px;
Validated via the Mermaid Chart MCP (valid: true). Visually distinguish this from every prior
single-parent Vertex AI module in this catalog β two required parent inputs feed the keystone.
Resource inventory: google_vertex_ai_index_endpoint_deployed_index.this (1 resource).
| Component | Requirement |
|---|---|
| Terraform | >= 1.12.0 |
hashicorp/google |
~> 7.0 (resolved v7.39.0 during authoring) |
| Provider block | None β the caller configures google |
Schema notes that bite:
deployed_indexesdoes not exist on the Index Endpoint resource itself β this module is the real, separately Terraform-manageable deployment mechanism, background context for why it exists at all.- No
labelsfield at all. - Confirmed 45/45/20 timeout asymmetry β not this domain's usual uniform 20 minutes.
- No
self_linkand noupdate_timeattribute β the missingupdate_timeis a genuine asymmetry with every other Vertex AI module in this catalog. automatic_resources/dedicated_resourcesare NOT textually confirmed mutually exclusive β unlike the sibling Index Endpoint'snetwork/private_service_connect_configpair.
roles/aiplatform.useron the target project β deploy/undeploy indexes; same role as every other module in this domain.
aiplatform.googleapis.comenabled (viaterraform-google-project-services).- Both the target Index and the target Index Endpoint must already exist and be applied first β hard dependencies, not optional cross-references.
- If
reserved_ip_rangesis used, the referenced GCE address(es) must already exist under the peered VPC. - Deployment operations are genuinely slow β expect apply times consistent with the confirmed 45-minute create/update default.
terraform-google-vertex-ai-index-endpoint-deployed-index/
βββ providers.tf
βββ variables.tf # deployed_index_id, index, index_endpoint, automatic_resources,...
βββ main.tf # google_vertex_ai_index_endpoint_deployed_index.this
βββ outputs.tf # id, name, create_time, index_sync_time, private_endpoints β no self_link/update_time/labels
βββ README.md
βββ SCOPE.md
βββ examples/
βββ basic/
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "prodDeployment01"
index = module.index.id
index_endpoint = module.index_endpoint.id
}Consumes:
| Input | Type | Source module |
|---|---|---|
index |
string (.id form) |
terraform-google-vertex-ai-index (required) |
index_endpoint |
string (.id form) |
terraform-google-vertex-ai-index-endpoint (required) |
reserved_ip_ranges entries |
string (.name form) |
terraform-google-global-address (optional) |
deployed_index_auth_config.auth_provider.allowed_issuers entries |
string (.email form) |
terraform-google-service-account (optional) |
Emits:
| Output | Description | Consumed by |
|---|---|---|
id |
Composite {{index_endpoint}}/deployedIndex/{{deployed_index_id}} β no self_link |
None β terminal |
name |
Computed | None |
create_time |
No corresponding update_time |
None |
index_sync_time |
Latest-state sync flag | None |
private_endpoints |
Conditional/informational | None |
1 Β· Minimal deployment β three required fields only
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "basicDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
}βΉοΈ
automatic_resources/dedicated_resourcesleft entirely at provider defaults here.
2 Β· automatic_resources with explicit replica counts
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "autoScaledDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
automatic_resources = {
min_replica_count = 2
max_replica_count = 10
}
}3 Β· dedicated_resources with an explicit machine_type
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "dedicatedDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
dedicated_resources = {
machine_spec = {
machine_type = "e2-standard-16"
}
min_replica_count = 2
max_replica_count = 4
}
}π No
machine_type/replica-count default is baked into this module β the caller must make an explicit, informed sizing choice, mirroring the cost-safety framing already established forterraform-google-vertex-ai-deployment-resource-pool.
4 Β· deployed_index_auth_config wired to a service account
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "authenticatedDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
deployed_index_auth_config = {
auth_provider = {
allowed_issuers = [module.query_client_sa.email]
audiences = ["https://query-client.example.com"]
}
}
}5 Β· reserved_ip_ranges + deployment_group
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "prodDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
reserved_ip_ranges = [module.reserved_address.name]
deployment_group = "prod"
}6 Β· enable_access_logging toggled off
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "noLoggingDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
enable_access_logging = false
}
β οΈ This module defaultsenable_access_loggingtotrueper this suite's general audit-logging row β only disable it with an explicit, deliberate reason.
7 Β· A display_name
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "labeledDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
display_name = "Production Vector Search Deployment"
}8 Β· Explicit region
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "regionalDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
region = "us-central1"
}9 Β· Relying on the default deletion_policy = "PREVENT"
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "protectedDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
}βΉοΈ No
deletion_policyset here β the module default of"PREVENT"applies. Destroying a DeployedIndex that is actively serving production query traffic is a real operational hazard.
10 Β· deletion_policy = "DELETE" opt-out
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "scratchDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
deletion_policy = "DELETE"
}11 Β· deletion_policy = "ABANDON"
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "migratingDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
deletion_policy = "ABANDON"
}12 Β· Custom timeouts (45/45/20 default, not 20/20/20)
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "extendedTimeoutDeployment"
index = module.index.id
index_endpoint = module.index_endpoint.id
timeouts = {
create = "90m"
update = "90m"
delete = "30m"
}
}βΉοΈ This resource's own provider defaults are already asymmetric β 45 minutes for create/update, 20 minutes for delete β do not assume a uniform 20-minute baseline when overriding.
