Skip to main content

Create an image and configure access to it in another project via Terraform

We recommend creating resources in order. If you create all resources at once, Terraform will account for dependencies between resources that you specified in the configuration file. If dependencies are not specified, resources will be created in parallel, which may lead to errors. For instance, a resource required for creating another resource might not have been created yet.


  1. Configure providers for the source project.

  2. Create an image.

  3. Configure access to the image in another project.

  4. Configure providers for the target project.

  5. Accept the image in the target project.

Configuration files

Example file for configuring providers
terraform {
required_providers {
servercore = {
source = "terraform.servercore.com/servercore/servercore"
version = "~> 6.0"
}
openstack = {
source = "terraform-provider-openstack/openstack"
version = "2.1.0"
}
}
}

provider "servercore" {
domain_name = "123456"
username = "user"
password = "password"
auth_region = "uz-1"
auth_url = "https://cloud.api.servercore.com/identity/v3/"
}

resource "servercore_project_v2" "project_1" {
name = "project"
}

resource "servercore_iam_serviceuser_v1" "serviceuser_1" {
name = "username"
password = "password"
role {
role_name = "member"
scope = "project"
project_id = servercore_project_v2.project_1.id
}
}

provider "openstack" {
auth_url = "https://cloud.api.servercore.com/identity/v3"
domain_name = "123456"
tenant_id = servercore_project_v2.project_1.id
user_name = servercore_iam_serviceuser_v1.serviceuser_1.name
password = servercore_iam_serviceuser_v1.serviceuser_1.password
region = "uz-1"
}
Example file for creating an image and configuring access to the image for other projects
resource "openstack_images_image_v2" "image_1" {
name = "Debian 12.10"
container_format = "bare"
disk_format = "qcow2"
visibility = "shared"

properties = {
key = "value"
}
}

resource "openstack_images_image_access_v2" "member_1" {
image_id = openstack_images_image_v2.image_1.id
member_id = "bed6b6cbb86a4e2d8dc2735c2f1000e4"
}

Example file for accepting an image in the target project
data "openstack_images_image_v2" "image_1" {
name = "Debian 12.10"
visibility = "shared"
member_status = "all"
}

resource "openstack_images_image_access_accept_v2" "member_1" {
image_id = data.openstack_images_image_v2.image_1.id
status = "accepted"
}

1. Configure providers for the source project

If you have configured Servercore and OpenStack providers, skip this step.

  1. Make sure you have created a service user in the control panel member with roles in the Account access scope and iam.admin.

  2. Create a directory to store configuration files and a separate file with the .tf extension to configure providers.

  3. Add the Servercore and OpenStack providers to the file for provider configuration:

    terraform {
    required_providers {
    servercore = {
    source = "terraform.servercore.com/servercore/servercore"
    version = "~> 7.1.0"
    }
    openstack = {
    source = "terraform-provider-openstack/openstack"
    version = "2.1.0"
    }
    }
    }

    Here version is the provider version. The current version of the OpenStack provider can be found in the Terraform Registry and GitHub.

    For more information about products, services, and features that can be managed using providers, see the Servercore and OpenStack Providers guide.

  4. Initialize the Servercore provider:

    provider "servercore" {
    domain_name = "123456"
    username = "user"
    password = "password"
    auth_region = "uz-1"
    auth_url = "https://cloud.api.servercore.com/identity/v3/"
    }

    Where:

    • domain_name — Servercore account number. You can find it in the control panel in the top-right corner;
    • username — the name of the service user with the member role in the Account access scope and iam.admin. You can view it in the control panel: in the top menu, click IAMService Users section (this section is only available to the account owner and users with the iam.admin role);
    • password — service user password. You can view it when creating the user or change it to a new one;
    • auth_regionpool for authorization in the uz-1 format; do not use pools in the SPB-2 format. The authorization pool might not match the pool in which you create resources. The list of available pools can be viewed in the guide Product availability by location.
  5. Create a project:

    resource "servercore_project_v2" "project_1" {
    name = "project"
    }

    See the detailed resource description for servercore_project_v2.

