Okustera Provider
The Okustera provider is used to manage cloud infrastructure and PaaS resources in Okustera via the platform REST API and Apache APISIX gateway.
Example Usage
Personal Access Token (Recommended for CI/CD or CLI)
terraform {
required_providers {
okustera = {
source = "okustera/okustera"
version = "~> 1.0.0"
}
}
}
provider "okustera" {
endpoint = "https://portal.okustera.com/api/v1"
api_token = var.okustera_api_token
tenant_id = "tenant-finance"
}
In-Cluster Workload Identity (Recommended for Kubernetes GitOps)
provider "okustera" {
endpoint = "http://apisix-gateway.apisix.svc/api/v1"
workload_identity = {
enabled = true
token_file = "/var/run/secrets/okustera/token"
role_arn = "arn:okustera:iam::tenant-finance:role/TerraformDeployer"
}
}
User Credentials with Optional 2FA
provider "okustera" {
endpoint = "https://portal.okustera.com/api/v1"
username = var.okustera_username
password = var.okustera_password
totp_code = var.okustera_2fa_code # Optional: if TOTP 2FA is active
}
Supported Resources & Data Sources
Resources
| Resource | Category | Description |
|---|---|---|
okustera_tenant | Identity & Access | Provisions isolated tenant workspaces / Keystone projects |
okustera_user | Identity & Access | Manages user accounts and credentials |
okustera_role_assignment | Identity & Access | Binds roles to users within tenants |
okustera_iam_role | Security & IAM | Declares fine-grained IAM endpoint policies |
okustera_pod_identity_binding | Security & IAM | Binds K8s ServiceAccounts to Okustera IAM roles |
okustera_secret | Secrets (Barbican) | Encrypted storage for certificates, passphrases, and keys |
okustera_database_postgresql | Managed DBaaS | CloudNativePG PostgreSQL 16 HA clusters |
okustera_database_mysql | Managed DBaaS | Oracle MySQL Operator 8.0 HA clusters |
okustera_database_mongodb | Managed DBaaS | Percona Server for MongoDB HA replica sets |
okustera_database_valkey | Managed DBaaS | Spotahome Valkey clusters with Sentinel quorum |
okustera_database_qdrant | Managed DBaaS | Vector database for embeddings and similarity search |
okustera_rabbitmq_cluster | Messaging & Queue | HA RabbitMQ cluster via Topology Operator |
okustera_artifactory_repository | Artifact Registry | Multi-format registry (Docker, Helm, npm, PyPI, Maven) |
okustera_ai_rag_collection | AI & Machine Learning | Knowledge collections indexed with Qdrant vector store |
okustera_s3_bucket | Storage (IaaS) | Ceph RADOS Gateway S3 buckets with quotas and versioning |
okustera_s3_credentials | Storage (IaaS) | Ceph S3 access keys with OpenStack Barbican secret escrow |
okustera_storage_volume | Storage (Cinder) | Persistent Ceph RBD block storage volumes |
okustera_storage_volume_attachment | Storage & Compute | Attaches Cinder block storage volumes to Nova instances |
okustera_storage_snapshot | Storage (Cinder) | Point-in-time copy-on-write volume snapshots |
okustera_network | Networking (Neutron) | Isolated Layer 2/3 VPC networks and subnets |
okustera_security_group | Networking (Neutron) | Virtual firewall security group containers |
okustera_security_group_rule | Networking (Neutron) | Ingress and egress firewall packet filtering rules |
okustera_floating_ip | Networking (Neutron) | Routable public IPv4 floating IPs |
okustera_floating_ip_associate | Networking (Neutron) | Binds public floating IPs to Neutron interface ports |
okustera_compute_instance | Compute (Nova) | Nova virtual machines with cloud-init bootstrap |
okustera_kubernetes_cluster_template | Kubernetes (Magnum) | Reusable blueprints for Magnum Kubernetes clusters |
okustera_kubernetes_cluster | Kubernetes (Magnum) | Production Kubernetes clusters with automated kubeconfig |
okustera_loadbalancer | Load Balancing (Octavia) | High-availability Amphora load balancers |
okustera_apisix_route | API Gateway | Ingress routes with SSL/TLS termination, WAF, and CORS |
okustera_gateway_certificate | API Gateway | Automated Let's Encrypt / internal CA TLS certificates |
okustera_function | Serverless FaaS | Event-driven serverless functions powered by OpenFaaS |
okustera_layer | Serverless FaaS | Shared CephFS dependency layers with multi-tenant RBAC |
okustera_layer_version | Serverless FaaS | Immutable snapshot versions of serverless shared layers |
okustera_layer_permission | Serverless FaaS | Cross-tenant access permissions for shared layers |
