almaforge_oidc_connector Data Source
Read an AlmaForge OIDCConnector resource by name.
This data source reads existing cluster resources. It does not create, change, or delete them. Authenticate using the Terraform setup guide. Your identity needs permission to read the selected resources.
See OIDC SSO for issuer settings and claim-to-role mapping. Secret fields are redacted by the API and returned as null.
See the configuration reference for the resource manifest and field context.
Set name to the existing object's metadata.name. The result is available in metadata and spec. A missing object produces an error.
Example Usage
Save this configuration in a new directory. Replace the example name with the existing object you want to read. Review the plan before applying it. Applying this data-only configuration saves the outputs without changing cluster resources.
terraform initterraform plan -out=plan.tfplanterraform apply plan.tfplanterraform outputterraform {
required_providers {
almaforge = {
source = "get.almaforge.com/almaforge/almaforge"
}
}
}
provider "almaforge" {}
data "almaforge_oidc_connector" "existing" {
name = "engineering"
}
output "name" {
value = data.almaforge_oidc_connector.existing.metadata.name
}
To manage changes instead of only reading, use the resource. Read resources versus data sources before choosing ownership.
Schema
Required
name(String) Name of the resource to read.
Read-Only
metadata(Attributes) (see below for nested schema)spec(Attributes) Spec contains the resource configuration. (see below for nested schema)
Nested Schema for metadata
Read-Only:
labels(Map of String) Labels attached to the resource.name(String) Resource name. Changing this name replaces the resource.resource_version(String) Server revision used to detect concurrent changes.
Nested Schema for spec
Read-Only:
acr_values(String) ACR is the Authentication Context Class Reference value.allow_unverified_email(Boolean) AllowUnverifiedEmail tells the connector to accept OIDC users with unverified emails.claims_to_roles(List of Object) ClaimsToRoles specifies dynamic mapping from OIDC claims to AlmaForge roles. (see below for nested schema)client_id(String) ClientID is the OIDC app client ID.client_secret(String, Sensitive) ClientSecret is the OIDC app client secret. Accepts a literal value or a value-expansion reference such as "${file:/etc/oidc.secret}" or "${env:OIDC_CLIENT_SECRET}".display(String) Display is the connector display name shown in the login UI.google_admin_email(String) GoogleAdminEmail is the email of a Google admin to impersonate for group lookups.google_service_account(String, Sensitive) GoogleServiceAccount is the Google service account JSON (for Google Workspace). Accepts a literal JSON value or a ${env:NAME} / ${file:PATH} reference.issuer_url(String) IssuerURL is the endpoint of the provider, e.g. https://accounts.google.com.max_age(String) MaxAge is how recently the identity provider must have authenticated a user for a login to be accepted. The login request carries it to the provider, which is expected to re-authenticate anyone whose session is older, and the response is refused unless it reports an authentication time inside the window. It does not bound the lifetime of the session that the login produces. Written as a duration, for example "12h" or "30m". Zero means no requirement.pkce_mode(String) PKCEMode controls PKCE (Proof Key for Code Exchange) usage. Valid values: "auto" (default), "enabled", "disabled".prompt(String) Prompt is the OIDC "prompt" parameter sent on the authorization request. Valid values per OIDC Core 1.0 §3.1.2.1: "none", "login", "consent", "select_account". Space-separated combinations are allowed (e.g. "login consent"). When left empty it defaults to "select_account", which makes the identity provider show its account picker instead of silently reusing an existing session.provider(String) Provider is the external identity provider name.scope(List of String) Scope specifies additional OAuth2 scopes to request from the provider.username_claim(String) UsernameClaim specifies the name of the claim to use as the user's AlmaForge username.
Nested Schema for spec.claims_to_roles
Read-Only:
claim(String)roles(List of String)value(String)