Create and authorize image repositories using a Terraform module

Updated at:

Modules are the primary method for code reuse in Terraform. For more information about modules, see Basic terms. This topic describes how to use a Terraform module to quickly create a Container Registry namespace and image repositories, and to create and authorize a RAM user to access these repositories.

Background

Alibaba Cloud Container Registry (ACR) is a platform that provides secure hosting and efficient distribution for OCI-compliant artifacts, such as container images and Helm charts. It helps you manage the entire image lifecycle. For more information, see What is Alibaba Cloud Container Registry (ACR)? When your DevOps tools access an image repository on Alibaba Cloud, they must use an authorized Alibaba Cloud account.

Prerequisites

  • ACR is activated. For more information, see Billing of ACR.

  • Use a RAM user to complete the operations in this topic. Grant the AliyunRAMFullAccess and AliyunContainerRegistryFullAccess permissions to the RAM user. For more information, see Create a RAM user and Manage RAM user permissions.

  • The runtime environment for Terraform is prepared by using one of the following methods:

    • Terraform Explorer: Alibaba Cloud provides an online runtime environment for Terraform. You can log on to the environment and use Terraform without needing to install it. Suitable for scenarios where you need to use and debug Terraform in a low-cost, efficient, and convenient manner.

    • Create resources with Terraform: Cloud Shell is preinstalled with Terraform and configured with your identity credentials. You can run Terraform commands in Cloud Shell. Suitable for scenarios where you need to use and access Terraform in a low-cost, efficient, and convenient manner.

    • Install and configure Terraform on your on-premises machine: Suitable for scenarios where network connections are unstable or a custom development environment is needed.

Note

Some resources used in this tutorial incur charges. To avoid unwanted costs, release the resources when they are no longer needed.

Resources used

Procedure

  1. In a new working directory, create a configuration file named main.tf and copy the following code into the main.tf file.

    provider "alicloud" {}
    resource "random_integer" "default" {
      min = 10000
      max = 99999
    }
    module "cr" {
      source       = "roura356a/cr/alicloud"
      version      = "1.3.1"
      # The name of the namespace. 
      namespace    = "cr_repo_namespace_auto-${random_integer.default.result}"
      # The list of repositories to create and authorize.
      repositories = ["one", "two", "three"]
      # The logon password for the RAM user. Replace this with a strong password.
      password     = "YourPassword@123"
    }
  2. Run the following command to initialize the Terraform working directory.

    terraform init

    The following output indicates a successful initialization.

    Terraform has been successfully initialized!
    You may now begin working with Terraform. Try running "terraform plan" to see
    any changes that are required for your infrastructure. All Terraform commands
    should now work.
    If you ever set or change modules or backend configuration for Terraform,
    rerun this command to reinitialize your working directory. If you forget, other
    commands will detect it and remind you to do so if necessary.
  3. Run the following command to apply the configuration.

    terraform apply

    When prompted, enter yes and press Enter. Wait for the command to complete. The following output indicates that the resources are created.

    Important

    After the command runs successfully, it generates a file that contains the AccessKey in the current directory. Store this file securely to prevent credential leaks.

    module.cr.data.alicloud_account.current: Reading...
    module.cr.data.alicloud_regions.current: Reading...
    module.cr.data.alicloud_account.current: Read complete after 0s [id=*******]
    module.cr.data.alicloud_regions.current: Read complete after 0s [id=******]
    Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols:
      + create
    ...
    Do you want to perform these actions?
      Terraform will perform the actions described above.
      Only 'yes' will be accepted to approve.
      Enter a value: yes
    Apply complete! Resources: 4 added, 0 changed, 0 destroyed.
  4. Verify the results.

    Terraform show

    Run the following command to view the details of the created resources:

    terraform show
    shell@Alicloud:~/ram3$ terraform show
    # random_integer.default:
    resource "random_integer" "default" {
        id      = "xxx"
        max     = 99999
        min     = 10000
        result  = xxx
    }
    # module.cr.data.alicloud_account.current:
    data "alicloud_account" "current" {
        id = "xxx"
    }
    # module.cr.data.alicloud_regions.current:
    data "alicloud_regions" "current" {
        current = true
        id      = "xxx"
        ids     = [
            "cn-hangzhou",
        ]
        regions = [
            {
                id            = "cn-hangzhou"
                local_name    = "China (Hangzhou)"
                region_id     = "cn-hangzhou"
            },
        ]
    }
    
    # module.cr.alicloud_cr_namespace.default:
    resource "alicloud_cr_namespace" "default" {
        auto_create        = false
        default_visibility = "PUBLIC"
        id                 = "xxx"
        name               = "xxx"
    }
    
    # module.cr.alicloud_cr_repo.default:
    resource "alicloud_cr_repo" "default" {
        domain_list = {
            internal = "xxx"
            public   = "xxx"
            vpc      = "xxx"
        }
        id          = "xxx"
        name        = "xxx"
        namespace   = "xxx"
        repo_type   = "PUBLIC"
        summary     = "xxx"
    }
            },
        ]
    }
    # module.cr.alicloud_cr_namespace.registry_namespace:
    resource "alicloud_cr_namespace" "registry_namespace" {
        auto_create        = true
        default_visibility = "PRIVATE"
        id                 = "cr_repo_namespace_auto-xxx"
        name               = "cr_repo_namespace_auto-xxx"
    }
    # module.cr.alicloud_cr_repo.namespace_repositories[0]:
    resource "alicloud_cr_repo" "namespace_repositories" {
        detail      = null
        domain_list = {
            "internal" = "registry-internal.cn-hangzhou.aliyuncs.com"
            "public"   = "registry.cn-hangzhou.aliyuncs.com"
            "vpc"      = "registry-vpc.cn-hangzhou.aliyuncs.com"
        }
    }

    Verify in the console

    1. Log on to the ACR console. In the left-side navigation pane, click Instances and then click the Personal Edition instance. In the left-side navigation pane of the instance page, choose Repository > Repositories.

      The page displays three image repositories named three, two, and one. The repository type is Private and the status is Normal.

    2. Log on to the Resource Access Management (RAM) console. In the left-side navigation pane, choose Identities > Users. Click the User Logon Name/Display Name.

      A RAM user record is displayed in the user list. The logon name starts with cr_repo_namespace_auto, the display name is CR 'cr_repo_namespace_auto' Namespace User, and the description indicates that the user is for Container Registry.

    3. Click the Permissions tab.

      On the Personal Permissions sub-tab, a custom policy is displayed. The policy name is in the format cr_repo_namespace_auto-{namespace}-cr-policy. The description indicates that the policy grants push and pull permissions for the corresponding Container Registry namespace. The resource scope is Account Level.

Release resources

Run the following command to release the resources when you no longer need them. For more information about terraform destroy, see Common commands.

terraform destroy

References