Skip to main content

almaforge_github_connector Data Source

Read an AlmaForge GithubConnector resource by name.

This data source reads existing cluster resources. It does not create, change, or delete them. Authenticate using the Terraform setup guide. Your identity needs permission to read the selected resources.

See GitHub SSO for OAuth app settings and team-to-role mapping. Secret fields are redacted by the API and returned as null.

See the configuration reference for the resource manifest and field context.

Set name to the existing object's metadata.name. The result is available in metadata and spec. A missing object produces an error.

Example Usage​

Save this configuration in a new directory. Replace the example name with the existing object you want to read. Review the plan before applying it. Applying this data-only configuration saves the outputs without changing cluster resources.

Terminal
terraform initterraform plan -out=plan.tfplanterraform apply plan.tfplanterraform output
HCL
terraform {
required_providers {
almaforge = {
source = "get.almaforge.com/almaforge/almaforge"
}
}
}

provider "almaforge" {}

data "almaforge_github_connector" "existing" {
name = "github"
}

output "name" {
value = data.almaforge_github_connector.existing.metadata.name
}

To manage changes instead of only reading, use the resource. Read resources versus data sources before choosing ownership.

Schema​

Required​

  • name (String) Name of the resource to read.

Read-Only​

Nested Schema for metadata​

Read-Only:

  • labels (Map of String) Labels attached to the resource.
  • name (String) Resource name. Changing this name replaces the resource.
  • resource_version (String) Server revision used to detect concurrent changes.

Nested Schema for spec​

Read-Only:

  • allowed_email_domains (List of String) AllowedEmailDomains is an optional ordered list of email domains used to pick the user's AlmaForge username from their verified GitHub emails. The domains are evaluated in order. The first verified email whose domain matches any listed domain wins. If empty, the primary verified email is used.
  • api_endpoint_url (String) APIEndpointURL is the URL of the API endpoint of the GitHub instance this connector is for. Defaults to https://api.github.com when empty.
  • client_id (String) ClientID is the GitHub OAuth app client ID.
  • client_secret (String, Sensitive) ClientSecret is the GitHub OAuth app client secret. Accepts a literal value or a value-expansion reference such as "${file:/etc/github.secret}" or "${env:GITHUB_CLIENT_SECRET}".
  • display (String) Display is the connector display name shown in the login UI.
  • endpoint_url (String) EndpointURL is the URL of the GitHub instance this connector is for. Defaults to https://github.com when empty.
  • teams_to_roles (List of Object) TeamsToRoles maps GitHub team memberships onto allowed roles. (see below for nested schema)

Nested Schema for spec.teams_to_roles​

Read-Only:

  • organization (String)
  • roles (List of String)
  • team (String)