Add a user certificate via Terraform
We recommend creating resources in order. If you create all resources at once, Terraform will account for dependencies between resources that you specified in the configuration file. If dependencies are not specified, resources will be created in parallel, which may lead to errors. For instance, a resource required for creating another resource might not have been created yet.
- Optional: configure providers.
- Add a certificate.
Configuration files
Example file for configuring providers
terraform {
required_providers {
servercore = {
source = "terraform.servercore.com/servercore/servercore"
version = "~> 6.0"
}
openstack = {
source = "terraform-provider-openstack/openstack"
version = "2.1.0"
}
}
}
provider "servercore" {
domain_name = "123456"
username = "user"
password = "password"
auth_region = "uz-1"
auth_url = "https://cloud.api.servercore.com/identity/v3/"
}
resource "servercore_project_v2" "project_1" {
name = "project"
}
resource "servercore_iam_serviceuser_v1" "serviceuser_1" {
name = "username"
password = "password"
role {
role_name = "member"
scope = "project"
project_id = servercore_project_v2.project_1.id
}
}
provider "openstack" {
auth_url = "https://cloud.api.servercore.com/identity/v3"
domain_name = "123456"
tenant_id = servercore_project_v2.project_1.id
user_name = servercore_iam_serviceuser_v1.serviceuser_1.name
password = servercore_iam_serviceuser_v1.serviceuser_1.password
region = "uz-1"
}
Example file for adding a certificate
resource "servercore_secretsmanager_certificate_v1" "certificate_1" {
name = "certificate",
certificates = [file("./_cert.pem")]
private_key = file("./_private_key.pem")
project_id = servercore_project_v2.project_1.id
}
1. Optional: configure providers
If you have configured the Servercore and OpenStack providers, skip this step.
-
Make sure you have created a service user in the control panel
memberwith roles in the Account access scope andiam.admin. -
Create a directory to store configuration files and a separate file with the
.tfextension to configure providers. -
Add the Servercore and OpenStack providers to the file for provider configuration:
terraform {required_providers {servercore = {source = "terraform.servercore.com/servercore/servercore"version = "~> 7.1.0"}openstack = {source = "terraform-provider-openstack/openstack"version = "2.1.0"}}}Here
versionis the provider version. The current version of the OpenStack provider can be found in the Terraform Registry and GitHub.For more information about products, services, and features that can be managed using providers, see the Servercore and OpenStack Providers guide.
-
Initialize the Servercore provider:
provider "servercore" {domain_name = "123456"username = "user"password = "password"auth_region = "uz-1"auth_url = "https://cloud.api.servercore.com/identity/v3/"}Where:
domain_name— Servercore account number. You can find it in the control panel in the top-right corner;username— the name of the service user with thememberrole in the Account access scope andiam.admin. You can view it in the control panel: in the top menu, click IAM → Service Users section (this section is only available to the account owner and users with theiam.adminrole);password— service user password. You can view it when creating the user or change it to a new one;auth_region— pool for authentication in theuz-1format; do not use pools in theSPB-2format. The authentication pool may not match the pool where you create resources. The list of available pools can be found in the Availability Matrix instructions.
-
Create a project:
resource "servercore_project_v2" "project_1" {name = "project"}See the detailed resource description for servercore_project_v2.
-
Create a service user for project access and assign the
memberrole in the Project access scope:resource "servercore_iam_serviceuser_v1" "serviceuser_1" {name = "username"password = "password"role {role_name = "member"scope = "project"project_id = servercore_project_v2.project_1.id}}Where:
-
username— user name; -
password— user password. The password must be at least 20 characters long and include at least:- one uppercase and one lowercase Latin letter (
A-Z,a-z); - one digit (
0-9); - one special character from the ASCII Printable 7-Bit Special Characters list:
!"#$%&'()*+,-./:;<=>?@[]^_{|}~;
- one uppercase and one lowercase Latin letter (
-
project_id— project ID. You can find it in the control panel: in the top menu, click IAM → Projects section → in the row of the required project, click .
See the detailed resource description for servercore_iam_serviceuser_v1.
-
-
Initialize the OpenStack provider:
provider "openstack" {auth_url = "https://cloud.api.servercore.com/identity/v3"domain_name = "123456"tenant_id = servercore_project_v2.project_1.iduser_name = servercore_iam_serviceuser_v1.serviceuser_1.namepassword = servercore_iam_serviceuser_v1.serviceuser_1.passwordregion = "uz-1"}Where:
domain_name— Servercore account number. You can view it in the control panel in the top-right corner;region— pool, for example,uz-1. All resources will be created in this pool. The list of available pools can be found in the Availability Matrix instructions.
-
If you are creating resources at the same time as configuring providers, add the
depends_onargument for OpenStack resources. For example, for the openstack_networking_network_v2 resource:resource "openstack_networking_network_v2" "network_1" {name = "private-network"admin_state_up = "true"depends_on = [servercore_project_v2.project_1,servercore_iam_serviceuser_v1.serviceuser_1]} -
Open the CLI.
-
Initialize the Terraform configuration in the directory:
terraform init -
Verify that the configuration files are syntactically correct:
terraform validate -
Format the configuration files:
terraform fmt -
Check which resources will be created:
terraform plan -
Apply the changes and create the resources:
terraform apply -
Confirm creation — enter yes and press Enter. The created resources will appear in the control panel.
-
If you do not have enough quotas to create resources, increase the quotas.
2. Add a certificate
resource "servercore_secretsmanager_certificate_v1" "certificate_1" {
name = "certificate",
certificates = [file("./_cert.pem")]
private_key = file("./_private_key.pem")
project_id = servercore_project_v2.project_1.id
}
Where:
name— certificate name;certificates— path to the certificate chain. Each certificate must start with-----BEGIN CERTIFICATE-----and end with-----END CERTIFICATE-----;private_key— path to the private key. The key must start with-----BEGIN PRIVATE KEY-----and end with-----END PRIVATE KEY-----.
See the detailed description of the servercore_secretsmanager_certificate_v1 resource.