Create and authorize image repositories using a Terraform module
Modules are the primary method for code reuse in Terraform. For more information about modules, see Basic terms. This topic describes how to use a Terraform module to quickly create a Container Registry namespace and image repositories, and to create and authorize a RAM user to access these repositories.
Background
Alibaba Cloud Container Registry (ACR) is a platform that provides secure hosting and efficient distribution for OCI-compliant artifacts, such as container images and Helm charts. It helps you manage the entire image lifecycle. For more information, see What is Alibaba Cloud Container Registry (ACR)? When your DevOps tools access an image repository on Alibaba Cloud, they must use an authorized Alibaba Cloud account.
Prerequisites
ACR is activated. For more information, see Billing of ACR.
Use a RAM user to complete the operations in this topic. Grant the AliyunRAMFullAccess and AliyunContainerRegistryFullAccess permissions to the RAM user. For more information, see Create a RAM user and Manage RAM user permissions.
The runtime environment for Terraform is prepared by using one of the following methods:
Terraform Explorer: Alibaba Cloud provides an online runtime environment for Terraform. You can log on to the environment and use Terraform without needing to install it. Suitable for scenarios where you need to use and debug Terraform in a low-cost, efficient, and convenient manner.
Create resources with Terraform: Cloud Shell is preinstalled with Terraform and configured with your identity credentials. You can run Terraform commands in Cloud Shell. Suitable for scenarios where you need to use and access Terraform in a low-cost, efficient, and convenient manner.
Install and configure Terraform on your on-premises machine: Suitable for scenarios where network connections are unstable or a custom development environment is needed.
Some resources used in this tutorial incur charges. To avoid unwanted costs, release the resources when they are no longer needed.
Resources used
alicloud_cr_namespace: An ACR namespace.
alicloud_cr_repo: An image repository.
alicloud_ram_access_key: An AccessKey for a RAM user.
alicloud_ram_login_profile: The logon profile for a RAM user.
alicloud_ram_policy: A RAM policy.
alicloud_ram_user: A RAM user.
alicloud_ram_user_policy_attachment: A policy attachment for a RAM user.
Procedure
In a new working directory, create a configuration file named main.tf and copy the following code into the main.tf file.
provider "alicloud" {} resource "random_integer" "default" { min = 10000 max = 99999 } module "cr" { source = "roura356a/cr/alicloud" version = "1.3.1" # The name of the namespace. namespace = "cr_repo_namespace_auto-${random_integer.default.result}" # The list of repositories to create and authorize. repositories = ["one", "two", "three"] # The logon password for the RAM user. Replace this with a strong password. password = "YourPassword@123" }Run the following command to initialize the Terraform working directory.
terraform initThe following output indicates a successful initialization.
Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure. All Terraform commands should now work. If you ever set or change modules or backend configuration for Terraform, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary.Run the following command to apply the configuration.
terraform applyWhen prompted, enter
yesand press Enter. Wait for the command to complete. The following output indicates that the resources are created.ImportantAfter the command runs successfully, it generates a file that contains the AccessKey in the current directory. Store this file securely to prevent credential leaks.
module.cr.data.alicloud_account.current: Reading... module.cr.data.alicloud_regions.current: Reading... module.cr.data.alicloud_account.current: Read complete after 0s [id=*******] module.cr.data.alicloud_regions.current: Read complete after 0s [id=******] Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols: + create ... Do you want to perform these actions? Terraform will perform the actions described above. Only 'yes' will be accepted to approve. Enter a value: yes Apply complete! Resources: 4 added, 0 changed, 0 destroyed.Verify the results.
Terraform show
Run the following command to view the details of the created resources:
terraform showshell@Alicloud:~/ram3$ terraform show # random_integer.default: resource "random_integer" "default" { id = "xxx" max = 99999 min = 10000 result = xxx } # module.cr.data.alicloud_account.current: data "alicloud_account" "current" { id = "xxx" } # module.cr.data.alicloud_regions.current: data "alicloud_regions" "current" { current = true id = "xxx" ids = [ "cn-hangzhou", ] regions = [ { id = "cn-hangzhou" local_name = "China (Hangzhou)" region_id = "cn-hangzhou" }, ] } # module.cr.alicloud_cr_namespace.default: resource "alicloud_cr_namespace" "default" { auto_create = false default_visibility = "PUBLIC" id = "xxx" name = "xxx" } # module.cr.alicloud_cr_repo.default: resource "alicloud_cr_repo" "default" { domain_list = { internal = "xxx" public = "xxx" vpc = "xxx" } id = "xxx" name = "xxx" namespace = "xxx" repo_type = "PUBLIC" summary = "xxx" } }, ] } # module.cr.alicloud_cr_namespace.registry_namespace: resource "alicloud_cr_namespace" "registry_namespace" { auto_create = true default_visibility = "PRIVATE" id = "cr_repo_namespace_auto-xxx" name = "cr_repo_namespace_auto-xxx" } # module.cr.alicloud_cr_repo.namespace_repositories[0]: resource "alicloud_cr_repo" "namespace_repositories" { detail = null domain_list = { "internal" = "registry-internal.cn-hangzhou.aliyuncs.com" "public" = "registry.cn-hangzhou.aliyuncs.com" "vpc" = "registry-vpc.cn-hangzhou.aliyuncs.com" } }Verify in the console
Log on to the ACR console. In the left-side navigation pane, click and then click the Personal Edition instance. In the left-side navigation pane of the instance page, choose .
The page displays three image repositories named three, two, and one. The repository type is Private and the status is Normal.
Log on to the Resource Access Management (RAM) console. In the left-side navigation pane, choose . Click the User Logon Name/Display Name.
A RAM user record is displayed in the user list. The logon name starts with
cr_repo_namespace_auto, the display name is CR 'cr_repo_namespace_auto' Namespace User, and the description indicates that the user is for Container Registry.Click the Permissions tab.
On the Personal Permissions sub-tab, a custom policy is displayed. The policy name is in the format
cr_repo_namespace_auto-{namespace}-cr-policy. The description indicates that the policy grants push and pull permissions for the corresponding Container Registry namespace. The resource scope is Account Level.
Release resources
Run the following command to release the resources when you no longer need them. For more information about terraform destroy, see Common commands.
terraform destroyReferences
For an introduction to Terraform, see What is Alibaba Cloud Terraform?.
If the
terraform initcommand times out due to network latency or other issues and fails to download providers, see Configure an acceleration solution for Terraform Init.