Skip to main content

Okustera Provider

The Okustera provider is used to manage cloud infrastructure and PaaS resources in Okustera via the platform REST API and Apache APISIX gateway.

Example Usage​

terraform {
required_providers {
okustera = {
source = "okustera/okustera"
version = "~> 1.0.0"
}
}
}

provider "okustera" {
endpoint = "https://portal.okustera.com/api/v1"
api_token = var.okustera_api_token
tenant_id = "tenant-finance"
}
provider "okustera" {
endpoint = "http://apisix-gateway.apisix.svc/api/v1"

workload_identity = {
enabled = true
token_file = "/var/run/secrets/okustera/token"
role_arn = "arn:okustera:iam::tenant-finance:role/TerraformDeployer"
}
}

User Credentials with Optional 2FA​

provider "okustera" {
endpoint = "https://portal.okustera.com/api/v1"
username = var.okustera_username
password = var.okustera_password
totp_code = var.okustera_2fa_code # Optional: if TOTP 2FA is active
}

Supported Resources & Data Sources​

Resources​

ResourceCategoryDescription
okustera_tenantIdentity & AccessProvisions isolated tenant workspaces / Keystone projects
okustera_userIdentity & AccessManages user accounts and credentials
okustera_role_assignmentIdentity & AccessBinds roles to users within tenants
okustera_iam_roleSecurity & IAMDeclares fine-grained IAM endpoint policies
okustera_pod_identity_bindingSecurity & IAMBinds K8s ServiceAccounts to Okustera IAM roles
okustera_secretSecrets (Barbican)Encrypted storage for certificates, passphrases, and keys
okustera_database_postgresqlManaged DBaaSCloudNativePG PostgreSQL 16 HA clusters
okustera_database_mysqlManaged DBaaSOracle MySQL Operator 8.0 HA clusters
okustera_database_mongodbManaged DBaaSPercona Server for MongoDB HA replica sets
okustera_database_valkeyManaged DBaaSSpotahome Valkey clusters with Sentinel quorum
okustera_database_qdrantManaged DBaaSVector database for embeddings and similarity search
okustera_rabbitmq_clusterMessaging & QueueHA RabbitMQ cluster via Topology Operator
okustera_artifactory_repositoryArtifact RegistryMulti-format registry (Docker, Helm, npm, PyPI, Maven)
okustera_ai_rag_collectionAI & Machine LearningKnowledge collections indexed with Qdrant vector store
okustera_s3_bucketStorage (IaaS)Ceph RADOS Gateway S3 buckets with quotas and versioning
okustera_s3_credentialsStorage (IaaS)Ceph S3 access keys with OpenStack Barbican secret escrow
okustera_storage_volumeStorage (Cinder)Persistent Ceph RBD block storage volumes
okustera_storage_volume_attachmentStorage & ComputeAttaches Cinder block storage volumes to Nova instances
okustera_storage_snapshotStorage (Cinder)Point-in-time copy-on-write volume snapshots
okustera_networkNetworking (Neutron)Isolated Layer 2/3 VPC networks and subnets
okustera_security_groupNetworking (Neutron)Virtual firewall security group containers
okustera_security_group_ruleNetworking (Neutron)Ingress and egress firewall packet filtering rules
okustera_floating_ipNetworking (Neutron)Routable public IPv4 floating IPs
okustera_floating_ip_associateNetworking (Neutron)Binds public floating IPs to Neutron interface ports
okustera_compute_instanceCompute (Nova)Nova virtual machines with cloud-init bootstrap
okustera_kubernetes_cluster_templateKubernetes (Magnum)Reusable blueprints for Magnum Kubernetes clusters
okustera_kubernetes_clusterKubernetes (Magnum)Production Kubernetes clusters with automated kubeconfig
okustera_loadbalancerLoad Balancing (Octavia)High-availability Amphora load balancers
okustera_apisix_routeAPI GatewayIngress routes with SSL/TLS termination, WAF, and CORS
okustera_gateway_certificateAPI GatewayAutomated Let's Encrypt / internal CA TLS certificates
okustera_functionServerless FaaSEvent-driven serverless functions powered by OpenFaaS
okustera_layerServerless FaaSShared CephFS dependency layers with multi-tenant RBAC
okustera_layer_versionServerless FaaSImmutable snapshot versions of serverless shared layers
okustera_layer_permissionServerless FaaSCross-tenant access permissions for shared layers
okustera_workflow_dagWorkflows (Airflow)Managed Apache Airflow DAGs with S3 synchronization
okustera_billing_budgetFinOps & BillingMonthly budget limits, alert thresholds, and quota freezes

