Create an alert contact using Terraform

Updated at:

Terraform is an open source tool that you can use to securely and efficiently provision and manage cloud infrastructure. You can use Terraform to manage Cloud Monitor resources. This topic describes how to use Terraform to create an alert contact for Cloud Monitor.

Note

You can run the sample code with a single click. Run with one click

Prerequisites

  • An Alibaba Cloud account has full permissions for all resources, which poses a high security risk if the credentials are leaked. We recommend that you use a Resource Access Management (RAM) user and create an AccessKey for the RAM user. For more information, see Create a RAM user and Create an AccessKey.

  • Grant the RAM user the AliyunCloudMonitorFullAccess permission to manage Cloud Monitor resources. For more information, see Manage RAM user permissions.

    {
        "Version": "1",
        "Statement": [
            {
                "Action": "cms:*",
                "Resource": "*",
                "Effect": "Allow"
            },
            {
                "Action": "arms:*",
                "Resource": "*",
                "Effect": "Allow"
            },
            {
                "Action": [
                    "ecs:DescribeInstances",
                    "rds:DescribeDBInstances",
                    "slb:DescribeLoadBalancer*",
                    "vpc:DescribeEipAddresses",
                    "vpc:DescribeRouterInterfaces",
                    "vpc:DescribeGlobalAccelerationInstances",
                    "vpc:DescribeVpnGateways",
                    "vpc:DescribeNatGateways",
                    "vpc:DescribeBandwidthPackages",
                    "vpc:DescribeCommonBandwidthPackages",
                    "oss:ListBuckets",
                    "log:ListProject",
                    "cdn:DescribeUserDomains",
                    "mns:ListQueue",
                    "mns:ListTopic",
                    "ess:DescribeScalingGroups",
                    "ocs:DescribeInstances",
                    "kvstore:DescribeInstances",
                    "kvstore:DescribeLogicInstanceTopology",
                    "hbase:DescribeClusterList",
                    "hitsdb:DescribeHiTSDBInstanceList",
                    "dds:DescribeDBInstances",
                    "petadata:DescribeInstances",
                    "petadata:DescribeDatabases",
                    "gpdb:DescribeDBInstances",
                    "emr:ListClusters",
                    "opensearch:ListApps",
                    "elasticsearch:ListInstance",
                    "mongodb:DescribeDBInstances",
                    "rds:DescribeReplicas",
                    "CloudAPI:DescribeApis",
                    "netgateway:DescribeNatGateways",
                    "ddos:DescribeInstancePage",
                    "live:DescribeLiveUserDomains",
                    "cen:DescribeCens",
                    "cen:DescribeCenAttachedChildInstances",
                    "kafka:GetKafkaInstanceList",
                    "scdn:DescribeScdnUserDomains",
                    "dcdn:DescribeDcdnUserDomains",
                    "polardb:DescribeDBInstances",
                    "polardb:DescribeRegions",
                    "polardb:DescribeDBClusters",
                    "cs:DescribeClusters",
                    "resourcemanager:GetAccount",
                    "resourcemanager:ListAccountsForParent",
                    "resourcemanager:ListAccounts",
                    "resourcemanager:GetFolder",
                    "resourcemanager:ListFoldersForParent",
                    "resourcemanager:ListAncestors",
                    "resourcemanager:GetResourceDirectory"
                ],
                "Resource": "*",
                "Effect": "Allow"
            },
            {
                "Action": [
                    "quotas:ListProductQuotas",
                    "quotas:GetProductQuota",
                    "quotas:ListProducts",
                    "quotas:ListProductQuotaDimensions",
                    "quotas:ListProductDimensionGroups"
                ],
                "Resource": "acs:quotas:*:*:*",
                "Effect": "Allow"
            },
            {
                "Action": "ram:CreateServiceLinkedRole",
                "Resource": "*",
                "Effect": "Allow",
                "Condition": {
                    "StringEquals": {
                        "ram:ServiceName": "cloudmonitor.aliyuncs.com"
                    }
                }
            }
        ]
    }
  • Prepare a Terraform runtime environment. You can use one of the following methods:

    Use Terraform in Terraform Explorer: Alibaba Cloud provides an online runtime environment for Terraform. You do not need to install Terraform. You can log on to use and test Terraform online. This method is suitable for scenarios where you want to quickly and easily test and debug Terraform at no cost.

    Cloud Shell: Alibaba Cloud Cloud Shell comes with pre-installed Terraform components and configured identity credentials. You can run Terraform commands directly in Cloud Shell. This method is suitable for scenarios where you want to quickly and easily access and use Terraform at a low cost.

    Install and configure Terraform locally: This method is suitable for scenarios with poor network connectivity or where a custom developer environment is required.

Important

Make sure that your Terraform version is v0.12.28 or later. To check the current version, run the terraform --version command.

Resources used

alicloud_cms_alarm_contact: Creates an alert contact.

Create an alert contact using Terraform

This example shows how to create an alert contact.

  1. Create a working directory and a configuration file named main.tf within it. The main.tf file is the main Terraform file that defines the resources to deploy.

    variable "region" {
      default = "cn-heyuan"
    }
    provider "alicloud" {
      region = var.region
    }
    variable "name" {
      default = "tf_example"
    }
    variable "describe" {
      default = "For example"
    }
    variable "mail" {
      default = "username@example.com"
    }
    resource "alicloud_cms_alarm_contact" "example" {
      # (Required, ForceNew) The name of the alert contact. The name must be 2 to 40 characters in length.
      alarm_contact_name = var.name
      # (Required) The description of the alert contact.
      describe           = var.describe
      # (Optional) The email address of the alert contact.
      channels_mail      = var.mail
      # channels_sms (Optional) The phone number of the alert contact.
      # channels_sms     =    "193****1234"
      # The email address is not effective until the activation link is clicked. Terraform detects a property difference in the current template. You can ignore this difference.
      lifecycle {
        ignore_changes = [channels_mail]
      }
    }
  2. Run the following command to initialize the Terraform runtime environment.

    terraform init

    The following output indicates that Terraform has been successfully initialized.

    Initializing the backend...
    
    Initializing provider plugins...
    - Finding latest version of hashicorp/alicloud...
    - Installing hashicorp/alicloud v1.234.0...
    - Installed hashicorp/alicloud v1.234.0 (signed by HashiCorp)
    
    Terraform has created a lock file .terraform.lock.hcl to record the provider
    selections it made above. Include this file in your version control repository
    so that Terraform can guarantee to make the same selections by default when
    you run "terraform init" in the future.
    
    Terraform has been successfully initialized!
    
    You may now begin working with Terraform. Try running "terraform plan" to see
    any changes that are required for your infrastructure. All Terraform commands
    should now work.
    
    If you ever set or change modules or backend configuration for Terraform,
    rerun this command to reinitialize your working directory. If you forget, other
    commands will detect it and remind you to do so if necessary.
  3. Create an execution plan and preview the changes.

    terraform plan
  4. Run the following command to create an alert contact.

    terraform apply

    When prompted during the execution, enter yes and press the Enter key. Wait for the command to complete. If the following information is displayed, the alert contact has been created.

    Plan: 1 to add, 0 to change, 0 to destroy.
    
    Do you want to perform these actions?
      Terraform will perform the actions described above.
      Only 'yes' will be accepted to approve.
    
      Enter a value: yes
    
    alicloud_cms_alarm_contact.example: Creating...
    alicloud_cms_alarm_contact.example: Creation complete after 1s [id=********]
    
    Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
  5. You can verify the result.

    Execute the terraform show command

    Run the following command to query the details of the resources created by Terraform:

    terraform show

    image

    Log on to the CloudMonitor console

    After the resource is created, you can view the alert contact in the Cloud Monitor console, or using OpenAPI or an SDK.image

Clean up resources

If you no longer need the resources that are created and managed by Terraform, you can run the following command to release them. For more information about terraform destroy, see Common commands.

terraform destroy

Complete example

Note

You can run the sample code with a single click. Run with one click

Sample code

variable "region" {
  default = "cn-heyuan"
}
provider "alicloud" {
  region = var.region
}
variable "name" {
  default = "tf_example"
}
variable "describe" {
  default = "For example"
}
variable "mail" {
  default = "username@example.com"
}
resource "alicloud_cms_alarm_contact" "example" {
  # (Required, ForceNew) The name of the alert contact. The name must be 2 to 40 characters in length.
  alarm_contact_name = var.name
  # (Required) The description of the alert contact.
  describe           = var.describe
  # (Optional) The email address of the alert contact.
  channels_mail      = var.mail
  # channels_sms (Optional) The phone number of the alert contact.
  # channels_sms     =    "193****1234"
  # The email address is not effective until the activation link is clicked. Terraform detects a property difference in the current template. You can ignore this difference.
  lifecycle {
    ignore_changes = [channels_mail]
  }
}

For more examples, go to the product folder in More complete examples.