6 ms·
Could you share some of the issues you're experiencing with the provider? We've also hit some problems with the provider but worked around most of the issues in
by sorenmartius 4y ago
Could you share some of the issues you're experiencing with the provider? We've also hit some problems with the provider but worked around most of the issues in our open-source modules (eg, https://github.com/mineiros-io/terraform-github-repository https://github.com/mineiros-io/terraform-github-repository) and by using Terramate (eg, renaming repositories causes re-creation in the provider, with Terramate we're dynamically creating move statements to prevent this. Check out Terramate if you haven't done it yet: https://github.com/mineiros-io/terramate https://github.com/mineiros-io/terramate)
- nikolay 4y agoRegarding Terramate - I've reviewed it, it definitely is a better reincarnation of Terragrunt not using templating but HCL, yet, it does not solve all of our issues, so, we chose CDKTF for the glue code.
- sorenmartius 4y agoThe fundamental difference is that Terragrunt is a wrapper for Terraform, compared to Terramate, which generates native Terraform code that runs in all kinds of Terraform tooling such as CIs, etc. Also, Terramate adds new concepts such as eg change detection, which is helpful when building pipelines. Terramate may also be used together with Terragrunt. For details please see https://blog.mineiros.io/introducing-terramate-an-orchestrator-and-code-generator-for-terraform-5e538c9ee055?source=friends_link&sk=5272c487ef709c80a34d0b451590f263 https://blog.mineiros.io/introducing-terramate-an-orchestrat... and https://blog.mineiros.io/terramate-and-terragrunt-f27f2ec4032f?source=friends_link&sk=8834b3de00d4af4744aac63051ff3b53 https://blog.mineiros.io/terramate-and-terragrunt-f27f2ec403...
- nikolay 4y agoI didn't mean it behaves the same, but it accomplishes a similar goal. Definitely Terramate is the better tool and integrates with Terraform Cloud unlike Terragrunt.
- sorenmartius 4y agoThank you!
- sorenmartius 4y agoThanks for sharing those insights. I'd love to hear what kind of issues you managed to resolve with CDKTF compared to using HCL other than being more developer centric? I personally like CDKTF, but for me, it's still in a too early state of development to build a stable product on top.
- nikolay 4y agoOne example is the handling of dynamic providers. Imagine, instead of having the inventory of environments hardcoded in directory structure, you have them in a configuration setting. Or, another example, having a dynamic list of Kubernetes clusters, which you need to install Helm charts into, for which you need dynamic aliased Kubernetes providers.
- sorenmartius 4y agoInteresting - dynamic providers and configurations are exactly what we're doing with Terramate also. Seems like we're having a very similar approach while using different tooling. Thanks for sharing the insights with me!
- nikolay 4y agoI know you can do it - but not as dynamically as I want, too. Maybe I'm not getting something, but I don't see the `for_each` or `count` equivalent in `generate_hcl` [0]. Also, stacks are predefined, not dynamic. With CDKTF, I can generate any number of stacks with one piece of code. In addition, I can define stack dependencies - let's say, my dev database stack depends on dev IAM stack - something that Terraform does not do and developers need to remember the order of `terraform apply` across stacks. [0]: https://github.com/mineiros-io/terramate/blob/main/docs/codegen/generate-hcl.md https://github.com/mineiros-io/terramate/blob/main/docs/code...
- katcipis 4y agoOn the dynamic side of things we are working right now on adding support for dynamic block generation on generate_hcl, which should help. Regarding dependencies, did you took a look on the orchestration features on Terramate ? https://github.com/mineiros-io/terramate/blob/main/docs/orchestration.md https://github.com/mineiros-io/terramate/blob/main/docs/orch... They should be enough to let you easily define ordering and not depend on developers doing the ordering manually.
- nikolay 4y agoWell, there are a lot of open issues [0] with no outlook to get them ever closed. We've had issues with branch protection rules (the same code works with old actors in the state, but new actors erroring out without any reason), organization secrets, etc. [0]: https://github.com/integrations/terraform-provider-github/issues https://github.com/integrations/terraform-provider-github/is...