Skip to main content
The Terraform exporter generates the Terraform configuration of an environment set up from the Console. After you import the exported resources into a Terraform state, Terraform manages the environment.

What gets exported

The export contains a resource block for each of these:
  • The organization (qovery_organization), and all of its container registries, Helm repositories, labels groups and annotations groups.
  • The cluster of the environment (qovery_cluster) and its cloud credentials (qovery_aws_credentials, qovery_gcp_credentials, qovery_scaleway_credentials or qovery_eks_anywhere_vsphere_credentials). The provider has no resource for Azure credentials: an AKS cluster references its credentials through a qovery_azure_credentials data source.
  • The git tokens that the applications, jobs and Terraform services of the environment use (qovery_git_token).
  • The project, the environment and its deployment stages.
  • The services of the environment: applications, containers, jobs, Helm charts, Terraform services and databases, with their variables and secrets.
  • The services created from the service catalog, exported as the qovery_blueprint that manages them rather than as a Helm chart or a Terraform service. Each one comes with its own import block.
The export does not contain a qovery_deployment resource. Build settings are exported as build.* keys in advanced_settings_json, not as a build_settings block.

Export an environment

1

Open the export

In the Console, open the environment, click the Other actions menu (three dots) and select Export as Terraform. Only organization admins can export an environment.
2

Choose whether to include secrets

Turn on Export secrets to include the secret values in the export.
Exported secret values are written in plain text in variables.tf, and Terraform also stores them in its state. Do not commit either to version control, and keep the state in a protected backend.
3

Download

Click Export. The download is a zip file with two files:
  • main.tf: the provider configuration and the resources.
  • variables.tf: the input variables. qovery_access_token holds the API token of the provider. The other variables hold the secrets of the project, the environment, the services and the blueprints, the cloud credentials, the registry and Helm repository credentials, and the git tokens. With Export secrets on, each of them defaults to its value. Otherwise they have no default, and you set them yourself.

Import the exported resources

1

Set the input variables

The provider reads its token from the qovery_access_token variable:
Set the variables that have no default the same way, or in a terraform.tfvars file that you keep out of version control.
2

Initialize

3

Add an import block for every resource

In a new file, such as imports.tf, add an import block for every resource of main.tf, except the blueprints: main.tf already imports them, and a second import block for the same resource is an error. import blocks need Terraform 1.5 or later. Each resource is named after its kind, followed by z and the first eight characters of its ID. For example, the environment a1b2c3d4-… is qovery_environment.environment_za1b2c3d4.
imports.tf
The import ID is the resource ID for the organization, the project, the environment, the services, and the labels and annotations groups. It is <organization_id>,<resource_id> for the cloud credentials, the cluster, the container registries, the Helm repositories and the git tokens, and <environment_id>,<stage_name> for the deployment stages. The Registry page of each resource gives its format.
4

Review the plan

The plan lists every import. The Qovery API never returns secret values or the spec_overrides of blueprints, so the plan also sets them once from the configuration. For a blueprint that has secret variables or spec overrides, that apply redeploys its service. Apart from that, a complete import plans no change. Review any other change before you apply it: it is a difference between the exported configuration and Qovery.
5

Apply

Terraform records the imported resources in its state. You can then remove the import blocks.

After the import

Terraform now manages the exported resources: change them in the configuration, not in the Console. A change made from the Console shows up in the next terraform plan, and the next terraform apply reverts it. Secret values are the exception: the API never returns them, so a secret changed from the Console does not show up in the plan. See How the provider tracks changes. The export only describes the resources. To deploy the environment on terraform apply, add a qovery_deployment resource, as in the basic application example. Destroying that resource, or removing it from the configuration, deletes the environment and its services. Store the state in a remote backend so that your team shares it.

Next steps

Terraform Provider

Set up the provider

Basic Application

Deploy an environment with qovery_deployment

Terraform Registry

Reference of every resource and its import ID

Environment Variables

Variables and secrets