Skip to content
Console
Menu

Queues

Workflows

Getting Started

Authentication

KV Store

Terraform

The platform's declarative resources in a `.tf` file, from the same contracts as the API.

The Sylphx Terraform provider manages the platform's declarative resources: every Resource type with a declarative spec — the SPEC_STATUS shape, marked terraform: true — is a resource and a data source over the one API, from the same contracts as the API reference and the CLI. The provider is clients/terraform in the repository, and it registers as sylphxai/sylphx — the Registry namespace is the repository's GitHub owner. 40 types are managed; Types lists them.

#Configure

Terraform
terraform {
  required_providers {
    sylphx = {
      source = "sylphxai/sylphx"
    }
  }
}

provider "sylphx" {
  # api_key defaults to SYLPHX_API_KEY; base_url to SYLPHX_BASE_URL.
  org     = "org_…"
  project = "prj_…"
  env     = "env_…"
}

org, project and env scope every call to one environment, and they are where a resource's parent comes from when it is left out. api_key falls back to SYLPHX_API_KEY and base_url to SYLPHX_BASE_URL, so a CI run needs no key in the configuration.

#A resource

access.sylphx.com/ApiKey — the API keys collection — as a block:

Terraform
resource "sylphx_access_api_key" "api_key" {
  parent = "orgs/acme/projects/shop/envs/production"
  spec   = { kind = "secret", scopes = ["…"] }
}

A Create method is a resource block; its Get is the matching data block, which reads a resource the configuration does not manage. Every method page carries the same block under Terraform, with that call's example values.

#Mapping

SchemaTerraform
Resource {service}.sylphx.com/{Kind} (terraform: true, SPEC_STATUS)resource and data source sylphx_{service}_{kind}
spec fieldsthe spec object: REQUIRED fields are required, the rest optional and computed (the API fills defaults; an unset value keeps its prior state)
status, uid, meta.etag, meta.generation, timescomputed
meta.labels, meta.annotations, meta.display_namelabels, annotations, display_name
IMMUTABLE (or no Update method)forces replacement
sensitiveSensitive; INPUT_ONLY values are write-only and keep their configured value in state
nameid, name, and the import id
parent, caller-chosen idparent (default from the provider's org/project/env) and <kind>_id; both force replacement
reconciled typesevery mutation waits on its Operation within timeouts (default 20m)

#CRUD

Create sends the caller-chosen id; Read uses Get, and NOT_FOUND removes the resource from state; Update sends a PATCH with an explicit update_mask from the plan diff and the last-read etag as If-Match; Delete sends the etag, and the API enforces deletion_protection. plan runs each create and update with validate_only, so server-side validation fails at plan time. Errors carry the API's code, detail and request id.

#Import

A resource's import id is its name, so an existing one comes under management with its full path:

Shell
terraform import sylphx_access_api_key.api_key "orgs/acme/projects/shop/envs/production/api_keys/api-key"

terraform import writes state only; add the block the same values describe, and plan says whether the two agree.

#Types

Every managed type and the Resource type it maps; the Resource type links to the collection, whose page carries what the resource is and its fields:

TypeResource type
sylphx_access_api_keyaccess.sylphx.com/ApiKey
sylphx_access_environmentaccess.sylphx.com/Environment
sylphx_access_orgaccess.sylphx.com/Org
sylphx_access_projectaccess.sylphx.com/Project
sylphx_auth_oauth_clientauth.sylphx.com/OauthClient
sylphx_billing_billing_accountbilling.sylphx.com/BillingAccount
sylphx_broker_trust_policybroker.sylphx.com/TrustPolicy
sylphx_config_config_flagconfig.sylphx.com/ConfigFlag
sylphx_config_config_segmentconfig.sylphx.com/ConfigSegment
sylphx_connections_connectionconnections.sylphx.com/Connection
sylphx_connections_connection_providerconnections.sylphx.com/ConnectionProvider
sylphx_data_bucketdata.sylphx.com/Bucket
sylphx_data_databasedata.sylphx.com/Database
sylphx_data_kv_namespacedata.sylphx.com/KvNamespace
sylphx_data_search_indexdata.sylphx.com/SearchIndex
sylphx_events_inbound_endpointevents.sylphx.com/InboundEndpoint
sylphx_events_queueevents.sylphx.com/Queue
sylphx_events_realtime_channelevents.sylphx.com/RealtimeChannel
sylphx_events_subscriptionevents.sylphx.com/Subscription
sylphx_events_topicevents.sylphx.com/Topic
sylphx_events_webhook_endpointevents.sylphx.com/WebhookEndpoint
sylphx_hosting_previewhosting.sylphx.com/Preview
sylphx_hosting_servicehosting.sylphx.com/Service
sylphx_hosting_source_linkhosting.sylphx.com/SourceLink
sylphx_keys_keykeys.sylphx.com/Key
sylphx_network_domainnetwork.sylphx.com/Domain
sylphx_network_egress_identitynetwork.sylphx.com/EgressIdentity
sylphx_network_private_linknetwork.sylphx.com/PrivateLink
sylphx_network_routenetwork.sylphx.com/Route
sylphx_notify_email_domainnotify.sylphx.com/EmailDomain
sylphx_notify_sendernotify.sylphx.com/Sender
sylphx_release_releaserelease.sylphx.com/Release
sylphx_runners_scale_setrunners.sylphx.com/ScaleSet
sylphx_sandboxes_poolsandboxes.sylphx.com/Pool
sylphx_secrets_secretsecrets.sylphx.com/Secret
sylphx_secrets_secret_bindingsecrets.sylphx.com/SecretBinding
sylphx_workflows_distributed_jobworkflows.sylphx.com/DistributedJob
sylphx_workflows_jobworkflows.sylphx.com/Job
sylphx_workflows_scheduleworkflows.sylphx.com/Schedule
sylphx_workflows_workflowworkflows.sylphx.com/Workflow