Skip to main content
The Terraform exporter generates the Terraform configuration of an environment set up from the Console. After you import the exported resources into a Terraform state, Terraform manages the environment.
Change the provider version of the export. Until the exporter is updated for provider 1.0, the exported main.tf pins the provider below 1.0 (version = ">= 0.87.0, < 1.0.0"). Change the constraint to version = "~> 1.0" before you run terraform init.On a cluster that uses Karpenter, the export also sets features.karpenter.spot_enabled, which provider 1.0 removed. Delete it and set spot_enabled on each node pool, as described in the 1.0 upgrade guide.

What gets exported

The export contains a resource block for each of these:
  • The organization (qovery_organization), and all of its container registries, Helm repositories, labels groups and annotations groups.
  • The cluster of the environment (qovery_cluster) and its cloud credentials (qovery_aws_credentials, qovery_gcp_credentials, qovery_scaleway_credentials or qovery_eks_anywhere_vsphere_credentials).
  • The git tokens that the applications, jobs and Terraform services of the environment use (qovery_git_token).
  • The project, the environment and its deployment stages.
  • The services of the environment: applications, containers, jobs, Helm charts, Terraform services and databases, with their variables and secrets.
The export does not contain Azure credentials or a qovery_deployment resource.

Export an environment

1

Open the export

In the Console, open the environment, click the Other actions menu (three dots) and select Export as Terraform. Only organization admins can export an environment.
2

Choose whether to include secrets

Turn on Export secrets to include the secret values in the export.
Exported secret values are written in plain text in variables.tf. Do not commit them to version control.
3

Download

Click Export. The download is a zip file with two files:
  • main.tf: the provider configuration and the resources.
  • variables.tf: the input variables. qovery_access_token holds the API token of the provider. The other variables hold the secrets of the project, the environment and the services, the cloud credentials, the registry and Helm repository credentials, and the git tokens. With Export secrets on, each of them defaults to its value. Otherwise they have no default, and you set them yourself.

Import the exported resources

1

Set the provider version

In main.tf, set the provider version to "~> 1.0", as described at the top of this page.
2

Set the input variables

The provider reads its token from the qovery_access_token variable:
Set the variables that have no default the same way, or in a terraform.tfvars file that you keep out of version control.
3

Initialize

4

Add an import block for every resource

In a new file, such as imports.tf, add an import block for every resource of main.tf. Each resource is named after its kind, followed by z and the first eight characters of its ID. For example, the environment a1b2c3d4-… is qovery_environment.environment_za1b2c3d4.
imports.tf
The import ID is the resource ID for the organization, the project, the environment, the services, and the labels and annotations groups. It is <organization_id>,<resource_id> for the cloud credentials, the cluster, the container registries, the Helm repositories and the git tokens, and <environment_id>,<stage_name> for the deployment stages. The Registry page of each resource gives its format.
5

Review the plan

The plan lists every import. The Qovery API never returns secret values, so the plan also updates each secret once with the value of its variable. Apart from that, a complete import plans no change. Review any other change before you apply it: it is a difference between the exported configuration and Qovery.
6

Apply

Terraform records the imported resources in its state. You can then remove the import blocks.

After the import

Terraform now manages the exported resources: change them in the configuration, not in the Console. A change made from the Console shows up in the next terraform plan, and the next terraform apply reverts it. Secret values are the exception: the API never returns them, so a secret changed from the Console does not show up in the plan. See How the provider tracks changes. The export only describes the resources. To deploy the environment on terraform apply, add a qovery_deployment resource, as in the basic application example. Destroying that resource, or removing it from the configuration, deletes the environment and its services. Store the state in a remote backend so that your team shares it.

Next steps

Terraform Provider

Set up the provider

Basic Application

Deploy an environment with qovery_deployment

Terraform Registry

Reference of every resource and its import ID

Environment Variables

Variables and secrets