> ## Documentation Index
> Fetch the complete documentation index at: https://qovery-gdubroeucq-qov-2319.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Terraform Provider

> Manage Qovery resources as code with the Qovery Terraform provider

The Qovery Terraform provider manages Qovery resources from Terraform: organization settings, cloud credentials, clusters, projects, environments, services (applications, containers, jobs, Helm charts, Terraform services and databases) and their variables. You describe the resources in HCL, review the changes with `terraform plan`, and apply them with `terraform apply`.

This page covers the setup. The reference of every resource and data source is on the [Terraform Registry](https://registry.terraform.io/providers/qovery/qovery/latest/docs).

<Info>
  Upgrading from an earlier version? Read the [upgrade guide](https://registry.terraform.io/providers/qovery/qovery/latest/docs/guides/upgrade-to-1.0) before you change the version constraint.
</Info>

## Requirements

* Terraform. The provider is tested against Terraform 1.15. Earlier versions are expected to work but are not tested.
* A Qovery API token.

## Install the provider

Declare the provider and pin its major version, so that a future major release cannot introduce a breaking change without an explicit upgrade:

```hcl main.tf theme={null}
terraform {
  required_providers {
    qovery = {
      source  = "qovery/qovery"
      version = "~> 1.0"
    }
  }
}

# Reads the API token from the QOVERY_API_TOKEN environment variable.
provider "qovery" {}
```

Run `terraform init` to download the provider.

## Authentication

The provider authenticates with a Qovery API token. To create one, see [API Token](/configuration/organization/api-token). The token carries a role: give it one that allows the changes your configuration makes.

Pass the token in one of two ways:

* Set the `QOVERY_API_TOKEN` environment variable. The provider reads it when the `token` argument is not set.

  ```bash theme={null}
  export QOVERY_API_TOKEN="<your-api-token>"
  ```

* Set the `token` argument from a sensitive input variable:

  ```hcl theme={null}
  variable "qovery_api_token" {
    type      = string
    sensitive = true
  }

  provider "qovery" {
    token = var.qovery_api_token
  }
  ```

<Warning>
  Do not write the token in your configuration files or commit it to version control.
</Warning>

## Find resource IDs

Resources reference each other by ID. To use a resource that your configuration does not manage, such as an existing cluster, pass its ID to the configuration, usually as an input variable.

* **Console**: IDs appear in the page URL, for example `https://console.qovery.com/organization/<organization_id>/project/<project_id>/overview`.
* **CLI**: `qovery organization list`, `qovery project list`, `qovery cluster list` and `qovery environment list` print the ID of each resource. Run `qovery context set` first to select the organization and the project. See the [CLI documentation](/cli/overview).

Data sources look up an existing resource by its `id`, not by its name (`qovery_organization_member` uses the member's `email`). Organization-level data sources, such as `qovery_cluster`, also require `organization_id`:

```hcl theme={null}
variable "organization_id" {
  type = string
}

variable "cluster_id" {
  type = string
}

data "qovery_cluster" "main" {
  id              = var.cluster_id
  organization_id = var.organization_id
}

output "cluster_name" {
  value = data.qovery_cluster.main.name
}
```

To bring a resource created from the Console or the API under Terraform, declare it in the configuration and add an `import` block. The Registry page of each resource gives its import ID. The [Terraform exporter](/terraform-provider/exporter) generates the configuration of a whole environment.

## How the provider tracks changes

The configuration is the source of truth. `terraform plan` refreshes every resource from the Qovery API, so a change made from the Console or the API shows up as a difference, and the next `terraform apply` reverts it to the configured value. The API never returns secrets, such as secret values, passwords and secret keys: Terraform keeps them as configured, so a change made to them outside Terraform does not show up in the plan. Removing an attribute from the configuration plans its default value or its removal.

A few attributes keep their current value when you remove them, because the Qovery API gives Terraform no way to reset them, for example `deployment_stage_id` and `advanced_settings_json`. The [Managing changes guide](https://registry.terraform.io/providers/qovery/qovery/latest/docs/guides/managing-changes) explains the rules and lists these exceptions.

Change the resources that Terraform manages in the configuration, not in the Console.

## Deploy an environment

Creating or changing a service with Terraform updates its configuration in Qovery but does not deploy it. The [`qovery_deployment`](https://registry.terraform.io/providers/qovery/qovery/latest/docs/resources/deployment) resource deploys, stops or restarts an environment on `terraform apply`. You can also deploy from the Console. Qovery stores no deployment object, so a deployment started from the Console does not show up in `terraform plan`.

<Warning>
  Destroying a `qovery_deployment`, or removing it from the configuration, deletes its environment and all the services in it. Only declare it for an environment that the same configuration creates or has imported.
</Warning>

## Next steps

<CardGroup cols={3}>
  <Card title="Basic Application" icon="rocket" href="/terraform-provider/basic-application">
    Deploy an application from a git repository
  </Card>

  <Card title="Application with Database" icon="database" href="/terraform-provider/application-with-database">
    Connect an application to a database
  </Card>

  <Card title="Linking Services Together" icon="link" href="/terraform-provider/linking-services">
    Connect services to each other
  </Card>

  <Card title="Multi-Environment Setup" icon="layer-group" href="/terraform-provider/multi-environment">
    Create development, staging and production environments
  </Card>

  <Card title="Airbyte Deployment" icon="diagram-project" href="/terraform-provider/airbyte-deployment">
    Deploy a Helm chart with a database and a proxy
  </Card>

  <Card title="Advanced Patterns" icon="code" href="/terraform-provider/advanced-patterns">
    Modules, workspaces and remote state
  </Card>

  <Card title="Terraform Exporter" icon="file-export" href="/terraform-provider/exporter">
    Generate the configuration of an existing environment
  </Card>

  <Card title="Terraform Registry" icon="book-open" href="https://registry.terraform.io/providers/qovery/qovery/latest/docs">
    Reference of every resource and data source
  </Card>

  <Card title="GitHub Repository" icon="https://mintcdn.com/qovery-gdubroeucq-qov-2319/d4pJZUv4pt_7pey0/images/logos/github-icon.svg?fit=max&auto=format&n=d4pJZUv4pt_7pey0&q=85&s=90b7c77283994a9a65bdddcb4b84ecc2" href="https://github.com/Qovery/terraform-provider-qovery" width="24" height="24" data-path="images/logos/github-icon.svg">
    Provider source code and issues
  </Card>
</CardGroup>
