7 ms·
Terraform 0.7 released
- micah_chatt 10y agoTerraform seems like a great project, and the new import feature could nearly convince me to switch. My biggest barrier to using it is the lack of cross-account role support with AWS[0]. [0] https://github.com/aws/aws-sdk-go/issues/472 https://github.com/aws/aws-sdk-go/issues/472
- dfinninger 10y agoThat was a pretty big issue for us as well. We've gone through some acquisitions and we left with a bundle of different accounts. Wound up taking a day and writing a ruby script that checked out an STS token, and exec'ed a new bash shell with the correct environment variables. the $PS1 has the account name in there so it's not too hard to know what shell points where. Also helpful that we set up a "control account" that handles consolidated billing and user login. We've had some pretty good success so far, however I can definitely see how that feature would be good baked-in somehow.
- Rapzid 10y agoHoly cow, I did the exact same thing with the bash shell and the custom $PS1. That's crazy. The main difference is I just piggy backed off "aws s3 ls" and let it handle prompting for the MFA token and getting the temporary credentials.
- JimmyL 10y agoWe use https://github.com/atward/aws-profile/blob/master/aws-profile https://github.com/atward/aws-profile/blob/master/aws-profil... to do pretty much the same thing, although without the $PS1 hacking. Our rule is that a user's default profile should always be the "control account" (on which they have permission to do nothing except STS and AssumeRole), and that they need to use this wrapper and explicitly specify a profile for all "real" API commands. This also works nicely with MFA. Having this built into TF would be nice, but there are enough tools out there that don't support AWS role-jumping that I suspect we'll end up using that wrapper for a long time.
- micah_chatt 10y agoSuccess! The issue was just merged[0], hopefully this will make its way into TF soon. [0] https://github.com/aws/aws-sdk-go/issues/472#issuecomment-237342876 https://github.com/aws/aws-sdk-go/issues/472#issuecomment-23...
- AYBABTME 10y agoShameless plug: we use terraform a lot within DigitalOcean and I made a resource provider for our recent release of block storage. It's part of this release[1]! (I'm happy, sorry!) By the way, contributing to the project was very straightforward and the participants involved are super nice. I recommend you send them a patch if you have an itch! [1]: https://www.terraform.io/docs/providers/do/r/volume.html https://www.terraform.io/docs/providers/do/r/volume.html
- doh 10y agoI'm the most excited about the _List and Map Types_. It was a huge pain to concatenate strings in arrays to move them and then parse them again.
- Rapzid 10y agoHave you been able to find the docs on how to use them?! I turned up a few list methods in the interpolation docs, but didn't see how to actually compose a list. I'm still having to send module outputs as a space separated string then join(split( it into my IAM policies :|
- nivertech 10y agohttps://www.terraform.io/docs/configuration/variables.html https://www.terraform.io/docs/configuration/variables.html
- doh 10y agoPretty simple. # you don't need to state the list in here variable "test" { type = "list" default = ["test1", "test2"] } module "test_module" { test = "${var.test}" } # in module test_module variable "test" { type = "list" } # and now you can use it as ${var.test} Hopefully it helps
- deleted 10y ago[deleted]
- GrandTheftR 10y agoThis is a great release, have been using Terraform for the last year, a life-saver for us. Kudos to the TF team/community and Mitchell
- kdeldycke 10y agoThis release is the first one with built-in support for Scaleway as a provider: https://terraform.io/docs/providers/scaleway/ https://terraform.io/docs/providers/scaleway/
- jlgaddis 10y agoTerraform looks really nice although it seems it would be of limited use to me as most of my servers are physical. I do have a some VMs running on VMware, however. Anyone know what versions of vSphere are supported (I see it's been tested with 5.5 and 6.0, but I think we've still got a few older ones out there)?
- the_duke 10y agoFor others like me, who don't know Terraform: "Terraform is a tool for building, changing, and versioning infrastructure safely and efficiently. Terraform can manage existing and popular service providers as well as custom in-house solutions." https://www.terraform.io/ https://www.terraform.io/
- akramhussein 10y agoCan't praise Terraform enough. Just so well designed and a prevents you from ripping your hair out. Great team as well.
- _asummers 10y agoDoes anyone that has used Terraform have any major complaints about it, or conversely any specific praises for something it does well compared to other tools in that space?
