almaforge_pagerduty_connector Resource
Manage an AlmaForge PagerdutyConnector resource.
Before you start
Use the Terraform setup guide to install the provider and sign in. Your identity needs permission to manage this resource. Keep one owner for each resource name, following the ownership rules.
Create a PagerDuty REST API key, not a service integration key, and choose the bot user's email address. Follow the PagerDuty integration guide to prepare services and on-call approval rules. Use the exact resource name pagerduty, which the built-in integration reads.
The default API URL is https://api.pagerduty.com. For a PagerDuty EU account, set api_url = "https://api.eu.pagerduty.com". On-call matching uses the AlmaForge user's login email. Creating the connector alone does not define which roles can be requested or automatically approved.
Example Usage
Download main.tf into its own directory. Replace example values with your cluster and integration settings. Use the plan and apply workflow after preparing the prerequisites above.
Supply sensitive inputs from your secret manager or protected TF_VAR_ environment variables. Sensitive values are hidden in normal plan output but remain in saved plans and state. See connector secrets.
# Connect PagerDuty for access-request incidents and on-call approval rules.
terraform {
required_providers {
almaforge = {
source = "get.almaforge.com/almaforge/almaforge"
}
}
}
provider "almaforge" {}
variable "api_key" {
type = string
description = "PagerDuty REST API key. Supply through TF_VAR_api_key."
sensitive = true
}
resource "almaforge_pagerduty_connector" "pagerduty" {
metadata = {
name = "pagerduty"
}
spec = {
api_key = var.api_key
user_email = "[email protected]"
}
}
See the configuration reference for the resource manifest and field context.
Changes and deletion
Configuration is authoritative. Removing an optional attribute resets its API default or clears it when no default exists. Changing metadata.name replaces the resource. Review the plan before applying. See lifecycle behavior.
Destroy deletes the connector. Check the linked integration guide's operations and removal sections before removing a connector that users or approval workflows depend on.
To read an existing object without managing it, use the named data source.
Schema
Required
metadata(Attributes) (see below for nested schema)
Optional
spec(Attributes) Spec contains the resource configuration. (see below for nested schema)
Nested Schema for metadata
Required:
name(String) Resource name. Changing this name replaces the resource.
Optional:
labels(Map of String) Labels attached to the resource.
Read-Only:
resource_version(String) Server revision used to detect concurrent changes.
Nested Schema for spec
Optional:
api_key(String, Sensitive) APIKey is the Pagerduty REST API key. Accepts a literal value or a value-expansion reference such as "${file:/etc/pagerduty/key}" or "${env:PAGERDUTY_API_KEY}".api_url(String) APIURL overrides the Pagerduty REST API base URL. Defaults to https://api.pagerduty.com when empty.approve_on_call(Boolean) ApproveOnCall enables auto-approval of access requests when the requester is currently on call for one of the configured Pagerduty services. Off by default. Opt in by setting true. When false (or unset), the plugin still creates the Pagerduty incident but leaves the access request for human review.user_email(String) UserEmail is the Pagerduty user email the plugin authenticates as for REST API calls (From: header).
Import
Create the matching resource block first, then import the existing object's metadata.name. With the example above, the Terraform address and server name are:
terraform import almaforge_pagerduty_connector.pagerduty pagerdutyterraform planUse the address from your configuration and the name of the existing object. Import records the object in Terraform state. Review the first plan carefully because omitted fields will reset or clear on apply. The import guide also covers generating configuration from an existing object.
Supply the connector's current secret values before applying. The API redacts credentials on reads, so import cannot recover them. Configured secrets are preserved during subsequent refreshes.