Skip to main content

Overview

This example shows how to deploy Airbyte on Qovery using Terraform. Airbyte is deployed from its official Helm chart, with a PostgreSQL database and a proxy that protects the Airbyte web app with basic authentication.
This page is based on qovery-airbyte, an external example repository. The proxy application of this page builds from that repository.

What You’ll Deploy

  • PostgreSQL Database: Managed database for Airbyte metadata
  • Airbyte (Helm): Airbyte deployed from the official Helm chart
  • Proxy Application: Reverse proxy with basic authentication in front of the Airbyte web app
  • Deployment Stages: Ordered deployment (Database → App → Proxy)

Prerequisites

Before deploying, gather these values:
  • A Qovery API token and the IDs of your organization, project and cluster. See Find resource IDs.
  • A cluster on AWS. The database uses db.t3.small, an AWS RDS instance type. On another cloud provider, set an instance type that the provider offers.
  • Basic authentication credentials for the proxy: one htpasswd entry with a SHA-1 password, username:{SHA}.... The Gateway API expects this format, and NGINX accepts it too, so the credentials work whichever of the two routes the traffic.

File Structure

variables.tf

variables.tf

main.tf

main.tf

airbyte-values.yaml

Create a airbyte-values.yaml file to customize Airbyte configuration. Qovery replaces each qovery.env.<NAME> with the value of the <NAME> variable of the Helm service when it deploys the chart, as described in Environment Variables in Values.

Deployment Steps

1

Clone or Create Files

The files of the repository can differ from the ones on this page.
2

Set Environment Variables

3

Set Basic Authentication

4

Initialize Terraform

5

Plan and Apply

terraform apply waits for the deployment of the three stages.
6

Access Airbyte

Open the URL of the proxy and log in with your basic authentication credentials:
You can also forward a local port to the proxy. When prompted, select the airbyte-webapp-proxy service:
Port forwarding connects to the proxy directly, without the basic authentication of the public endpoint.

Cleanup

Key Takeaways

This example demonstrates several advanced Terraform patterns:
Deploying multiple interconnected services:
  • Managed PostgreSQL database
  • Helm chart application
  • Proxy application for authentication
Ensuring proper deployment order with qovery_deployment_stage resources and the deployment_stage_id of each service:
  1. DATABASE: PostgreSQL deploys first
  2. APP: Airbyte Helm chart deploys after database
  3. PROXY: Authentication proxy deploys last
Using Qovery’s database connection details in Helm values:
  • Aliases of the database’s built-in variables on the Helm service
  • Variables referenced as qovery.env.<NAME> in airbyte-values.yaml
  • The internal host of the Helm release injected in the proxy with {{...}} interpolation
Integrating third-party Helm repositories:
  • Adding Airbyte’s official Helm repository
  • Deploying specific chart versions
  • Overriding values with custom configuration
  • Basic authentication on the public endpoint of the proxy
  • Private database accessibility
  • Database password passed as a secret alias, never written in the configuration
Liveness and readiness probes on the proxy:
  • Initial delay to allow services to start
  • Regular health checks
  • Automatic restarts on failure
Setting CPU and memory for each service:
  • Minimal resources for proxy (100 mCPU, 128 MB)
  • Managed database with an instance type and defined storage
  • Cluster-wide resource permissions for Airbyte

Troubleshooting

Airbyte deployment typically takes several minutes:
  • Database must be ready first, and a managed database takes several minutes to create
  • Helm chart pulls multiple images
  • Airbyte bootloader initializes the database
If the Helm deployment times out, increase timeout_sec on qovery_helm (600 seconds by default).Check deployment status:
If you can’t access the Airbyte UI:
  1. Verify all services are deployed
  2. Check proxy application is running
  3. Ensure basic auth credentials are correct
  4. Try port-forwarding locally
If Airbyte can’t connect to the database:
  • Verify database is in RUNNING state
  • Check the aliases of the Helm service point to the variables of the database
  • Review airbyte-values.yaml configuration
  • Check Airbyte logs for connection errors

Next Steps

Example Repository

External example repository this page is based on

Airbyte Documentation

Learn more about Airbyte

Helm Configuration

Deploy more Helm charts

Advanced Patterns

Learn advanced Terraform techniques