Skip to main content

AlmaForge Terraform Provider

Manage roles, locks, SSO connectors, and approval connectors through the AlmaForge API. Authenticate with alma login before running Terraform. The provider uses your current CLI profile unless you select another profile.

Start with the Terraform guide for a complete first apply. You need an existing cluster, a working CLI login, and an identity permitted to manage the resources in your configuration. The provider changes resources inside the cluster. It does not install AlmaForge or bootstrap the first administrator.

Use a resource block to create or manage an object. Use a data block to read an existing object without taking ownership. See resources and data sources for the supported kinds and their product guides.

The configuration reference describes the underlying resources and their manifests.

Example Usage​

HCL
terraform {
required_providers {
almaforge = {
source = "get.almaforge.com/almaforge/almaforge"
}
}
}

provider "almaforge" {}

Authentication​

An empty provider block uses the current alma profile. Set the ALMA_PROXY environment variable to a saved cluster's proxy hostname, optionally with a port, to select another profile. The provider reads profiles from $XDG_CONFIG_HOME/almaforge when XDG_CONFIG_HOME is set, or ~/.config/almaforge otherwise. These environment variables work the same way in alma and Terraform.

Run alma status to check the current identity and certificate expiry. Renew an expired login with alma login before planning or applying. The provider reads existing credentials and does not renew them. For automation, prepare a profile using CLI workload sessions in the same job.

State and ownership​

Configuration is authoritative. Removing an optional field resets its API default or clears it. A removed role grant is revoked on apply. Read changes and deletion before managing an existing policy.

Import existing resources rather than trying to create them again. Follow import existing resources, and keep each object under one owner.

Connector secrets remain in Terraform state and saved plans even when marked sensitive. Follow connector secrets before adding SSO or approval connectors.

Schema​

Resources​

Data Sources​