- scrollaway 10y agoI haven't been using it very long but I'll go. My main complaints: - Very steep learning curve. It uses its own configuration language (HCL) which means you have new syntax to learn on top of its overwhelming API. - It's stateful, so you have a state file that you have to store and keep synchronized in your team. There's capabilities for storing the state remotely but it's very much not ideal. You seemingly can't generate that state file from scratch based on your current provider's state. - The templates are atrociously ugly and the string interpolation is limited, has extremely rough edges. - It's very much an 0.x product. I keep hitting bugs. EC2 machines don't destroy properly if they have mounted drives. S3 buckets can't be force-destroyed if they have versioning enabled. Some normalization issues here and there which cause constant changes to show up. - The custom format means the files aren't easily parsed and/or generated unless you're using hashicorp's own hcl go library. This sucks, to say the least. TOML with some conventions and jinja2 templating would have done the job just fine and would have been a ton more readable imho. It's still good software and design. I would definitely pick it up for new project, but I wouldn't bother migrating existing ones just yet unless you know you'll need it. I use it alongside Ansible and the two pair quite nicely.
- psadauskas 10y agoI agree with most of your points, but wanted to point out that Terraform also understands JSON for its config files, their HCL is just a simpler form. In one of my projects, I have most of the configs as .tf files, but another tool generates a bit of JSON (to update the ASG config after creating a new AMI) that Terraform incorporates into its plan.
- scrollaway 10y agoThat's true. More specifically (and if I understand hcl correctly), HCL is a superset of JSON which means JSON files are HCL files. (Source: https://github.com/hashicorp/hcl https://github.com/hashicorp/hcl) I still wish they'd gone with TOML :) They have good reasoning as to why not JSON/YAML, but those are the issues TOML actually solves and it's just so much more readable imho.
- akurilin 10y agoWhat are people's thoughts on Cloudformation vs Terraform for a project that only ever expects to use AWS?
- psadauskas 10y agoI found Terraform's config file syntax to be much simpler and understandable than Cloudformation's JSON. However, there are a couple edge-cases around some of AWS' newer services, such as Lambda, that didn't seem well-supported, as of a few months ago. If I was using Cloudformation, I probably would have written a tool 20% as complete as Terraform to generate the json from another config file, so I'm glad Terraform exists so that I didn't have to.
- mason55 10y agoWe ended up going with Terraform because it's much easier to handle more complicated use cases. When we were using Cloudformation stacks everything had to be done through hooking together JSON. I found that to do anything complex I needed to drop into a combination of Python with boto3 and Cloudformation anyway.
- lancefisher 10y agoI'm fairly new to both, and I initially setup some infrastructure with CloudFormation. I found it difficult to use and the JSON impossible to write by hand. You need to use a tool like their online editor to generate it - at least initially. It was also tough to extract identifiers to variables that can be changed outside the templates. I'm using Terraform now, and I like it much better. It has its own language for defining resources, but I find it very readable and easy to write by hand. My goal is to have my "infrastructure as code" so it can be tested in a sandbox and changes can be reviewed as pull requests. Going forward Terraform is my choice.
- Florin_Andrei 10y agoCloudFormation covers all AWS features in full detail. OTOH, you end up reading and editing tons and tons of JSON that were never meant for human consumption. I don't know what goals Amazon had when they came up with CF, but if human readability was one of them, then they've failed that goal. I've seen a lot of people start writing their own CF management systems, in Python or whatever, and end up with a lot of infrastructure defined in the logic of the homegrown management tool - like a badly written PHP page where presentation and logic are all mixed up. You see that once, you never want to go there again. Terraform does not cover all AWS features, but the exceptions are few and tend to be lesser used features. The file format is human readable (this is subjective to some extent), and can be composed and modularized easily. https://opencredo.com/terraform-infrastructure-design-patterns/ https://opencredo.com/terraform-infrastructure-design-patter... https://github.com/hashicorp/best-practices https://github.com/hashicorp/best-practices https://atlas.hashicorp.com/help/intro/use-cases/multiple-environments https://atlas.hashicorp.com/help/intro/use-cases/multiple-en... https://www.terraform.io/intro/getting-started/modules.html https://www.terraform.io/intro/getting-started/modules.html https://www.terraform.io/docs/state/remote/index.html https://www.terraform.io/docs/state/remote/index.html I'm not a big fan of buzzwords and soundbites, but Terraform comes pretty close to fulfilling the ideal of "software-defined infrastructure" in a way that is accessible, easy to use, easy to expand, and just makes sense - in the way a good programming language just makes sense.
- teajunky 10y agoDo I need AWS to use this tool? The company I work for operates its own data center.
- ominous_prime 10y agoTerraform isn't specific to AWS. You can see a list of the builtin providers here that may be useful: https://www.terraform.io/docs/providers/index.html https://www.terraform.io/docs/providers/index.html