Skip to content

About

Terraform module: terraform-google-vertex-ai-index-endpoint-deployed-index

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

Β 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

☁️ Google Cloud Vertex AI Index Endpoint Deployed Index Terraform Module

Deploys a Vertex AI Vector Search Index onto an Index Endpoint for online nearest-neighbor query serving, targeting hashicorp/google ~> 7.0.

Terraform Provider Module Type Resources Posture


🧩 Overview

  • Creates exactly one google_vertex_ai_index_endpoint_deployed_index resource β€” this module performs the actual deployment step terraform-google-vertex-ai-index-endpoint's own README explicitly said was out of scope.
  • This is the first module in this catalog with TWO required parent-scoping cross-module inputs (index + index_endpoint) β€” every other Vertex AI module so far has had at most one.
  • No labels field exists on this resource at all β€” the first module in this domain's slice to genuinely lack labels support.
  • Confirmed timeout asymmetry: create/update default to 45 minutes, delete to 20 minutes β€” longer than this domain's usual uniform 20-minute pattern, reflecting genuinely slow deployment operations.
  • enable_access_logging defaults to true β€” a newly-documented extension of this suite's general audit-logging secure-default row to this Vertex AI module.

πŸ’‘ Why it matters: Building an Index and an Index Endpoint doesn't serve any queries on its own β€” this module is the missing link that actually puts an Index online for nearest-neighbor lookups.


❀️ Support this project

If these Terraform modules have been helpful to you or your organization, I'd appreciate your support in any of the following ways:

Whether it's a star, a professional connection, or a coffee, every gesture helps keep these modules actively maintained and continually improving. Thank you for being part of the community!


πŸ—ΊοΈ Where this fits

flowchart LR
 IDX["terraform-google-vertex-ai-index"]:::keystone
 IEP["terraform-google-vertex-ai-index-endpoint"]:::keystone
 THIS["terraform-google-vertex-ai-index-endpoint-deployed-index<br/>(this module)"]:::thismodule
 GA["terraform-google-global-address<br/>(optional)"]:::external
 SA["terraform-google-service-account<br/>(optional)"]:::external

 IDX -->|"id -> index (required)"| THIS
 IEP -->|"id -> index_endpoint (required)"| THIS
 GA -.->|"name -> reserved_ip_ranges (optional)"| THIS
 SA -.->|"email -> deployed_index_auth_config.auth_provider.allowed_issuers (optional)"| THIS

 classDef thismodule fill:#4285F4,color:#FFFFFF,stroke:#174EA6,stroke-width:1px;
 classDef keystone fill:#174EA6,color:#FFFFFF,stroke:#174EA6,stroke-width:1px;
 classDef external fill:#E8EAED,color:#202124,stroke:#9AA0A6,stroke-width:1px,stroke-dasharray: 3 3;
Loading

Validated via the Mermaid Chart MCP (valid: true). Part of the existing data-ml subgraph. Both terraform-google-vertex-ai-index and terraform-google-vertex-ai-index-endpoint are equally required upstream keystones β€” neither is more load-bearing than the other.


🧬 What this builds

flowchart TB
 subgraph Inputs
 DEPID["var.deployed_index_id"]
 IDX["var.index"]
 IEP["var.index_endpoint"]
 AUTOR["var.automatic_resources"]
 DEDR["var.dedicated_resources"]
 end

 KEYSTONE["google_vertex_ai_index_endpoint_deployed_index.this<br/>(two required parents)"]:::keystone

 subgraph Outputs
 ID["id"]
 NM["name"]
 CT["create_time"]
 end

 DEPID --> KEYSTONE
 IDX --> KEYSTONE
 IEP --> KEYSTONE
 AUTOR --> KEYSTONE
 DEDR --> KEYSTONE

 KEYSTONE --> ID
 KEYSTONE --> NM
 KEYSTONE --> CT

 classDef keystone fill:#174EA6,color:#FFFFFF,stroke:#174EA6,stroke-width:1px;
Loading

Validated via the Mermaid Chart MCP (valid: true). Visually distinguish this from every prior single-parent Vertex AI module in this catalog β€” two required parent inputs feed the keystone.

Resource inventory: google_vertex_ai_index_endpoint_deployed_index.this (1 resource).


βœ… Provider / Versions

Component Requirement
Terraform >= 1.12.0
hashicorp/google ~> 7.0 (resolved v7.39.0 during authoring)
Provider block None β€” the caller configures google

Schema notes that bite:

  • deployed_indexes does not exist on the Index Endpoint resource itself β€” this module is the real, separately Terraform-manageable deployment mechanism, background context for why it exists at all.
  • No labels field at all.
  • Confirmed 45/45/20 timeout asymmetry β€” not this domain's usual uniform 20 minutes.
  • No self_link and no update_time attribute β€” the missing update_time is a genuine asymmetry with every other Vertex AI module in this catalog.
  • automatic_resources/dedicated_resources are NOT textually confirmed mutually exclusive β€” unlike the sibling Index Endpoint's network/private_service_connect_config pair.

