A Billing Budget Somebody Actually Hears About
The API accepts a budget with default recipients disabled and no channel, topic or threshold rule - a number that is tracked and never sent anywhere. Refuses that, insists on a FORECASTED_SPEND rule, and defaults credit_types_treatment to EXCLUDE_ALL_CREDITS, because a budget that counts credits measures your runway, not your spend, and looks healthy until the month they run out.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "billing_budget" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-billing-budget/gcp"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
gcp-billing-budget
A billing budget somebody actually hears about, measured on money you are
really going to be charged. Works with Terraform and OpenTofu (>= 1.6),
google provider >= 6.0, < 7.0.
The default recipients are the billing account admins. Usually one person
who set the account up years ago and a shared alias that filters to a folder.
disable_default_iam_recipients turns even that off, and the API accepts a
budget with it set and no channel, no topic and no project recipients: a
number that is tracked and never sent anywhere. Refused here without
accept_silent_budget.
No threshold rule means no notification. Threshold rules are optional in the API; a budget with none never crosses anything. Refused.
CURRENT_SPEND fires after the money is spent. FORECASTED_SPEND fires
when the month is on course to cross the line. The defaults include one;
removing it needs accept_actual_only.
credit_types_treatment defaults to INCLUDE_ALL_CREDITS in Google's API,
which measures your runway rather than your spend: a budget that counts
credits looks healthy until the month they run out. This module defaults to
EXCLUDE_ALL_CREDITS and says which one it is in measures_real_spend.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
gcp-org-policy
dry_run_spec is a separate configuration from spec and only spec enforces, so a dry-run policy appears in the console, evaluates everything and denies nothing. inherit_from_parent defaults to false, which makes a local addition silently REPLACE the organization policy rather than add to it.
gcp-project-factory
Opinionated project creation: API enablement, billing budget, default-SA lockdown, audit log sinks and baseline IAM.
gcp-resource-tags
Tag keys and values are definitions; conditional IAM, organisation policies and firewall rules read bindings, and a tag bound to nothing governs nothing while appearing fully defined. Bindings come with the keys - to folders, so every project beneath inherits - and the values that attach nowhere are listed in an output, along with the namespaced names conditions need.
gcp-essential-contacts
Without Essential Contacts, security notices, suspension warnings, billing problems and API shutdowns go to whoever holds Owner - a service account and an alias nobody reads - and the list is empty by default. Contacts per category, with a refusal when any category is left uncovered and an output naming the ones that still fall through to the Owner path.
oci-budget
The budget and its alert rules are separate resources, and recipients on a rule is optional: a budget created with no rule, or a rule with no address, computes actual and forecast spend and tells nobody but the console list. Refuses a budget no rule of which reaches an address, and insists on a FORECAST rule so the first alert is a warning rather than a receipt.
azure-budget
Azure requires a notification block, which makes the problem look solved: a notification can be created disabled, and contact_roles = Owner emails whoever holds the role, which is often a service principal with no mailbox. Insists on an enabled notification with a real address or action group, and on a Forecasted threshold so the first message arrives while there is still a month to act.