> ## Documentation Index
> Fetch the complete documentation index at: https://qovery-gdubroeucq-qov-2319.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Terraform Exporter

> Generate the Terraform configuration of an existing environment

The Terraform exporter generates the Terraform configuration of an environment set up from the Console. After you import the exported resources into a Terraform state, Terraform manages the environment.

<Warning>
  **Change the provider version of the export.** Until the exporter is updated for provider 1.0, the exported `main.tf` pins the provider below 1.0 (`version = ">= 0.87.0, < 1.0.0"`). Change the constraint to `version = "~> 1.0"` before you run `terraform init`.

  On a cluster that uses Karpenter, the export also sets `features.karpenter.spot_enabled`, which provider 1.0 removed. Delete it and set `spot_enabled` on each node pool, as described in the [1.0 upgrade guide](https://registry.terraform.io/providers/qovery/qovery/latest/docs/guides/upgrade-to-1.0).
</Warning>

## What gets exported

The export contains a `resource` block for each of these:

* The organization (`qovery_organization`), and all of its container registries, Helm repositories, labels groups and annotations groups.
* The cluster of the environment (`qovery_cluster`) and its cloud credentials (`qovery_aws_credentials`, `qovery_gcp_credentials`, `qovery_scaleway_credentials` or `qovery_eks_anywhere_vsphere_credentials`).
* The git tokens that the applications, jobs and Terraform services of the environment use (`qovery_git_token`).
* The project, the environment and its deployment stages.
* The services of the environment: applications, containers, jobs, Helm charts, Terraform services and databases, with their variables and secrets.

The export does not contain Azure credentials or a `qovery_deployment` resource.

## Export an environment

<Steps>
  <Step title="Open the export">
    In the Console, open the environment, click the **Other actions** menu (three dots) and select **Export as Terraform**. Only organization admins can export an environment.
  </Step>

  <Step title="Choose whether to include secrets">
    Turn on **Export secrets** to include the secret values in the export.

    <Warning>
      Exported secret values are written in plain text in `variables.tf`. Do not commit them to version control.
    </Warning>
  </Step>

  <Step title="Download">
    Click **Export**. The download is a zip file with two files:

    * `main.tf`: the provider configuration and the resources.
    * `variables.tf`: the input variables. `qovery_access_token` holds the API token of the provider. The other variables hold the secrets of the project, the environment and the services, the cloud credentials, the registry and Helm repository credentials, and the git tokens. With **Export secrets** on, each of them defaults to its value. Otherwise they have no default, and you set them yourself.
  </Step>
</Steps>

## Import the exported resources

<Steps>
  <Step title="Set the provider version">
    In `main.tf`, set the provider `version` to `"~> 1.0"`, as described at the top of this page.
  </Step>

  <Step title="Set the input variables">
    The provider reads its token from the `qovery_access_token` variable:

    ```bash theme={null}
    export TF_VAR_qovery_access_token="<your-api-token>"
    ```

    Set the variables that have no default the same way, or in a `terraform.tfvars` file that you keep out of version control.
  </Step>

  <Step title="Initialize">
    ```bash theme={null}
    terraform init
    ```
  </Step>

  <Step title="Add an import block for every resource">
    In a new file, such as `imports.tf`, add an `import` block for every resource of `main.tf`. Each resource is named after its kind, followed by `z` and the first eight characters of its ID. For example, the environment `a1b2c3d4-…` is `qovery_environment.environment_za1b2c3d4`.

    ```hcl imports.tf theme={null}
    import {
      to = qovery_environment.environment_za1b2c3d4
      id = "<environment_id>"
    }

    import {
      to = qovery_cluster.cluster_z5e6f7a8b
      id = "<organization_id>,<cluster_id>"
    }
    ```

    The import ID is the resource ID for the organization, the project, the environment, the services, and the labels and annotations groups. It is `<organization_id>,<resource_id>` for the cloud credentials, the cluster, the container registries, the Helm repositories and the git tokens, and `<environment_id>,<stage_name>` for the deployment stages. The Registry page of each resource gives its format.
  </Step>

  <Step title="Review the plan">
    ```bash theme={null}
    terraform plan
    ```

    The plan lists every import. The Qovery API never returns secret values, so the plan also updates each secret once with the value of its variable. Apart from that, a complete import plans no change. Review any other change before you apply it: it is a difference between the exported configuration and Qovery.
  </Step>

  <Step title="Apply">
    ```bash theme={null}
    terraform apply
    ```

    Terraform records the imported resources in its state. You can then remove the `import` blocks.
  </Step>
</Steps>

## After the import

Terraform now manages the exported resources: change them in the configuration, not in the Console. A change made from the Console shows up in the next `terraform plan`, and the next `terraform apply` reverts it. Secret values are the exception: the API never returns them, so a secret changed from the Console does not show up in the plan. See [How the provider tracks changes](/terraform-provider/overview#how-the-provider-tracks-changes).

The export only describes the resources. To deploy the environment on `terraform apply`, add a `qovery_deployment` resource, as in the [basic application example](/terraform-provider/basic-application). Destroying that resource, or removing it from the configuration, deletes the environment and its services.

Store the state in a [remote backend](https://developer.hashicorp.com/terraform/language/backend) so that your team shares it.

## Next steps

<CardGroup cols={2}>
  <Card title="Terraform Provider" icon="code" href="/terraform-provider/overview">
    Set up the provider
  </Card>

  <Card title="Basic Application" icon="rocket" href="/terraform-provider/basic-application">
    Deploy an environment with qovery\_deployment
  </Card>

  <Card title="Terraform Registry" icon="book-open" href="https://registry.terraform.io/providers/qovery/qovery/latest/docs">
    Reference of every resource and its import ID
  </Card>

  <Card title="Environment Variables" icon="sliders" href="/configuration/environment-variables">
    Variables and secrets
  </Card>
</CardGroup>