πŸ”‘ Required IAM Roles

  • roles/aiplatform.user on the target project β€” deploy/undeploy indexes; same role as every other module in this domain.

☁️ GCP Prerequisites

  • aiplatform.googleapis.com enabled (via terraform-google-project-services).
  • Both the target Index and the target Index Endpoint must already exist and be applied first β€” hard dependencies, not optional cross-references.
  • If reserved_ip_ranges is used, the referenced GCE address(es) must already exist under the peered VPC.
  • Deployment operations are genuinely slow β€” expect apply times consistent with the confirmed 45-minute create/update default.

πŸ“ Module Structure

terraform-google-vertex-ai-index-endpoint-deployed-index/
β”œβ”€β”€ providers.tf
β”œβ”€β”€ variables.tf # deployed_index_id, index, index_endpoint, automatic_resources,...
β”œβ”€β”€ main.tf # google_vertex_ai_index_endpoint_deployed_index.this
β”œβ”€β”€ outputs.tf # id, name, create_time, index_sync_time, private_endpoints β€” no self_link/update_time/labels
β”œβ”€β”€ README.md
β”œβ”€β”€ SCOPE.md
└── examples/
 └── basic/

βš™οΈ Quick Start

module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "prodDeployment01"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id
}

πŸ”Œ Cross-Module Contract

Consumes:

Input Type Source module
index string (.id form) terraform-google-vertex-ai-index (required)
index_endpoint string (.id form) terraform-google-vertex-ai-index-endpoint (required)
reserved_ip_ranges entries string (.name form) terraform-google-global-address (optional)
deployed_index_auth_config.auth_provider.allowed_issuers entries string (.email form) terraform-google-service-account (optional)

Emits:

Output Description Consumed by
id Composite {{index_endpoint}}/deployedIndex/{{deployed_index_id}} β€” no self_link None β€” terminal
name Computed None
create_time No corresponding update_time None
index_sync_time Latest-state sync flag None
private_endpoints Conditional/informational None

πŸ“š Example Library

1 Β· Minimal deployment β€” three required fields only
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "basicDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id
}

ℹ️ automatic_resources/dedicated_resources left entirely at provider defaults here.

2 Β· automatic_resources with explicit replica counts
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "autoScaledDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id

  automatic_resources = {
    min_replica_count = 2
    max_replica_count = 10
  }
}
3 Β· dedicated_resources with an explicit machine_type
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "dedicatedDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id

  dedicated_resources = {
    machine_spec = {
      machine_type = "e2-standard-16"
    }
    min_replica_count = 2
    max_replica_count = 4
  }
}

πŸ”’ No machine_type/replica-count default is baked into this module β€” the caller must make an explicit, informed sizing choice, mirroring the cost-safety framing already established for terraform-google-vertex-ai-deployment-resource-pool.

4 Β· deployed_index_auth_config wired to a service account
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "authenticatedDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id

  deployed_index_auth_config = {
    auth_provider = {
      allowed_issuers = [module.query_client_sa.email]
      audiences       = ["https://query-client.example.com"]
    }
  }
}
5 Β· reserved_ip_ranges + deployment_group
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id  = "prodDeployment"
  index              = module.index.id
  index_endpoint     = module.index_endpoint.id
  reserved_ip_ranges = [module.reserved_address.name]
  deployment_group   = "prod"
}
6 Β· enable_access_logging toggled off
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id     = "noLoggingDeployment"
  index                 = module.index.id
  index_endpoint        = module.index_endpoint.id
  enable_access_logging = false
}

⚠️ This module defaults enable_access_logging to true per this suite's general audit-logging row β€” only disable it with an explicit, deliberate reason.

7 Β· A display_name
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "labeledDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id
  display_name      = "Production Vector Search Deployment"
}
8 Β· Explicit region
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "regionalDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id
  region            = "us-central1"
}
9 Β· Relying on the default deletion_policy = "PREVENT"
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "protectedDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id
}

ℹ️ No deletion_policy set here β€” the module default of "PREVENT" applies. Destroying a DeployedIndex that is actively serving production query traffic is a real operational hazard.

10 Β· deletion_policy = "DELETE" opt-out
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "scratchDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id
  deletion_policy   = "DELETE"
}
11 Β· deletion_policy = "ABANDON"
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "migratingDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id
  deletion_policy   = "ABANDON"
}
12 Β· Custom timeouts (45/45/20 default, not 20/20/20)
module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "extendedTimeoutDeployment"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id

  timeouts = {
    create = "90m"
    update = "90m"
    delete = "30m"
  }
}

ℹ️ This resource's own provider defaults are already asymmetric β€” 45 minutes for create/update, 20 minutes for delete β€” do not assume a uniform 20-minute baseline when overriding.

