Skip to main content

Getting Started with the Okustera Terraform Provider

This guide walks you through provisioning a complete production web application environment on Okustera using Terraform.


Prerequisites​

  1. An active account on Okustera with a personal access token (or working inside a Kubernetes cluster with Pod Workload Identity enabled).
  2. Terraform CLI >= 1.5.0 installed.

What We Will Deploy​

In this walkthrough, we will provision:

  1. A 3-node HA PostgreSQL 16 database (CloudNativePG) with automatic backups.
  2. A Valkey cache (Spotahome Operator with 3-node Sentinel quorum).
  3. An S3 storage bucket (Ceph RADOS Gateway) with versioning.
  4. A sandboxed serverless function (OpenFaaS with gVisor isolation).
  5. An Apache APISIX ingress route with rate-limiting and CORS policies.
  6. A Pod IAM role and binding for zero-trust in-cluster access.
  7. A monthly budget alert with spending threshold notifications.

Step 1: Initialize the Project​

Create a working directory and a main.tf file:

mkdir my-okustera-infrastructure
cd my-okustera-infrastructure

Add the provider block:

terraform {
required_providers {
okustera = {
source = "okustera/okustera"
version = "~> 1.0.0"
}
}
}

provider "okustera" {
endpoint = "https://portal.okustera.com/api/v1"
api_token = var.okustera_api_token
tenant_id = "tenant-prod"
}

variable "okustera_api_token" {
type = string
sensitive = true
description = "Okustera Personal Access Token"
}

Step 2: Declare Infrastructure Resources​

Add the database, cache, and storage resources:

# 1. PostgreSQL 16 HA Cluster
resource "okustera_database_postgresql" "db" {
name = "ecommerce-db"
instances = 3
storage_size_gb = 50
database_name = "ecommerce"
owner_username = "ecommerce_user"
enable_backups = true
}

# 2. Valkey Sentinel Cache
resource "okustera_database_valkey" "cache" {
name = "ecommerce-cache"
replicas = 3
memory_limit = "2Gi"
sentinel_replicas = 3
}

# 3. Ceph S3 Object Storage Bucket
resource "okustera_s3_bucket" "product_images" {
name = "ecommerce-product-images"
versioning = true
quota_gb = 100
}

Step 3: Declare Serverless Function & Ingress Routing​

# 4. Sandboxed Serverless Function (gVisor)
resource "okustera_function" "order_processor" {
name = "process-order"
image = "portal.okustera.com/artifactory/docker/order-worker:v1.0.0"
runtime = "sandboxed" # Enforces gVisor kernel virtualization
memory_limit = "512Mi"
timeout_seconds = 30

environment = {
DB_HOST = okustera_database_postgresql.db.primary_endpoint
VALKEY_HOST = okustera_database_valkey.cache.master_endpoint
BUCKET_NAME = okustera_s3_bucket.product_images.name
}
}

# 5. Apache APISIX Gateway Route with WAF and TLS
resource "okustera_apisix_route" "order_route" {
name = "order-processing-api"
host = "api.ecommerce.okustera.com"
paths = ["/api/v1/orders*"]

upstream = {
service_name = "okustera-function-process-order"
port = 8080
timeout = 15
}

# Automatic HTTPS & OWASP WAF Protection
tls_enabled = true
cluster_issuer = "letsencrypt-prod"
waf_enabled = true
waf_mode = "DetectionOnly"

rate_limit = {
requests_per_minute = 180
burst = 30
}

cors_enabled = true
}

Step 4: Configure Workload Identity & FinOps​

# 6. Pod IAM Role for Workers
resource "okustera_iam_role" "worker_role" {
name = "order-worker-role"
description = "Allows order-processing pods to access product images and databases"

endpoint_policies = [
{
effect = "Allow"
paths = ["/api/v1/storage/ecommerce-product-images/*"]
methods = ["GET", "PUT"]
}
]
}

resource "okustera_pod_identity_binding" "worker_binding" {
namespace = "tenant-prod"
service_account = "order-worker-sa"
role_name = okustera_iam_role.worker_role.name
}

# 7. Monthly FinOps Budget Cap & Threshold Alerts
resource "okustera_billing_budget" "budget" {
monthly_budget_limit = 200.00
alert_thresholds = [50, 80, 100]
notification_email = "[email protected]"
enable_email_alerts = true
}

Step 5: Plan and Apply​

export TF_VAR_okustera_api_token="your_personal_access_token"

terraform init
terraform plan
terraform apply

Terraform will connect to Okustera through Apache APISIX, orchestrate the creation of all resources, poll their readiness status, and store the state locally or in remote S3/Terraform Cloud backend.

For detailed instructions on configuring production remote state, Ceph RGW S3 buckets, and state locking, see the Managing Terraform State & Remote Backends guide.