  6. Create a service user for project access and assign the member role in the Project access scope:

    resource "servercore_iam_serviceuser_v1" "serviceuser_1" {
    name = "username"
    password = "password"
    role {
    role_name = "member"
    scope = "project"
    project_id = servercore_project_v2.project_1.id
    }
    }

    Where:

    • username — user name;

    • password — user password. The password must be at least 20 characters long and include at least:

      • one uppercase and one lowercase Latin letter (A-Z, a-z);
      • one digit (0-9);
      • one special character from the ASCII Printable 7-Bit Special Characters list:
        !"#$%&'()*+,-./:;<=>?@[]^_{|}~;
    • project_id — project ID. You can find it in the Control panel: in the top menu, click IAM → the Projects section → in the line of the required project, click .

    View the detailed description of the resource servercore_iam_serviceuser_v1.

  7. Initialize the OpenStack provider:

    provider "openstack" {
    auth_url = "https://cloud.api.servercore.com/identity/v3"
    domain_name = "123456"
    tenant_id = servercore_project_v2.project_1.id
    user_name = servercore_iam_serviceuser_v1.serviceuser_1.name
    password = servercore_iam_serviceuser_v1.serviceuser_1.password
    region = "uz-1"
    }

    Where:

    • domain_name — Servercore account number. You can find it in the Control panel in the upper right corner;
    • regionpool, for example uz-1. All resources will be created in this pool. The list of available pools can be viewed in the guide Product availability by location.
  8. If you create resources at the same time as configuring providers, add the depends_on argument for OpenStack resources. For example, for the openstack_networking_network_v2 resource:

    resource "openstack_networking_network_v2" "network_1" {
    name = "private-network"
    admin_state_up = "true"

    depends_on = [
    servercore_project_v2.project_1,
    servercore_iam_serviceuser_v1.serviceuser_1
    ]
    }
  9. Open the CLI.

  10. Initialize the Terraform configuration in the directory:

    terraform init
  11. Verify that the configuration files are syntactically correct:

    terraform validate
  12. Format the configuration files:

    terraform fmt
  13. Check which resources will be created:

    terraform plan
  14. Apply the changes and create the resources:

    terraform apply
  15. Confirm the creation: enter yes and press Enter. The created resources will be displayed in the Control panel.

  16. If there are not enough quotas to create resources, increase quotas.

2. Create an image

resource "openstack_images_image_v2" "image_1" {
name = "Debian 12.10"
container_format = "bare"
disk_format = "qcow2"
visibility = "shared"

properties = {
key = "value"
}
}

Where:

  • container_format — container format. Available values are ami, ari, aki, bare, ovf;
  • disk_format — image disk format. Available values are ami, ari, aki, vhd, vmdk, raw, qcow2, vdi, iso;
  • visibility = "shared" — the image can be added to other projects.

See the detailed description of the openstack_images_image_v2 resource.

3. Configure access to the image in the source project

resource "openstack_images_image_access_v2" "member_1" {
image_id = openstack_images_image_v2.image_1.id
member_id = "bed6b6cbb86a4e2d8dc2735c2f1000e4"
}

Here member_id is the ID of the target project. You can find it in the control panel: from the top menu, click ProductsCloud Servers → open the projects menu → in the line of the required project, click .

See the detailed resource description in openstack_images_image_access_v2.

4. Configure providers for the target project

Create a separate configuration file and set up providers for the account and project for which you configured access to the image.

  1. Make sure you have created a service user in the control panel member with roles in the Account access scope and iam.admin.

  2. Create a directory to store configuration files and a separate file with the .tf extension to configure providers.

  3. Add the Servercore and OpenStack providers to the file for provider configuration:

    terraform {
    required_providers {
    servercore = {
    source = "terraform.servercore.com/servercore/servercore"
    version = "~> 7.1.0"
    }
    openstack = {
    source = "terraform-provider-openstack/openstack"
    version = "2.1.0"
    }
    }
    }

    Here version is the provider version. The current version of the OpenStack provider can be found in the Terraform Registry and GitHub.

