https://github.com/inferadb/terraform-provider-inferadb
InferaDB Terraform provider — manage orgs, vaults, clients, teams
https://github.com/inferadb/terraform-provider-inferadb
access-control authorization fine-grained-access-control grpc inferadb jwt permissions provider rebac rest-api terraform zanzibar
Last synced: 6 months ago
JSON representation
InferaDB Terraform provider — manage orgs, vaults, clients, teams
- Host: GitHub
- URL: https://github.com/inferadb/terraform-provider-inferadb
- Owner: inferadb
- License: apache-2.0
- Created: 2025-11-15T06:37:59.000Z (8 months ago)
- Default Branch: main
- Last Pushed: 2026-01-19T22:19:01.000Z (6 months ago)
- Last Synced: 2026-01-20T05:31:57.345Z (6 months ago)
- Topics: access-control, authorization, fine-grained-access-control, grpc, inferadb, jwt, permissions, provider, rebac, rest-api, terraform, zanzibar
- Language: Go
- Homepage: https://inferadb.com
- Size: 131 KB
- Stars: 1
- Watchers: 0
- Forks: 0
- Open Issues: 1
-
Metadata Files:
- Readme: README.md
- License: LICENSE
- Codeowners: .github/CODEOWNERS
Awesome Lists containing this project
README
InferaDB Terraform Provider
Manage InferaDB organizations, vaults, clients, teams, and access grants
> [!IMPORTANT]
> Under active development. Not production-ready.
## Requirements
- [Terraform](https://developer.hashicorp.com/terraform/downloads) >= 1.0
- [Go](https://golang.org/doc/install) >= 1.23 (to build from source)
## Installation
### From Source
```bash
git clone https://github.com/inferadb/terraform-provider-inferadb.git
cd terraform-provider-inferadb
go build -v ./...
go install -v ./...
```
## Usage
```hcl
terraform {
required_providers {
inferadb = {
source = "inferadb/inferadb"
}
}
}
provider "inferadb" {
endpoint = "https://api.inferadb.com"
session_token = var.inferadb_session_token
}
# Create an organization
resource "inferadb_organization" "example" {
name = "My Organization"
tier = "dev"
}
# Create a vault
resource "inferadb_vault" "production" {
organization_id = inferadb_organization.example.id
name = "Production Policies"
description = "Authorization policies for production"
}
# Create a client (backend service identity)
resource "inferadb_client" "api" {
organization_id = inferadb_organization.example.id
vault_id = inferadb_vault.production.id
name = "API Server"
}
# Generate a certificate for the client
resource "inferadb_client_certificate" "api_cert" {
organization_id = inferadb_organization.example.id
client_id = inferadb_client.api.id
name = "API Certificate 2025"
}
# Output the private key (only available on creation!)
output "api_private_key" {
value = inferadb_client_certificate.api_cert.private_key_pem
sensitive = true
}
```
## Authentication
The provider requires a session token. Provide it via:
1. Provider configuration: `session_token = "..."`
2. Environment variable: `INFERADB_SESSION_TOKEN`
To obtain a session token, log in via the InferaDB CLI:
```bash
inferadb login
```
## Resources
| Resource | Description |
| ----------------------------- | ----------------------------------------------- |
| `inferadb_organization` | Manages organizations |
| `inferadb_vault` | Manages vaults for authorization policies |
| `inferadb_client` | Manages client identities for backend services |
| `inferadb_client_certificate` | Generates client authentication certificates |
| `inferadb_team` | Manages teams for group access control |
| `inferadb_team_member` | Manages team memberships |
| `inferadb_vault_user_grant` | Grants users vault access |
| `inferadb_vault_team_grant` | Grants teams vault access |
## Data Sources
| Data Source | Description |
| ----------------------- | ------------------------ |
| `inferadb_organization` | Reads organization data |
| `inferadb_vault` | Reads vault data |
| `inferadb_client` | Reads client data |
| `inferadb_team` | Reads team data |
## Development
```bash
# Build
go build -v ./...
# Run tests
go test -v -cover -timeout=120s -parallel=4 ./...
# Run acceptance tests (requires TF_ACC=1 and API credentials)
TF_ACC=1 go test -v -cover -timeout 120m ./...
# Generate documentation
go run github.com/hashicorp/terraform-plugin-docs/cmd/tfplugindocs
# Format code
gofmt -s -w -e .
# Run linter
golangci-lint run
```
## Related Resources
- [InferaDB Documentation](https://inferadb.com/docs)
- [Control API OpenAPI Spec](../control/openapi.yaml)
- [Engine Terraform Modules](../engine/terraform/)
## Community
Join us on [Discord](https://discord.gg/inferadb) for questions, discussions, and contributions.
## License
Dual-licensed under [MIT](LICENSE-MIT) or [Apache 2.0](LICENSE-APACHE).
