Other providers
Stategraph Orchestration works with any cloud or service that has a Terraform provider, not only AWS, GCP, and Azure: you store the access token of the provider as a GitHub secret or a GitLab CI/CD variable. Most providers read the token from an environment variable.
Orchestration runs Terraform on your GitHub Actions or GitLab CI runners, so the provider needs the same credentials there as on your workstation. Without them, it cannot read or change resources. The runner gets GitHub secrets and GitLab CI/CD variables as environment variables. See Variables.
Most providers are on the Terraform Registry. Authentication is different for each provider: check its documentation for the variable names and token scopes that it requires.
Typical setup
- Create a user, role, or service account on the provider, with the permissions that Orchestration needs.
- Generate an access token for it.
- Store the token as a repository secret (GitHub) or a masked CI/CD variable (GitLab), under the environment variable name that the provider expects.
Example: Fly.io
The fly provider reads its token from the provider block or from the FLY_API_TOKEN environment variable.
provider "fly" {
# Do not do this. Set the FLY_API_TOKEN environment variable instead.
flytoken = "abc123"
}
Use the environment variable. Everyone with read access to the repository can see a token in Git, and it stays in the history after you remove it.
Create the token
Choose the Fly.io user for Orchestration, and create an access token for it:
export FLY_API_TOKEN=$(fly auth token)
Store the token for your VCS, as below. On the next stategraph plan or stategraph apply, the runner gets FLY_API_TOKEN as an environment variable, and the provider authenticates with it.
GitHub
Store the token as the FLY_API_TOKEN secret with the GitHub CLI:
export REPO="<OWNER/REPO>"
gh secret --repo "$REPO" set FLY_API_TOKEN --body "$FLY_API_TOKEN"
GitLab
- Open your GitLab project and go to Settings, then CI/CD, then Variables.
- Click Add variable, enter the Key
FLY_API_TOKEN, and paste the token as the Value. - Mark the variable as masked, leave Protect variable cleared, then click Add variable.
GitLab passes protected variables only to pipelines on protected branches. Orchestration runs plans on the merge request's source branch, so those runs do not get a protected variable.
Next Steps
- Variables: secrets, CI/CD variables, and
.tfvarsfiles - Cloud credentials: OIDC, static credentials, and custom credential scripts
- Configuration: the
.stategraph/config.ymlfile