okustera_workflow_dag | Workflows (Airflow) | Managed Apache Airflow DAGs with S3 synchronization |
okustera_billing_budget | FinOps & Billing | Monthly budget limits, alert thresholds, and quota freezes |
Data Sources
| Data Source | Category | Description |
|---|---|---|
okustera_pricing_rates | FinOps & Billing | Active unit pricing across compute, storage, DB, and FaaS |
okustera_billing_overview | FinOps & Billing | Read-only tenant month-to-date spend, forecast, and trends |
okustera_observability_overview | Observability | Cluster CPU/RAM, pod status, and network bandwidth |
okustera_workflow_status | Workflows (Airflow) | Operational health, scheduler state, and S3 status of Airflow cluster |
okustera_workflow_dag | Workflows (Airflow) | Metadata, execution schedule, tags, and run status of an Airflow DAG |
okustera_layer | Serverless FaaS | Lookup shared CephFS layer details and latest version |
okustera_layer_version | Serverless FaaS | Details of a specific immutable layer snapshot version |
okustera_database_cluster | Managed DBaaS | Look up operational endpoints for running database clusters |
okustera_router | Networking (Neutron) | Inspect existing network routers and gateway links |
okustera_port | Networking (Neutron) | Discover Neutron network interface ports by port UUID or VM device ID |
okustera_compute_flavor | Compute (Nova) | Sizing specifications (vCPU, RAM, disk) for VM flavors |
okustera_image | Images (Glance) | Lookup available VM and container OS images |
okustera_kubernetes_cluster_config | Kubernetes (Magnum) | Fetch live signed Kubeconfig for Terraform Helm/K8s providers |
Schema
Optional
endpoint(String) The base URL for the Okustera API (e.g.https://portal.okustera.com/api/v1orhttp://apisix-gateway.apisix.svc/api/v1). May also be set via theOKUSTERA_ENDPOINTenvironment variable (or legacyOMC_ENDPOINT).api_token(String, Sensitive) A Personal Access Token (PAT) for Okustera. May also be set via theOKUSTERA_API_TOKENenvironment variable (or legacyOMC_API_TOKEN).tenant_id(String) The ID or name of the tenant project to scope operations under. May also be set via theOKUSTERA_TENANT_IDenvironment variable (or legacyOMC_TENANT_ID).username(String) Username for Okustera authentication. May also be set viaOKUSTERA_USERNAME(or legacyOMC_USERNAME).password(String, Sensitive) Password for Okustera authentication. May also be set viaOKUSTERA_PASSWORD(or legacyOMC_PASSWORD).totp_code(String, Sensitive) 6-digit TOTP two-factor authentication code. May also be set viaOKUSTERA_TOTP_CODE(or legacyOMC_TOTP_CODE).insecure_skip_verify(Boolean) Set totrueto skip TLS certificate verification. Useful for private staging environments with self-signed certificates. Defaults tofalse. May also be set viaOKUSTERA_INSECURE_SKIP_VERIFY(or legacyOMC_INSECURE_SKIP_VERIFY).host_header(String) Host header override for API Gateway routing (defaults toportal.okustera.com). May also be set viaOKUSTERA_HOST_HEADER(or legacyOMC_HOST_HEADER).workload_identity(Block, Optional) Configuration for Kubernetes Pod Workload Identity (see below for nested schema).
Nested Schema for workload_identity
enabled(Boolean) Set totrueto activate Workload Identity token discovery.token_file(String) Path to the projected Kubernetes ServiceAccount token file (defaults to/var/run/secrets/okustera/token,OKUSTERA_TOKEN_FILE, or legacyOMC_TOKEN_FILE).role_arn(String) The ARN of the Okustera IAM role to assume (e.g.,arn:okustera:iam::tenant-1002:role/TerraformDeployer).
Environment Variables
| Variable | Fallback Variable | Provider Attribute | Description |
|---|---|---|---|
OKUSTERA_ENDPOINT | OMC_ENDPOINT | endpoint | Base URL of the Okustera API / APISIX Gateway |
OKUSTERA_API_TOKEN | OMC_API_TOKEN | api_token | Personal Access Token |
OKUSTERA_TENANT_ID | OMC_TENANT_ID | tenant_id | Project or Tenant ID |
OKUSTERA_HOST_HEADER | OMC_HOST_HEADER | host_header | Host header override for APISIX Gateway routing |
OKUSTERA_USERNAME | OMC_USERNAME | username | User account email or ID |
OKUSTERA_PASSWORD | OMC_PASSWORD | password | User account password |
OKUSTERA_TOTP_CODE | OMC_TOTP_CODE | totp_code | Two-factor authentication code |
OKUSTERA_TOKEN_FILE | OMC_TOKEN_FILE | workload_identity.token_file | Path to projected K8s ServiceAccount JWT |
OKUSTERA_INSECURE_SKIP_VERIFY | OMC_INSECURE_SKIP_VERIFY | insecure_skip_verify | Skip TLS certificate verification |