Overview
This example shows how to deploy Airbyte on Qovery using Terraform. Airbyte is deployed from its official Helm chart, with a PostgreSQL database and a proxy that protects the Airbyte web app with basic authentication.This page is based on qovery-airbyte, an external example repository. The proxy application of this page builds from that repository.
What You’ll Deploy
- PostgreSQL Database: Managed database for Airbyte metadata
- Airbyte (Helm): Airbyte deployed from the official Helm chart
- Proxy Application: Reverse proxy with basic authentication in front of the Airbyte web app
- Deployment Stages: Ordered deployment (Database → App → Proxy)
Prerequisites
Before deploying, gather these values:- A Qovery API token and the IDs of your organization, project and cluster. See Find resource IDs.
- A cluster on AWS. The database uses
db.t3.small, an AWS RDS instance type. On another cloud provider, set an instance type that the provider offers. - Basic authentication credentials for the proxy: one htpasswd entry with a SHA-1 password,
username:{SHA}.... The Gateway API expects this format, and NGINX accepts it too, so the credentials work whichever of the two routes the traffic.
File Structure
variables.tf
variables.tf
main.tf
main.tf
airbyte-values.yaml
Create aairbyte-values.yaml file to customize Airbyte configuration. Qovery replaces each qovery.env.<NAME> with the value of the <NAME> variable of the Helm service when it deploys the chart, as described in Environment Variables in Values.
Deployment Steps
1
Clone or Create Files
2
Set Environment Variables
3
Set Basic Authentication
4
Initialize Terraform
5
Plan and Apply
terraform apply waits for the deployment of the three stages.6
Access Airbyte
Open the URL of the proxy and log in with your basic authentication credentials:You can also forward a local port to the proxy. When prompted, select the Port forwarding connects to the proxy directly, without the basic authentication of the public endpoint.
airbyte-webapp-proxy service:Cleanup
Key Takeaways
This example demonstrates several advanced Terraform patterns:Multi-Service Deployment
Multi-Service Deployment
Deploying multiple interconnected services:
- Managed PostgreSQL database
- Helm chart application
- Proxy application for authentication
Deployment Stages
Deployment Stages
Ensuring proper deployment order with
qovery_deployment_stage resources and the deployment_stage_id of each service:- DATABASE: PostgreSQL deploys first
- APP: Airbyte Helm chart deploys after database
- PROXY: Authentication proxy deploys last
Dynamic Configuration
Dynamic Configuration
Using Qovery’s database connection details in Helm values:
- Aliases of the database’s built-in variables on the Helm service
- Variables referenced as
qovery.env.<NAME>inairbyte-values.yaml - The internal host of the Helm release injected in the proxy with
{{...}}interpolation
External Helm Charts
External Helm Charts
Integrating third-party Helm repositories:
- Adding Airbyte’s official Helm repository
- Deploying specific chart versions
- Overriding values with custom configuration
Security
Security
- Basic authentication on the public endpoint of the proxy
- Private database accessibility
- Database password passed as a secret alias, never written in the configuration
Health Checks
Health Checks
Liveness and readiness probes on the proxy:
- Initial delay to allow services to start
- Regular health checks
- Automatic restarts on failure
Resource Management
Resource Management
Setting CPU and memory for each service:
- Minimal resources for proxy (100 mCPU, 128 MB)
- Managed database with an instance type and defined storage
- Cluster-wide resource permissions for Airbyte
Troubleshooting
Deployment Takes Too Long
Deployment Takes Too Long
Airbyte deployment typically takes several minutes:
- Database must be ready first, and a managed database takes several minutes to create
- Helm chart pulls multiple images
- Airbyte bootloader initializes the database
timeout_sec on qovery_helm (600 seconds by default).Check deployment status:Cannot Access Web UI
Cannot Access Web UI
If you can’t access the Airbyte UI:
- Verify all services are deployed
- Check proxy application is running
- Ensure basic auth credentials are correct
- Try port-forwarding locally
Database Connection Issues
Database Connection Issues
If Airbyte can’t connect to the database:
- Verify database is in RUNNING state
- Check the aliases of the Helm service point to the variables of the database
- Review
airbyte-values.yamlconfiguration - Check Airbyte logs for connection errors
Next Steps
Example Repository
External example repository this page is based on
Airbyte Documentation
Learn more about Airbyte
Helm Configuration
Deploy more Helm charts
Advanced Patterns
Learn advanced Terraform techniques