Menu
Platform
AI
App store purchases
Database
Flags
Jobs and cron
Localization
Monitoring
Notifications
Payments
Queues
Sandboxes
Webhooks
Getting Started
Authentication
KV Store
Deploy & Infrastructure
Reference
Terraform
The platform's declarative resources in a `.tf` file, from the same contracts as the API.
The Sylphx Terraform provider manages the platform's declarative resources:
every Resource type with a declarative spec — the SPEC_STATUS shape, marked
terraform: true — is a resource and a data source over the one API, from the
same contracts as the API reference and the CLI. The
provider is clients/terraform in the repository, and it registers as
sylphxai/sylphx — the Registry namespace is the repository's GitHub owner.
40 types are managed; Types lists them.
#Configure
terraform {
required_providers {
sylphx = {
source = "sylphxai/sylphx"
}
}
}
provider "sylphx" {
# api_key defaults to SYLPHX_API_KEY; base_url to SYLPHX_BASE_URL.
org = "org_…"
project = "prj_…"
env = "env_…"
}org, project and env scope every call to one environment, and they are
where a resource's parent comes from when it is left out. api_key falls
back to SYLPHX_API_KEY and base_url to SYLPHX_BASE_URL, so a CI run needs
no key in the configuration.
#A resource
access.sylphx.com/ApiKey — the API keys collection — as a block:
resource "sylphx_access_api_key" "api_key" {
parent = "orgs/acme/projects/shop/envs/production"
spec = { kind = "secret", scopes = ["…"] }
}A Create method is a resource block; its Get is the matching data
block, which reads a resource the configuration does not manage. Every method
page carries the same block under Terraform, with that call's example
values.
#Mapping
| Schema | Terraform |
|---|---|
Resource {service}.sylphx.com/{Kind} (terraform: true, SPEC_STATUS) | resource and data source sylphx_{service}_{kind} |
spec fields | the spec object: REQUIRED fields are required, the rest optional and computed (the API fills defaults; an unset value keeps its prior state) |
status, uid, meta.etag, meta.generation, times | computed |
meta.labels, meta.annotations, meta.display_name | labels, annotations, display_name |
IMMUTABLE (or no Update method) | forces replacement |
sensitive | Sensitive; INPUT_ONLY values are write-only and keep their configured value in state |
name | id, name, and the import id |
| parent, caller-chosen id | parent (default from the provider's org/project/env) and <kind>_id; both force replacement |
| reconciled types | every mutation waits on its Operation within timeouts (default 20m) |
#CRUD
Create sends the caller-chosen id; Read uses Get, and NOT_FOUND removes the
resource from state; Update sends a PATCH with an explicit update_mask from
the plan diff and the last-read etag as If-Match; Delete sends the etag, and
the API enforces deletion_protection. plan runs each create and update with
validate_only, so server-side validation fails at plan time. Errors carry the
API's code, detail and request id.
#Import
A resource's import id is its name, so an existing one comes under management with its full path:
terraform import sylphx_access_api_key.api_key "orgs/acme/projects/shop/envs/production/api_keys/api-key"terraform import writes state only; add the block the same values describe,
and plan says whether the two agree.
#Types
Every managed type and the Resource type it maps; the Resource type links to the collection, whose page carries what the resource is and its fields: