Terraform resources with dynamic provider values

February 11, 2021 – Samuli Seppänen

Sometimes you'd like to pass a dynamic value to a Terraform resource's provider parameter. This can be done, but some background first.

Terraform allows you to define multiple providers of the same type using provider aliases. This is useful when you're working with a provider that is tied to a region, the AWS provider being a prime example. The moment you want to create resources in multiple regions you will have to learn provider aliases.

If some of your resources are in nested modules you need to pass them down from their parent module like this:

provider "aws" {
  region = "us-east-1"
  alias  = "us-east-1"
}

provider "aws" {
  region = "us-east-2"
  alias  = "us-east-2"
}

module "production" {
  source            = "../modules/cloud"
  providers         = { aws = aws,

                        aws.us-east-2 = aws.us-east-2 }
  --- snip ---

This works well until you use the same module to produce several nearly identical environments. Say "production", "staging" and "development", which are not necessarily located in the same region. At that point you may very well encounter that one pesky resource that would need to have a "provider" parameter whose value is constructed dynamically. At this point you're itching to do something like this:

resource "aws_s3_bucket" "mybucket" {
  bucket = "mybucket.example.org"
  provider = "aws.${var.s3_bucket_region}"
}

The thanks you get from Terraform in return is this:

Error: Could not load plugin
                                                                                          
Plugin reinitialization required. Please run "terraform init".

This happens because Terraform thinks you are trying to use provider type "var" which has the alias of "${var.region}". In other words it does not expect a string as the argument and gets completely confused. Apparently resource providers are evaluated before variable expansion, so you have to hardcode the provider to each resource.

Fortunately you're not totally shit out of luck. If you're motivated enough you can wrap the resources that need dynamic provider configuration into module and pass that module the correct providers as shown at the top.

Want to talk to an expert?

If you want to reach us, just send us a message or book a free call!
Categories

Tags

#aad #Access #acl #alertmanager #ansible #ansible module development #Apache #API #augeas #authentication #authorization #automation #automatization #aws #azure #backup #bash #bitbucket #buildbot #cache #centos #cloud #cloud-init #cloudflare #cloudfront #cluster #connectionsJpa #control repo #custom fact #database #debian #devops #digital sovereignty #DNS #docker #domain mode #duplo #ejabberd #email #encryption #erb #europe #eyaml #fabric #facter #facts #fargate #fedora #file #finnish #foreman #freeipa #git #github #gitlab #gnome #google #grafana #hammer #hiera #IAM #import #infinispan #Infrastructure as Code #ipmi #irc #jboss #jdk #jenkins #JMESPath #kanban #keycloak #librarian-puppet #librenms #linkedin #Linux #Location #loop #marketing #mautic #Mellon #mfa #monitoring #mysql #nagios #network-manager #oauth #oauth2 #office365 #open source #openvpn #oxygen #packer #paranormal #pdk #people #php #pkcs7 #pomodoro #Powershell #preseed #presentation #profiles #prometheus #provisioning #puppet #puppet-bolt #puppet-litmus #puppetboard #puppetdb #Puppetfile #puppetserver #puppet types and providers #pxeboot #qemu #quality #r10k #recruitment #redirect #Restrict #Reverse Proxy #roles #rspec #ruby #SAML #sem #shell #showsql #snmp #snmpd #software developement #spam #ssh #sso #standardization #systemd #systemd-resolved #teams #terraform #ubuntu #user-data #vagrant #vanity awards #variable #vim #virtualbox #visualstudio #webdevelopment #wildfly #Windows #wireguard #wordpress #workflow #x11 #xmpp #zimbra
We are
 Puppeteers
menucross-circle