13 Β· ποΈ End-to-end composition
Completing the three-module Index β Index Endpoint β Deployed Index chain this catalog has now fully closed.
module "index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index.git?ref=v1.0.0"
display_name = "casey-prod-vector-index"
region = "us-central1"
#... metadata, index_update_method, etc.
}
module "index_endpoint" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint.git?ref=v1.0.0"
display_name = "casey-prod-index-endpoint"
region = "us-central1"
#... network or public_endpoint_enabled, etc.
}
module "deployed_index" {
source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"
deployed_index_id = "prodDeployment01"
index = module.index.id
index_endpoint = module.index_endpoint.id
automatic_resources = {
min_replica_count = 2
max_replica_count = 10
}
}| Variable | Type | Default | Notes |
|---|---|---|---|
deployed_index_id |
string |
β (required) | Up to 128 chars, must start with a letter |
index |
string |
β (required) | Consumes terraform-google-vertex-ai-index's id |
index_endpoint |
string |
β (required) | Consumes terraform-google-vertex-ai-index-endpoint's id |
display_name |
string |
null |
Up to 128 UTF-8 chars |
automatic_resources |
object({...}) |
null |
Not confirmed mutually exclusive with dedicated_resources |
dedicated_resources |
object({...}) |
null |
No baked-in machine_type/replica-count default |
enable_access_logging |
bool |
true |
House secure-by-default extension |
deployed_index_auth_config |
object({...}) |
null |
No default audiences/issuers |
reserved_ip_ranges |
list(string) |
[] |
Names, not ids/self_links |
deployment_group |
string |
null |
Up to 64 chars |
region |
string |
null |
No hardcoded allow-list |
deletion_policy |
string |
"PREVENT" |
Closed enum; house extension over provider default |
timeouts |
object({...}) |
null |
create/update default 45 min, delete default 20 min |
No labels variable β confirmed absent from this resource's schema entirely.
| Output | Description |
|---|---|
id |
Composite {{index_endpoint}}/deployedIndex/{{deployed_index_id}} |
name |
Computed |
create_time |
No corresponding update_time exists |
index_sync_time |
Latest-state sync flag |
private_endpoints |
Conditional/informational |
No self_link, no update_time, no labels-related output.
- Two required parent-scoping cross-module inputs β the single most structurally distinctive fact about this module in this catalog.
- Confirmed 45/45/20 timeout asymmetry β index deployment provisions real serving infrastructure; expect apply times to reflect that.
- Update-in-place finding: the schema's distinct
updatetimeout (matchingcreate, notdelete) is real evidence of a genuine in-place update path (likelyMutateDeployedIndex) β butdeployed_index_id/index/index_endpointare near-certainly force-new in practice as identity fields, an inference from their role, not a textually confirmed ForceNew flag. - No
labelsfield β the first module in this domain's slice to lack it.
| Concern | Secure default | Opt-out (explicit) |
|---|---|---|
| Access log visibility | enable_access_logging = true β house extension of this suite's general audit-logging row, applied to this Vertex AI module for the first time |
Caller sets false explicitly |
| Accidental destroy of a live, serving deployment | deletion_policy = "PREVENT" (house extension over the provider's native "DELETE" default) |
Caller sets "DELETE" or "ABANDON" explicitly |
| Compute sizing cost | No baked-in automatic_resources/dedicated_resources default β the caller must make an explicit, informed sizing choice, mirroring terraform-google-vertex-ai-deployment-resource-pool's own cost-safety framing |
N/A β deliberate absence of a default |
cd terraform-google-vertex-ai-index-endpoint-deployed-index
terraform init -backend=false
terraform validate
terraform fmt -checkvalidate/fmt cannot catch a "parent Index or Index Endpoint doesn't exist yet" apply-time
failure, a genuinely long deployment exceeding the 45-minute default under load, or a
reserved_ip_ranges address that doesn't actually exist β only a real plan/apply against a
live project would.
$ terraform output
id = "projects/casey-prod/locations/us-central1/indexEndpoints/casey-prod-index-endpoint/deployedIndex/prodDeployment01"
name = "prodDeployment01"
create_time = "2026-07-14T12:00:00Z"
index_sync_time = "2026-07-14T12:05:00Z"
| Symptom | Cause | Fix |
|---|---|---|
| Apply fails because the referenced Index or Index Endpoint does not exist | This module was applied before either parent resource | Apply terraform-google-vertex-ai-index and terraform-google-vertex-ai-index-endpoint first |
| Apply appears to hang past 45 minutes during index deployment | Index deployment is a genuinely slow API operation; large indexes or high load can exceed the default timeout | Increase timeouts.create/timeouts.update explicitly; this is expected behavior, not a bug |
No labels input exists, unlike every other module in this domain |
This resource's schema genuinely has no labels field β confirmed absent | There is no workaround; label the parent Index/Index Endpoint instead if tagging is required |
google_vertex_ai_index_endpoint_deployed_indexprovider docsterraform-google-vertex-ai-index-endpointβ this module's own SCOPE.md documented the gap this module closesterraform-google-vertex-ai-index- This module's
SCOPE.md