Data Sources​

Data SourceCategoryDescription
okustera_pricing_ratesFinOps & BillingActive unit pricing across compute, storage, DB, and FaaS
okustera_billing_overviewFinOps & BillingRead-only tenant month-to-date spend, forecast, and trends
okustera_observability_overviewObservabilityCluster CPU/RAM, pod status, and network bandwidth
okustera_workflow_statusWorkflows (Airflow)Operational health, scheduler state, and S3 status of Airflow cluster
okustera_workflow_dagWorkflows (Airflow)Metadata, execution schedule, tags, and run status of an Airflow DAG
okustera_layerServerless FaaSLookup shared CephFS layer details and latest version
okustera_layer_versionServerless FaaSDetails of a specific immutable layer snapshot version
okustera_database_clusterManaged DBaaSLook up operational endpoints for running database clusters
okustera_routerNetworking (Neutron)Inspect existing network routers and gateway links
okustera_portNetworking (Neutron)Discover Neutron network interface ports by port UUID or VM device ID
okustera_compute_flavorCompute (Nova)Sizing specifications (vCPU, RAM, disk) for VM flavors
okustera_imageImages (Glance)Lookup available VM and container OS images
okustera_kubernetes_cluster_configKubernetes (Magnum)Fetch live signed Kubeconfig for Terraform Helm/K8s providers

Schema​

Optional​

  • endpoint (String) The base URL for the Okustera API (e.g. https://portal.okustera.com/api/v1 or http://apisix-gateway.apisix.svc/api/v1). May also be set via the OKUSTERA_ENDPOINT environment variable (or legacy OMC_ENDPOINT).
  • api_token (String, Sensitive) A Personal Access Token (PAT) for Okustera. May also be set via the OKUSTERA_API_TOKEN environment variable (or legacy OMC_API_TOKEN).
  • tenant_id (String) The ID or name of the tenant project to scope operations under. May also be set via the OKUSTERA_TENANT_ID environment variable (or legacy OMC_TENANT_ID).
  • username (String) Username for Okustera authentication. May also be set via OKUSTERA_USERNAME (or legacy OMC_USERNAME).
  • password (String, Sensitive) Password for Okustera authentication. May also be set via OKUSTERA_PASSWORD (or legacy OMC_PASSWORD).
  • totp_code (String, Sensitive) 6-digit TOTP two-factor authentication code. May also be set via OKUSTERA_TOTP_CODE (or legacy OMC_TOTP_CODE).
  • insecure_skip_verify (Boolean) Set to true to skip TLS certificate verification. Useful for private staging environments with self-signed certificates. Defaults to false. May also be set via OKUSTERA_INSECURE_SKIP_VERIFY (or legacy OMC_INSECURE_SKIP_VERIFY).
  • host_header (String) Host header override for API Gateway routing (defaults to portal.okustera.com). May also be set via OKUSTERA_HOST_HEADER (or legacy OMC_HOST_HEADER).
  • workload_identity (Block, Optional) Configuration for Kubernetes Pod Workload Identity (see below for nested schema).

Nested Schema for workload_identity​

  • enabled (Boolean) Set to true to activate Workload Identity token discovery.
  • token_file (String) Path to the projected Kubernetes ServiceAccount token file (defaults to /var/run/secrets/okustera/token, OKUSTERA_TOKEN_FILE, or legacy OMC_TOKEN_FILE).
  • role_arn (String) The ARN of the Okustera IAM role to assume (e.g., arn:okustera:iam::tenant-1002:role/TerraformDeployer).

Environment Variables​

VariableFallback VariableProvider AttributeDescription
OKUSTERA_ENDPOINTOMC_ENDPOINTendpointBase URL of the Okustera API / APISIX Gateway
OKUSTERA_API_TOKENOMC_API_TOKENapi_tokenPersonal Access Token
OKUSTERA_TENANT_IDOMC_TENANT_IDtenant_idProject or Tenant ID
OKUSTERA_HOST_HEADEROMC_HOST_HEADERhost_headerHost header override for APISIX Gateway routing
OKUSTERA_USERNAMEOMC_USERNAMEusernameUser account email or ID
OKUSTERA_PASSWORDOMC_PASSWORDpasswordUser account password
OKUSTERA_TOTP_CODEOMC_TOTP_CODEtotp_codeTwo-factor authentication code
OKUSTERA_TOKEN_FILEOMC_TOKEN_FILEworkload_identity.token_filePath to projected K8s ServiceAccount JWT
OKUSTERA_INSECURE_SKIP_VERIFYOMC_INSECURE_SKIP_VERIFYinsecure_skip_verifySkip TLS certificate verification