A Snapshot Schedule Attached to Disks, that Outlives Them
The resource policy is the schedule; a disk follows it only through a separate attachment, so a policy that reads daily-keep-30 in the console and is attached to nothing has never taken a snapshot. Takes the disks with the schedule and refuses one with none. Keeps the snapshots when the disk is deleted, because APPLY_RETENTION_POLICY lets them age out in exactly the window they are needed.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "snapshot_schedule" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-snapshot-schedule/gcp"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
gcp-snapshot-schedule
A snapshot schedule that is attached to disks, and that outlives them. Works
with Terraform and OpenTofu (>= 1.6), google provider >= 6.0, < 7.0.
A schedule attached to no disk snapshots nothing. The resource policy is
the schedule; a disk follows it only once the policy is attached to that
disk, which is a separate resource. A policy that reads "daily, keep 30" in
the console and is attached to nothing has never produced a snapshot. This
module takes the disks with the schedule and refuses one with none unless
accept_unattached_schedule.
APPLY_RETENTION_POLICY deletes the snapshots when the disk is deleted -
they keep ageing out on the normal schedule after the disk is gone, which is
the window in which they are usually needed. This module keeps them
(KEEP_AUTO_SNAPSHOTS); the other setting needs
accept_snapshots_deleted_with_disk.
Storage location decides what a regional outage takes with it. A snapshot in the disk's own region shares its fate; the default is the nearest multi-region.
guest_flush needs the guest agent. Without it the snapshot is taken
anyway, crash-consistent, and the flag is a statement of intent.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
gcp-backup-dr
The vault and the plan are what the console shows; the association is what makes a backup exist, and a plan associated with nothing backs up nothing. Enforced retention is the setting ransomware cannot undo - no backup younger than it can be deleted by anyone - and WITHIN_PROJECT access lets a compromised owner restore everything. Resources come with the plan; 14 days enforced; org-scoped.
gcp-storage-transfer
delete_objects_unique_in_sink turns a backup into a mirror: an object deleted at the source is deleted at the destination on the next run, replicating the event the copy was meant to survive; and a job with no notification fails while its status stays ENABLED. Copies only, refuses mirroring and moving unless accepted, publishes every outcome to a topic, and spells out what the service agent needs.
gcp-filestore
A managed Cloud Filestore NFS share for GKE and Compute Engine, VPC-peered with no public exposure, optional per-client export rules for least-privilege access, and deletion protection on.
gcp-gcs-bucket
Hardened GCS bucket with uniform access, versioning, lifecycle/soft-delete policies, CMEK and least-privilege IAM.