But an import block for a resource that doesn't exist is a hard error, so something has to answer "does this exist?" first. That answer is one Cloud Asset Inventory scan, and three times the inventory and Terraform disagreed about what a resource is even called: service accounts by numeric uid rather than email, Firestore by project number rather than project id, and Pub/Sub schemas and Scheduler jobs never returned at all.