Skip to main content

almaforge_lock Resource

Manage an AlmaForge Lock resource.

Before you start​

Use the Terraform setup guide to install the provider and sign in. Your identity needs permission to manage this resource. Keep one owner for each resource name, following the ownership rules.

A lock blocks its target across the cluster. Choose a target from the revocation guide. Locking your own user or role can also block your next Terraform operation. Keep a separate, authorized recovery identity available.

Set expires_at to a fixed future RFC 3339 timestamp when enforcement should end automatically. Omitting it creates a lock with no expiry. Do not derive it from timestamp(), which would move the expiry on subsequent applies.

Example Usage​

Download main.tf into its own directory. Replace example values with your cluster and integration settings. Use the plan and apply workflow after preparing the prerequisites above.

HCL
# Block a user's access until a fixed time. Expiry does not delete the lock.
terraform {
required_providers {
almaforge = {
source = "get.almaforge.com/almaforge/almaforge"
}
}
}

provider "almaforge" {}

resource "almaforge_lock" "maintenance" {
metadata = {
name = "maintenance"
}
spec = {
target = {
user = "[email protected]"
}
message = "Maintenance window"
# Replace with the actual end of your maintenance window before applying.
expires_at = "2030-01-01T00:00:00Z"
}
}

See the configuration reference for the resource manifest and field context.

Changes and deletion​

Configuration is authoritative. Removing an optional attribute resets its API default or clears it when no default exists. Changing metadata.name replaces the resource. Review the plan before applying. See lifecycle behavior.

Expiry ends enforcement but leaves the lock readable. Terraform does not renew or recreate an expired lock. The server fills created_at and created_by. To unblock the target earlier, remove the lock resource from configuration and apply the reviewed deletion.

To read an existing object without managing it, use the named data source.

Schema​

Required​

Optional​

Nested Schema for metadata​

Required:

  • name (String) Resource name. Changing this name replaces the resource.

Optional:

  • labels (Map of String) Labels attached to the resource.

Read-Only:

  • resource_version (String) Server revision used to detect concurrent changes.

Nested Schema for spec​

Optional:

  • expires_at (String) ExpiresAt, if set, specifies when the lock ceases to be in force. Zero value (IsZero) means the lock has no expiry. Distinct from ObjectMeta lifecycle. The lock resource itself is not deleted when ExpiresAt elapses.
  • message (String) Message is the message displayed to locked-out users.
  • target (Attributes) Target describes the set of interactions that the lock applies to. (see below for nested schema)

Read-Only:

  • created_at (String) CreatedAt is the time the lock was created.
  • created_by (String) CreatedBy is the username of the lock author.

Nested Schema for spec.target​

Optional:

  • access_request (String) AccessRequest is the UUID of an access request.
  • login (String) Login is the name of a local UNIX user.
  • role (String) Role is the name of an RBAC role known to the cluster.
  • server_id (String) ServerID is the host ID of the AlmaForge instance.
  • user (String) User is the name of an AlmaForge user.

Import​

Create the matching resource block first, then import the existing object's metadata.name. With the example above, the Terraform address and server name are:

Terminal
terraform import almaforge_lock.maintenance maintenanceterraform plan

Use the address from your configuration and the name of the existing object. Import records the object in Terraform state. Review the first plan carefully because omitted fields will reset or clear on apply. The import guide also covers generating configuration from an existing object.