13 Β· πŸ—οΈ End-to-end composition

Completing the three-module Index β†’ Index Endpoint β†’ Deployed Index chain this catalog has now fully closed.

module "index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index.git?ref=v1.0.0"

  display_name = "casey-prod-vector-index"
  region       = "us-central1"
  #... metadata, index_update_method, etc.
}

module "index_endpoint" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint.git?ref=v1.0.0"

  display_name = "casey-prod-index-endpoint"
  region       = "us-central1"
  #... network or public_endpoint_enabled, etc.
}

module "deployed_index" {
  source = "git::https://github.com/microsoftexpert/terraform-google-vertex-ai-index-endpoint-deployed-index.git?ref=v1.0.0"

  deployed_index_id = "prodDeployment01"
  index             = module.index.id
  index_endpoint    = module.index_endpoint.id

  automatic_resources = {
    min_replica_count = 2
    max_replica_count = 10
  }
}

πŸ“₯ Inputs

Variable Type Default Notes
deployed_index_id string β€” (required) Up to 128 chars, must start with a letter
index string β€” (required) Consumes terraform-google-vertex-ai-index's id
index_endpoint string β€” (required) Consumes terraform-google-vertex-ai-index-endpoint's id
display_name string null Up to 128 UTF-8 chars
automatic_resources object({...}) null Not confirmed mutually exclusive with dedicated_resources
dedicated_resources object({...}) null No baked-in machine_type/replica-count default
enable_access_logging bool true House secure-by-default extension
deployed_index_auth_config object({...}) null No default audiences/issuers
reserved_ip_ranges list(string) [] Names, not ids/self_links
deployment_group string null Up to 64 chars
region string null No hardcoded allow-list
deletion_policy string "PREVENT" Closed enum; house extension over provider default
timeouts object({...}) null create/update default 45 min, delete default 20 min

No labels variable β€” confirmed absent from this resource's schema entirely.


🧾 Outputs

Output Description
id Composite {{index_endpoint}}/deployedIndex/{{deployed_index_id}}
name Computed
create_time No corresponding update_time exists
index_sync_time Latest-state sync flag
private_endpoints Conditional/informational

No self_link, no update_time, no labels-related output.


🧠 Architecture Notes

  • Two required parent-scoping cross-module inputs β€” the single most structurally distinctive fact about this module in this catalog.
  • Confirmed 45/45/20 timeout asymmetry β€” index deployment provisions real serving infrastructure; expect apply times to reflect that.
  • Update-in-place finding: the schema's distinct update timeout (matching create, not delete) is real evidence of a genuine in-place update path (likely MutateDeployedIndex) β€” but deployed_index_id/index/index_endpoint are near-certainly force-new in practice as identity fields, an inference from their role, not a textually confirmed ForceNew flag.
  • No labels field β€” the first module in this domain's slice to lack it.

🧱 Design Principles

Concern Secure default Opt-out (explicit)
Access log visibility enable_access_logging = true β€” house extension of this suite's general audit-logging row, applied to this Vertex AI module for the first time Caller sets false explicitly
Accidental destroy of a live, serving deployment deletion_policy = "PREVENT" (house extension over the provider's native "DELETE" default) Caller sets "DELETE" or "ABANDON" explicitly
Compute sizing cost No baked-in automatic_resources/dedicated_resources default β€” the caller must make an explicit, informed sizing choice, mirroring terraform-google-vertex-ai-deployment-resource-pool's own cost-safety framing N/A β€” deliberate absence of a default

πŸš€ Runbook

cd terraform-google-vertex-ai-index-endpoint-deployed-index
terraform init -backend=false
terraform validate
terraform fmt -check

πŸ§ͺ Testing

validate/fmt cannot catch a "parent Index or Index Endpoint doesn't exist yet" apply-time failure, a genuinely long deployment exceeding the 45-minute default under load, or a reserved_ip_ranges address that doesn't actually exist β€” only a real plan/apply against a live project would.


πŸ’¬ Example Output

$ terraform output
id = "projects/casey-prod/locations/us-central1/indexEndpoints/casey-prod-index-endpoint/deployedIndex/prodDeployment01"
name = "prodDeployment01"
create_time = "2026-07-14T12:00:00Z"
index_sync_time = "2026-07-14T12:05:00Z"

πŸ” Troubleshooting

Symptom Cause Fix
Apply fails because the referenced Index or Index Endpoint does not exist This module was applied before either parent resource Apply terraform-google-vertex-ai-index and terraform-google-vertex-ai-index-endpoint first
Apply appears to hang past 45 minutes during index deployment Index deployment is a genuinely slow API operation; large indexes or high load can exceed the default timeout Increase timeouts.create/timeouts.update explicitly; this is expected behavior, not a bug
No labels input exists, unlike every other module in this domain This resource's schema genuinely has no labels field β€” confirmed absent There is no workaround; label the parent Index/Index Endpoint instead if tagging is required

πŸ”— Related Docs

About

Terraform module: terraform-google-vertex-ai-index-endpoint-deployed-index

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages