---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Terraform"
description: "The Sylphx Terraform provider: configure it, declare a resource, and every managed type."
type: reference
product: platform
summary: "The platform's declarative resources in a `.tf` file, from the same contracts as the API."
updated: 2026-09-28
order: 11
---

The Sylphx Terraform provider manages the platform's declarative resources:
every Resource type with a declarative spec — the SPEC_STATUS shape, marked
`terraform: true` — is a resource and a data source over the one API, from the
same contracts as [the API reference](/docs/api) and the [CLI](/docs/cli). The
provider is `clients/terraform` in the repository, and it registers as
`sylphxai/sylphx` — the Registry namespace is the repository's GitHub owner.
40 types are managed; [Types](#types) lists them.

## Configure

```hcl
terraform {
  required_providers {
    sylphx = {
      source = "sylphxai/sylphx"
    }
  }
}

provider "sylphx" {
  # api_key defaults to SYLPHX_API_KEY; base_url to SYLPHX_BASE_URL.
  org     = "org_…"
  project = "prj_…"
  env     = "env_…"
}
```

`org`, `project` and `env` scope every call to one environment, and they are
where a resource's `parent` comes from when it is left out. `api_key` falls
back to `SYLPHX_API_KEY` and `base_url` to `SYLPHX_BASE_URL`, so a CI run needs
no key in the configuration.

## A resource

`access.sylphx.com/ApiKey` — the [API keys](/docs/api/api_keys) collection — as a block:

```hcl
resource "sylphx_access_api_key" "api_key" {
  parent = "orgs/acme/projects/shop/envs/production"
  spec   = { kind = "secret", scopes = ["…"] }
}
```

A `Create` method is a `resource` block; its `Get` is the matching `data`
block, which reads a resource the configuration does not manage. Every method
page carries the same block under **Terraform**, with that call's example
values.

## Mapping

| Schema | Terraform |
| --- | --- |
| Resource `{service}.sylphx.com/{Kind}` (`terraform: true`, SPEC_STATUS) | resource and data source `sylphx_{service}_{kind}` |
| `spec` fields | the `spec` object: REQUIRED fields are required, the rest optional and computed (the API fills defaults; an unset value keeps its prior state) |
| `status`, `uid`, `meta.etag`, `meta.generation`, times | computed |
| `meta.labels`, `meta.annotations`, `meta.display_name` | `labels`, `annotations`, `display_name` |
| `IMMUTABLE` (or no Update method) | forces replacement |
| `sensitive` | `Sensitive`; `INPUT_ONLY` values are write-only and keep their configured value in state |
| `name` | `id`, `name`, and the import id |
| parent, caller-chosen id | `parent` (default from the provider's `org`/`project`/`env`) and `<kind>_id`; both force replacement |
| reconciled types | every mutation waits on its Operation within `timeouts` (default 20m) |

## CRUD

Create sends the caller-chosen id; Read uses Get, and `NOT_FOUND` removes the
resource from state; Update sends a PATCH with an explicit `update_mask` from
the plan diff and the last-read etag as `If-Match`; Delete sends the etag, and
the API enforces `deletion_protection`. `plan` runs each create and update with
`validate_only`, so server-side validation fails at plan time. Errors carry the
API's `code`, `detail` and request id.

## Import

A resource's import id is its name, so an existing one comes under
management with its full path:

```bash
terraform import sylphx_access_api_key.api_key "orgs/acme/projects/shop/envs/production/api_keys/api-key"
```

`terraform import` writes state only; add the block the same values describe,
and `plan` says whether the two agree.

## Types

Every managed type and the Resource type it maps; the Resource type links
to the collection, whose page carries what the resource is and its fields:

| Type | Resource type |
| --- | --- |
| `sylphx_access_api_key` | [`access.sylphx.com/ApiKey`](/docs/api/api_keys) |
| `sylphx_access_environment` | [`access.sylphx.com/Environment`](/docs/api/envs) |
| `sylphx_access_org` | [`access.sylphx.com/Org`](/docs/api/orgs) |
| `sylphx_access_project` | [`access.sylphx.com/Project`](/docs/api/projects) |
| `sylphx_auth_oauth_client` | [`auth.sylphx.com/OauthClient`](/docs/api/oauth_clients) |
| `sylphx_billing_billing_account` | [`billing.sylphx.com/BillingAccount`](/docs/api/billing_accounts) |
| `sylphx_broker_trust_policy` | [`broker.sylphx.com/TrustPolicy`](/docs/api/trust_policies) |
| `sylphx_config_config_flag` | [`config.sylphx.com/ConfigFlag`](/docs/api/config_flags) |
| `sylphx_config_config_segment` | [`config.sylphx.com/ConfigSegment`](/docs/api/config_segments) |
| `sylphx_connections_connection` | [`connections.sylphx.com/Connection`](/docs/api/connections) |
| `sylphx_connections_connection_provider` | [`connections.sylphx.com/ConnectionProvider`](/docs/api/connection_providers) |
| `sylphx_data_bucket` | [`data.sylphx.com/Bucket`](/docs/api/buckets) |
| `sylphx_data_database` | [`data.sylphx.com/Database`](/docs/api/databases) |
| `sylphx_data_kv_namespace` | [`data.sylphx.com/KvNamespace`](/docs/api/kv_namespaces) |
| `sylphx_data_search_index` | [`data.sylphx.com/SearchIndex`](/docs/api/search_indexes) |
| `sylphx_events_inbound_endpoint` | [`events.sylphx.com/InboundEndpoint`](/docs/api/inbound_endpoints) |
| `sylphx_events_queue` | [`events.sylphx.com/Queue`](/docs/api/queues) |
| `sylphx_events_realtime_channel` | [`events.sylphx.com/RealtimeChannel`](/docs/api/realtime_channels) |
| `sylphx_events_subscription` | [`events.sylphx.com/Subscription`](/docs/api/subscriptions) |
| `sylphx_events_topic` | [`events.sylphx.com/Topic`](/docs/api/topics) |
| `sylphx_events_webhook_endpoint` | [`events.sylphx.com/WebhookEndpoint`](/docs/api/webhook_endpoints) |
| `sylphx_hosting_preview` | [`hosting.sylphx.com/Preview`](/docs/api/previews) |
| `sylphx_hosting_service` | [`hosting.sylphx.com/Service`](/docs/api/services) |
| `sylphx_hosting_source_link` | [`hosting.sylphx.com/SourceLink`](/docs/api/source_links) |
| `sylphx_keys_key` | [`keys.sylphx.com/Key`](/docs/api/keys) |
| `sylphx_network_domain` | [`network.sylphx.com/Domain`](/docs/api/domains) |
| `sylphx_network_egress_identity` | [`network.sylphx.com/EgressIdentity`](/docs/api/egress_identities) |
| `sylphx_network_private_link` | [`network.sylphx.com/PrivateLink`](/docs/api/private_links) |
| `sylphx_network_route` | [`network.sylphx.com/Route`](/docs/api/routes) |
| `sylphx_notify_email_domain` | [`notify.sylphx.com/EmailDomain`](/docs/api/mail_domains) |
| `sylphx_notify_sender` | [`notify.sylphx.com/Sender`](/docs/api/senders) |
| `sylphx_release_release` | [`release.sylphx.com/Release`](/docs/api/releases) |
| `sylphx_runners_scale_set` | [`runners.sylphx.com/ScaleSet`](/docs/api/scale_sets) |
| `sylphx_sandboxes_pool` | [`sandboxes.sylphx.com/Pool`](/docs/api/pools) |
| `sylphx_secrets_secret` | [`secrets.sylphx.com/Secret`](/docs/api/secrets) |
| `sylphx_secrets_secret_binding` | [`secrets.sylphx.com/SecretBinding`](/docs/api/secret_bindings) |
| `sylphx_workflows_distributed_job` | [`workflows.sylphx.com/DistributedJob`](/docs/api/distributed_jobs) |
| `sylphx_workflows_job` | [`workflows.sylphx.com/Job`](/docs/api/jobs) |
| `sylphx_workflows_schedule` | [`workflows.sylphx.com/Schedule`](/docs/api/schedules) |
| `sylphx_workflows_workflow` | [`workflows.sylphx.com/Workflow`](/docs/api/workflows) |
