almaforge_telegram_connector Resource
Manage an AlmaForge TelegramConnector resource.
Before you start
Use the Terraform setup guide to install the provider and sign in. Your identity needs permission to manage this resource. Keep one owner for each resource name, following the ownership rules.
Create a Telegram bot and obtain the destination chat ID using the Telegram integration guide. Keep a group's leading minus sign in its chat ID. Use the exact resource name telegram, which the built-in integration reads.
The "*" entry in role_to_recipients is required. Its values field contains chat IDs as strings. Telegram receives notifications. Users still approve or deny requests in AlmaForge. Configure those permissions through the access-request guide.
Example Usage
Download main.tf into its own directory. Replace example values with your cluster and integration settings. Use the plan and apply workflow after preparing the prerequisites above.
Supply sensitive inputs from your secret manager or protected TF_VAR_ environment variables. Sensitive values are hidden in normal plan output but remain in saved plans and state. See connector secrets.
# Send access-request notifications to a Telegram chat. Reviews stay in AlmaForge.
terraform {
required_providers {
almaforge = {
source = "get.almaforge.com/almaforge/almaforge"
}
}
}
provider "almaforge" {}
variable "bot_token" {
type = string
description = "Telegram bot token. Supply through TF_VAR_bot_token."
sensitive = true
}
resource "almaforge_telegram_connector" "telegram" {
metadata = {
name = "telegram"
}
spec = {
bot_token = var.bot_token
role_to_recipients = {
"*" = {
values = ["-1001234567890"]
}
}
}
}
See the configuration reference for the resource manifest and field context.
Changes and deletion
Configuration is authoritative. Removing an optional attribute resets its API default or clears it when no default exists. Changing metadata.name replaces the resource. Review the plan before applying. See lifecycle behavior.
Destroy deletes the connector. Check the linked integration guide's operations and removal sections before removing a connector that users or approval workflows depend on.
To read an existing object without managing it, use the named data source.
Schema
Required
metadata(Attributes) (see below for nested schema)
Optional
spec(Attributes) Spec contains the resource configuration. (see below for nested schema)
Nested Schema for metadata
Required:
name(String) Resource name. Changing this name replaces the resource.
Optional:
labels(Map of String) Labels attached to the resource.
Read-Only:
resource_version(String) Server revision used to detect concurrent changes.
Nested Schema for spec
Optional:
api_url(String) APIURL overrides the Telegram Bot API base URL. Defaults to https://api.telegram.org when empty.bot_token(String, Sensitive) BotToken is the Telegram bot token from BotFather. Accepts a literal value or a value-expansion reference such as "${file:/etc/telegram/token}" or "${env:TELEGRAM_BOT_TOKEN}".role_to_recipients(Map of Object) RoleToRecipients maps requested roles to Telegram chat identifiers. Values are numeric chat_id strings (for private chats, groups, or channels) or @channelusername for public channels. The "*" key is the required default recipient list. (see below for nested schema)
Nested Schema for spec.role_to_recipients
Optional:
values(List of String)
Import
Create the matching resource block first, then import the existing object's metadata.name. With the example above, the Terraform address and server name are:
terraform import almaforge_telegram_connector.telegram telegramterraform planUse the address from your configuration and the name of the existing object. Import records the object in Terraform state. Review the first plan carefully because omitted fields will reset or clear on apply. The import guide also covers generating configuration from an existing object.
Supply the connector's current secret values before applying. The API redacts credentials on reads, so import cannot recover them. Configured secrets are preserved during subsequent refreshes.