tfe-bootstrapper¶
This module bootstraps Terraform Cloud to create workspaces needed for Okta and Azure
Backfilling the Okta variable set to existing app workspaces¶
This module now attaches the existing OktaClientVariableSet (the same variable set
already attached to okta-client workspaces — see app/main.tf,
attach_external_okta_credentials) to "app" (API-service) workspaces as well, so the
okta provider can self-configure for external-identity's native Okta data sources
(forge#845). No new variable set or saif-utilities change was needed for this — it
reuses what already exists.
Merging this change only changes what happens on the next terraform plan of a
bootstrap-* workspace. It does not retroactively attach the variable set to existing
"app" workspaces that already exist and haven't been re-planned since this ships.
Consumers of saif-api-service whose bootstrap-* workspace isn't re-triggered would
silently keep missing Okta credentials until something forces a plan.
Two options to backfill, in order of preference:
- One-time TFC API bulk trigger. Script a run against every existing
bootstrap-*workspace (list via the TFC API filtered by project/tag) once this module version is published, e.g.POST /runswith a JSON:API body whosedata.relationships.workspace.data.idis the target workspace ID and whosedata.attributes.messagenotes why the run was triggered. Pros: explicit, auditable, no lingering behavior change. Cons: one-off script to write and run, and it re-applies every bootstrap workspace (broader blast radius than just the Okta attach) unless scoped carefully (e.g.is-destroy: false, plan-only first). - Mark the variable set
global = truein TFC. IfOktaClientVariableSetis switched to global scope, TFC auto-attaches it to all existing and future workspaces in the org without needing a Terraform-side attach or workspace re-plan at all. Pros: zero backfill work, no bulk trigger needed. Cons: over-broad — attaches to every workspace in the org (including non-API-service ones that don't need Okta credentials, and workspaces outside the External tenant), which conflicts with the External-tenant/API-service-only scoping this module implements; would also affectokta-clientworkspaces' existing global-scope posture. This needs a conscious tradeoff decision with whoever owns the TFC org-level variable-set policy, not something to change silently.
Neither option is executed by this module — a human should pick one and run it once,
after this change has shipped to main and been consumed by the target projects'
bootstrap workspaces (or immediately, if choosing the global = true route).
Providers¶
| Name | Version |
|---|---|
| tfe | >= 0.58.1, < 1.0.0 |
Inputs¶
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| additional_environments | Additional environments to create workspaces for, beyond the standard set returned by module.names.Environments (Test, QA, UAT, Production). Use this for non-standard environments like PlatformDev that aren't in the canonical product environment list. Only honored when var.environment is "" (the default-fan-out path); ignored when var.environment is set to a single env. |
list(object({ |
[] |
no |
| environment | The environment to create the resources in. | string |
"" |
no |
| has_external_auth | Whether or not to create external authentication (Okta) workspaces. | bool |
true |
no |
| has_internal_auth | Whether or not to create internal authentication (Entra ID) workspaces. | bool |
true |
no |
| has_subscriptions | Whether or not to create a subscription workspace. | bool |
false |
no |
| has_web_app | Whether or not to create a web app workspace. | bool |
false |
no |
| project_id | The id of the project to create the resources in. | string |
n/a | yes |
Outputs¶
No outputs.
Resources¶
- data source.tfe_organization.organization (/terraform-docs/main.tf#1)
- data source.tfe_policy_set.policy_set (/terraform-docs/main.tf#10)
- data source.tfe_project.project (/terraform-docs/main.tf#5)