Documentation menu

Tools & integrations

Terraform provider

A Terraform Plugin Framework provider that manages generic secrets, named variables, containers, access grants and stored OIDC client metadata through the SecretServer REST API.

The provider is not yet published to the Terraform Registry or as a public download. This page documents its configuration and behavior; its source address is afterdark/secretserver.

Configure

terraform {
  required_providers {
    secretserver = {
      source  = "afterdark/secretserver"
      version = "~> 1.0"
    }
  }
}

provider "secretserver" {
  api_url = "https://api.secretserver.io"   # or SS_API_URL; /api/v1 may be included
  api_key = var.secretserver_api_key       # or SS_API_KEY
}

Explicit attributes override SS_API_URL and SS_API_KEY. The URL defaults to https://api.secretserver.io; the API key is required. Use a scoped API key with only the permissions the managed resources need.

Resources, data sources and ephemeral resources

TypeNamePurposeScopes
Resourcesecretserver_secretGeneric secret. Use exactly one of value or value_wo.secrets:read, write, delete
Resourcesecretserver_containerContainer with name, slug and descriptioncontainers:read, write
Resourcesecretserver_shareAccess grant to exactly one user or group, read or manage, optional RFC3339 expires_atsharing:manage
Resourcesecretserver_variableNamed variable mapping; stores metadata onlyvariables:read, write
Resourcesecretserver_oidc_clientStored OIDC client metadata; does not register or rotate at the identity provideroidc:read, write
Data sourcesecretserver_secretRead by container and key, or by nameread access to the secret
Data sourcesecretserver_secret_versionRead a historical version by container, key and versionread access to the secret
Data sourcesecretserver_oidc_clientRead OIDC metadata by id, without the client secretoidc:read
Ephemeralsecretserver_secretRead a secret by name without storing it in stateread access to the secret
Ephemeralsecretserver_templateResolve a %%NAME%% template without storing it in stateread access to each referenced credential

Example

resource "secretserver_container" "prod" {
  name = "Production"
  slug = "prod"
}

resource "secretserver_secret" "db" {
  name             = "database-password"
  container_id     = secretserver_container.prod.id
  value_wo         = var.database_password
  value_wo_version = 1
}

resource "secretserver_share" "reader" {
  secret_type         = "secret"
  secret_id           = secretserver_secret.db.id
  shared_with_user_id = var.reader_user_id
  permission          = "read"
}

Keep values out of state

Ordinary value and data source results are marked sensitive but persist in state. Write-only value_wo needs Terraform 1.11 or newer; increment value_wo_version to change it. Terraform cannot detect remote drift of a write-only value. Ephemeral resources need Terraform 1.10 or newer and can feed write-only arguments:

ephemeral "secretserver_secret" "source" {
  name = "source-password"
}

resource "secretserver_secret" "copy" {
  name             = "copied-password"
  value_wo         = ephemeral.secretserver_secret.source.value
  value_wo_version = 1
}

Import

terraform import secretserver_secret.db database-password
terraform import secretserver_container.prod CONTAINER_UUID
terraform import secretserver_share.reader secret/SECRET_UUID/SHARE_UUID
terraform import secretserver_variable.sudo LOG_SERVER_TX1_S
terraform import secretserver_oidc_client.app OIDC_RECORD_UUID

Limits

  • Secret names and container slugs are immutable; changing them replaces the resource.
  • Any change to an access grant revokes it and creates a new one.
  • OIDC reads do not return client_secret, so it must be supplied on import, stays in state, and its remote drift cannot be detected. rotate_secret = true is rejected: rotate at the issuer, then update client_secret.
  • Requests use a 30 second timeout, do not follow redirects and cap responses at 4 MiB.