Skip to content

Setup Terraform Cloud account #3370

Description

@UlisesGascon

Based on the discussion in #3270 (comment). cc: @nodejs/build

I will need help to setup the Terraform Cloud Account for Node.js Org. This account will be used to create a Team in Terraform Cloud and provide access to individual accounts. Can you create the account using the *@iojs.org email?

Additional steps

  • Add my personal account to the team as well as Workspace Administrator level. This guide can help or I can do it if you share the credentials for Terraform Cloud
  • I will generate a token for the GitHub actions that will sync the terraform state

Activity

  1. mhdawson commented on May 26, 2023

    @mhdawson
    Member

    +1 with readonly access to start.

  2. targos commented on May 27, 2023

    @targos
    Member

    I created an account with the build email. Could be a good opportunity to start sharing build login credentials with 1Password

  3. targos commented on May 27, 2023

    @targos
    Member

    With the free tier, I can only add people as team owners. We would need at least the Standard plan to create additional teams. They say the first 500 resources per month are free, but I don't know what counts as a resource and if it will be enough for us.

  4. UlisesGascon commented on May 30, 2023

    @UlisesGascon
    MemberAuthor

    I love the idea to use 1password for this too. I believe 500 resources can cover our needs, but I will be sure once I got access to Cloudflare (#800).

    We can start with the free tier and see how critical is to move to the Standard plan, I believe the amount of users with direct access to terraform cloud will be very limited and probably admin compatible role.

  5. targos commented on May 31, 2023

    @targos
    Member

    @UlisesGascon What's your account's email address?

  6. UlisesGascon commented on May 31, 2023

    @UlisesGascon
    MemberAuthor

    My email is ulisesgascongonzalez@gmail.com. Thanks @targos ! :)

  7. UlisesGascon commented on May 31, 2023

    @UlisesGascon
    MemberAuthor

    It is working! Thanks a lot @targos 👍

  8. transferred this issue fromnodejs/adminon May 31, 2023
  9. targos commented on May 31, 2023

    @targos
    Member

    Reopening until the credentials have been somehow shared with @nodejs/build-infra

  10. reopened this on May 31, 2023
  11. UlisesGascon commented on Jun 12, 2023

    @UlisesGascon
    MemberAuthor

    There is no option to scope the Terraform Cloud. So any personal token might have access to all the workspaces in all the organizations as the user.

    I suggest to create an account with a build team email or another alias and generate the personal token from that account for the Github Actions part 🤔

  12. targos commented on Jun 12, 2023

    @targos
    Member

    create an account with a build team email or another alias

    Isn't it what this issue was about?

  13. UlisesGascon commented on Jun 13, 2023

    @UlisesGascon
    MemberAuthor

    Isn't it what this issue was about?

    Yes, that is correct. I expected to generate a token on behalf of the organization, but the current Terraform Cloud settings only allow me to generate tokens as myself. The next step will be to add a new member to the organization who is not a personal account and generate the token from that account. Is there a better way to manage this scenario?

  14. targos commented on Jun 13, 2023

    @targos
    Member

    The API Tokens page recommends to create Team Tokens for CI/CD. What's wrong with that?

  15. UlisesGascon commented on Jun 13, 2023

    @UlisesGascon
    MemberAuthor

    🤦 I didn't saw that in the UI. Thanks @targos!

    I created a team API Token and it is working as expected.
    Captura de pantalla 2023-06-13 a las 9 26 31

    I was not so sure about the expiration that we need, so I used a short one for now.

  16. targos commented on Jul 4, 2023

    @targos
    Member

    Reopening until the credentials have been somehow shared with https://github.com/orgs/nodejs/teams/build-infra

    Done in the secrets repo.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions