Configure the environment for working with Terraform
1. Install Terraform
-
Download the Terraform distribution for your operating system from the HashiCorp website or from a mirror. We recommend downloading Terraform version 1.9.
-
If you downloaded the Terraform distribution from the mirror, export the path to it to the
PATHenvironment variable:export PATH=$PATH:<path>Specify
<path>— the path to the Terraform binary file. -
Install Terraform. For Linux and macOS, follow the Install Terraform instructions in the HashiCorp documentation.
2. Create a service user
To work with the examples, you need to create a service user with two roles:
memberin the Account or Project scope — this role is required to initialize the Selectel provider and create resources. The scope affects available operations; you can view them in the member section of the Roles Reference guide;- and
iam.admin— to create additional users and manage access within projects.
-
In the control panel, click IAM in the top menu.
-
Go to the Service users section.
-
Click Add service user.
-
In the Service user details block:
4.1. Enter the username. It will be used for authorization.
4.2. Enter a password for the user or generate one. After creating the user, the password cannot be viewed — you can only change it. The password must be at least 20 characters long and contain at least:
- one uppercase and one lowercase Latin letter (
A-Z,a-z); - one digit (
0-9); - one special character from the ASCII Printable 7-Bit Special Characters list:
!"#$%&'()*+,-./:;<=>?@[]^_{|}~.
- one uppercase and one lowercase Latin letter (
-
In the Account access block:
5.1. Configure the permission for
iam.adminby selecting:5.2. Click Add permission.
5.3. Configure the permission for
memberby selecting:5.4. Optional: select a group for the user.
-
Click Add user. They will be added to the list on the Service users page. The account will be active immediately.
3. Configure providers
If the Selectel Terraform provider version in use is below 6.0.0, you can upgrade it. For more information, see the Upgrading Terraform Selectel Provider to version 6.0.0 guide on the Terraform Registry.
Selectel and OpenStack providers
Selectel provider
-
Make sure you have created a service user in the control panel
memberwith roles in the Account access scope andiam.admin. -
Create a directory to store configuration files and a separate file with the
.tfextension to configure providers. -
Add the Selectel and OpenStack providers to the file for provider configuration:
terraform {required_providers {selectel = {source = "selectel/selectel"version = "~> 7.1.0"}openstack = {source = "terraform-provider-openstack/openstack"version = "2.1.0"}}}Here
versionis the provider version. The current version can be found in the Selectel documentation (in Terraform Registry and GitHub) and OpenStack (in Terraform Registry and GitHub).For more information about products, services, and features that can be managed using providers, see the Selectel and OpenStack Providers guide.
-
Initialize the Selectel provider:
provider "selectel" {domain_name = "123456"username = "user"password = "password"auth_region = "ru-9"auth_url = "https://cloud.api.selcloud.ru/identity/v3/"}Where:
domain_name— Selectel account number. You can find it in the control panel in the top-right corner;username— the name of the service user with thememberrole in the Account access scope andiam.admin. You can view it in the control panel: in the top menu, click IAM → Service Users section (this section is only available to the account owner and users with theiam.adminrole);password— service user password. You can view it when creating the user or change it to a new one;auth_region— pool for authorization in theru-9format; do not use pools in theSPB-2format. The authorization pool might not match the pool in which you create resources. The list of available pools can be viewed in the guide Product availability by location.
-
Create a project:
resource "selectel_vpc_project_v2" "project_1" {name = "project"}See the detailed resource description for selectel_vpc_project_v2.
-
Create a service user for project access and assign the
memberrole in the Project access scope:resource "selectel_iam_serviceuser_v1" "serviceuser_1" {name = "username"password = "password"role {role_name = "member"scope = "project"project_id = selectel_vpc_project_v2.project_1.id}}Where:
-
username— user name; -
password— user password. The password must be at least 20 characters long and include at least:- one uppercase and one lowercase Latin letter (
A-Z,a-z); - one digit (
0-9); - one special character from the ASCII Printable 7-Bit Special Characters list:
!"#$%&'()*+,-./:;<=>?@[]^_{|}~;
- one uppercase and one lowercase Latin letter (
-
project_id— project ID. You can find it in the Control panel: in the top menu, click IAM → the Projects section → in the line of the required project, click .
View the detailed description of the resource selectel_iam_serviceuser_v1.
-
-
Initialize the OpenStack provider:
provider "openstack" {auth_url = "https://cloud.api.selcloud.ru/identity/v3"domain_name = "123456"tenant_id = selectel_vpc_project_v2.project_1.iduser_name = selectel_iam_serviceuser_v1.serviceuser_1.namepassword = selectel_iam_serviceuser_v1.serviceuser_1.passwordregion = "ru-9"}Where:
domain_name— Selectel account number. You can find it in the Control panel in the upper right corner;region— pool, for exampleru-9. All resources will be created in this pool. The list of available pools can be viewed in the guide Product availability by location.
-
If you create resources at the same time as configuring providers, add the
depends_onargument for OpenStack resources. For example, for the openstack_networking_network_v2 resource:resource "openstack_networking_network_v2" "network_1" {name = "private-network"admin_state_up = "true"depends_on = [selectel_vpc_project_v2.project_1,selectel_iam_serviceuser_v1.serviceuser_1]} -
Optional: if you want to use a mirror, create a separate Terraform CLI configuration file and add the following block to it:
provider_installation {network_mirror {url = "https://tf-proxy.selectel.ru/mirror/v1/"include = ["registry.terraform.io/*/*"]}direct {exclude = ["registry.terraform.io/*/*"]}}Learn more about mirror settings in the CLI Configuration File HashiCorp documentation.
-
Open the CLI.
-
Initialize the Terraform configuration in the directory:
terraform init -
Verify that the configuration files are syntactically correct:
terraform validate -
Format the configuration files:
terraform fmt -
Check which resources will be created:
terraform plan -
Apply the changes and create the resources:
terraform apply -
Confirm the creation: enter yes and press Enter. The created resources will be displayed in the Control panel.
-
If there are not enough quotas to create resources, increase quotas.