    For more information about products, services, and features that can be managed using providers, see the Servercore and OpenStack Providers guide.

  4. Initialize the Servercore provider:

    provider "servercore" {
    domain_name = "123456"
    username = "user"
    password = "password"
    auth_region = "uz-1"
    auth_url = "https://cloud.api.servercore.com/identity/v3/"
    }

    Where:

    • domain_name — Servercore account number. You can find it in the control panel in the top-right corner;
    • username — the name of the service user with the member role in the Account access scope and iam.admin. You can view it in the control panel: in the top menu, click IAMService Users section (this section is only available to the account owner and users with the iam.admin role);
    • password — service user password. You can view it when creating the user or change it to a new one;
    • auth_regionpool for authorization in the uz-1 format; do not use pools in the SPB-2 format. The authorization pool might not match the pool in which you create resources. The list of available pools can be viewed in the guide Product availability by location.
  5. Create a project:

    resource "servercore_project_v2" "project_1" {
    name = "project"
    }

    See the detailed resource description for servercore_project_v2.

  6. Create a service user for project access and assign the member role in the Project access scope:

    resource "servercore_iam_serviceuser_v1" "serviceuser_1" {
    name = "username"
    password = "password"
    role {
    role_name = "member"
    scope = "project"
    project_id = servercore_project_v2.project_1.id
    }
    }

    Where:

    • username — user name;

    • password — user password. The password must be at least 20 characters long and include at least:

      • one uppercase and one lowercase Latin letter (A-Z, a-z);
      • one digit (0-9);
      • one special character from the ASCII Printable 7-Bit Special Characters list:
        !"#$%&'()*+,-./:;<=>?@[]^_{|}~;
    • project_id — project ID. You can find it in the Control panel: in the top menu, click IAM → the Projects section → in the line of the required project, click .

    View the detailed description of the resource servercore_iam_serviceuser_v1.

  7. Initialize the OpenStack provider:

    provider "openstack" {
    auth_url = "https://cloud.api.servercore.com/identity/v3"
    domain_name = "123456"
    tenant_id = servercore_project_v2.project_1.id
    user_name = servercore_iam_serviceuser_v1.serviceuser_1.name
    password = servercore_iam_serviceuser_v1.serviceuser_1.password
    region = "uz-1"
    }

    Where:

    • domain_name — Servercore account number. You can find it in the Control panel in the upper right corner;
    • regionpool, for example uz-1. All resources will be created in this pool. The list of available pools can be viewed in the guide Product availability by location.
  8. If you create resources at the same time as configuring providers, add the depends_on argument for OpenStack resources. For example, for the openstack_networking_network_v2 resource:

    resource "openstack_networking_network_v2" "network_1" {
    name = "private-network"
    admin_state_up = "true"

    depends_on = [
    servercore_project_v2.project_1,
    servercore_iam_serviceuser_v1.serviceuser_1
    ]
    }
  9. Open the CLI.

  10. Initialize the Terraform configuration in the directory:

    terraform init
  11. Verify that the configuration files are syntactically correct:

    terraform validate
  12. Format the configuration files:

    terraform fmt
  13. Check which resources will be created:

    terraform plan
  14. Apply the changes and create the resources:

    terraform apply
  15. Confirm the creation: enter yes and press Enter. The created resources will be displayed in the Control panel.

  16. If there are not enough quotas to create resources, increase quotas.

5. Accept the image in the target project

data "openstack_images_image_v2" "image_1" {
name = "Debian 12.10"
visibility = "shared"
member_status = "all"
}

resource "openstack_images_image_access_accept_v2" "member_1" {
image_id = data.openstack_images_image_v2.image_1.id
status = "accepted"
}

Here status = "accepted" means the image will be accepted in the target project.

See the detailed resource description in openstack_images_image_access_accept_v2.