We began the process of removing this IP list from the blocked list of IPs, by emptying the array Terraform, when supplied with an empty list, changes the underlying GCP firewall rule to remove the source IP list - essentially changing the meaning of the rule as read in Terraform from “block this empty list of IPs” to “block everything”. Automatically apply “page override” for merging changes (for faster notification) Skip the “plan” phase during a revert for Terraform Safely removing the offending firewall rule and audit all remaining legacy Google Cloud firewall rules for loose specificity