Key concepts
After learning about template authoring, Terraform configuration directories, and the HashiCorp Configuration Language (HCL), this topic introduces the common terms and concepts you will use during the coding phase of the Terraform workflow.
Resource
A resource is a block of code that defines an infrastructure component, typically in a main.tf file. You declare a resource with the resource keyword, followed by a specific resource type and a custom name. The curly braces contain the arguments for configuring the resource.
resource "resource_type" "resource_name" {
# Specify arguments for the resource type
}
Terraform uses the resource type and resource name to identify an infrastructure element. The resource keyword identifies the code block as a component of your cloud infrastructure. The resource type alicloud_oss_bucket represents an Alibaba Cloud resource. The term resource is specific to Terraform and cannot be customized. The resource type varies based on the defined provider. example-bucket is the name of the resource within the current Terraform configuration.
resource "alicloud_oss_bucket" "example-bucket" {
bucket = "my-bucket-xxxx" # Specify a globally unique bucket name
}
The following example declares Alibaba Cloud as the provider and shows two Alibaba Cloud resource blocks: an OSS bucket and a vSwitch. The required arguments depend on the resource type. For the alicloud_oss_bucket resource, you only need to specify the bucket name to successfully create the resource. For the alicloud_vswitch resource, you must specify the ID of the VPC it belongs to (vpc_id), a CIDR block (cidr_block), and the availability zone (zone_id). Other arguments such as a name and tags are optional.
resource "alicloud_oss_bucket" "example-bucket" {
bucket = "my-bucket-xxxxx"
}
resource "alicloud_vswitch" "main_vswitch" {
vpc_id = "vpc-abc12345"
cidr_block = "10.0.1.0/24"
zone_id = "cn-hangzhou-k"
vswitch_name = "main-vswitch"
}
If your resources are complex and the configuration code is long, organize them into separate .tf files by resource type as a best practice. For example, configurations for ECS instance, OSS bucket, and database resources can be placed in instance.tf, oss.tf, and database.tf, respectively.
Provider
A provider implements each configurable resource type. Without a provider, Terraform cannot manage any type of infrastructure. Providers are typically defined in a providers.tf file, where you specify a terraform block containing the provider definition. When you declare a provider, Terraform automatically downloads its plugin when you run the init command.
terraform {
required_providers {
alicloud = {
source = "aliyun/alicloud"
version = "1.225.0"
}
}
}
provider "alicloud" {
# Configure your Alibaba Cloud credentials and region information
# For security, do not hardcode your Alibaba Cloud AccessKey and SecretKey in this file. Use environment variables or other secure methods instead:
# export ALICLOUD_ACCESS_KEY="<Your Alibaba Cloud AccessKey>"
# export ALICLOUD_SECRET_KEY="<Your Alibaba Cloud SecretKey>"
region = "cn-hangzhou"
}
A provider maps the APIs used to manage resources to Terraform resources, and it manages the interactions between resources and APIs. Provider configuration belongs to the root module of a Terraform configuration. alicloud is the local name of the provider you configure. To ensure the local name is configured correctly, you must include the provider in the required_providers block. The source argument specifies the provider's global source address. In the preceding example, source is set to aliyun/alicloud from the Terraform Registry. The version argument is optional but recommended. It constrains the provider to a specific version or version range to prevent Terraform from downloading a newer provider version that may include breaking changes. If you do not specify a version, Terraform automatically downloads the latest provider version during initialization.
For historical reasons, the Alibaba Cloud provider alicloud supports two source values: aliyun/alicloud and hashicorp/alicloud. Both sources point to identical implementations. For more information, see Terraform Overview.
Arguments such as access_key, secret_key, and region are specific to configuring the Alibaba Cloud provider. If the Terraform configuration does not include a provider block, Terraform assumes an empty default configuration, and Terraform sources access_key, secret_key, and region from environment variables by default. If the region is not specified in the environment variables, it defaults to cn-beijing. For more configuration arguments for the Alibaba Cloud provider, see the Provider Reference.
Variable
Variables parameterize your Terraform configuration. Input variables act as parameters for Terraform, allowing you to customize and share configurations without changing the source code. After you define a variable, you can set its value at runtime in several ways, such as through environment variables, CLI arguments, or key-value files. You can define resource attributes as key-value pairs at runtime or in a file with a .tfvars extension.
Variables let you easily separate attribute values from your configuration logic. In this example, main.tf declares a VPC, and the vpc_name attribute is declared as a variable in the variables.tf file. This parameterizes the attribute, allowing you to define its value at runtime or in a .tfvars file. For more information about variables, see Variables.
Output
The outputs.tf file defines the output values for your resources. Each resource instance managed by Terraform exposes attributes, and you can reference the values of these attributes elsewhere in your Terraform configuration. Output values let you expose this information as needed.
Some resource attributes are computed at creation time. For example, a resource endpoint or a vSwitch ID is generated when the resource is created. The computed vSwitch ID is required to create other resources, such as an ECS instance or an RDS instance. Outputs make this information accessible.
output "vswitch_id" {
value = alicloud_vswitch.main_vswitch.id
}
The label after the output keyword is the name, which must be a valid identifier. In the root module, Terraform displays this name to the user. In a child module, you can use this name to access the value. The value argument accepts an expression, and Terraform returns its result to the user.
# terraform apply
alicloud_vswitch.main_vswitch: Creating...
alicloud_vswitch.main_vswitch: Creation complete after 4s [id=vsw-bp1ev5ei73c7y5ib887v1]
Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
Outputs:
vswitch_id = "vsw-bp1ev5ei73c7y5ib887v1"
State
Terraform saves the state of the resources it manages in a state file. By default, the state file is stored locally, but it can also be stored remotely. In team collaboration scenarios, remote storage is often the preferred method.
{
"version": 4,
"terraform_version": "1.7.1",
"serial": 168,
"lineage": "46c0889c-f4ff-d1fd-2109-364f97e55c06",
"outputs": {
"vswitch_id": {
"value": "vsw-bp1ev5ei73c7y5ib887v1",
"type": "string"
}
},
"resources": [
{
"mode": "managed",
"type": "alicloud_vswitch",
"name": "main_vswitch",
"provider": "provider[\"registry.terraform.io/hashicorp/alicloud\"]",
"instances": [
{
"schema_version": 0,
"attributes": {
"availability_zone": "cn-hangzhou-k",
"cidr_block": "10.0.1.0/24",
"create_time": "2024-06-23T07:53:48Z",
"description": "",
"enable_ipv6": null,
"id": "vsw-bp1ev5ei73c7y5ib887v1",
...
Do not modify this file. It is created and updated automatically. If the state file is corrupted, Terraform may fail to run or may create duplicate resources. For more information about state, see State in Terraform.
Module
A Terraform module is a set of Terraform configuration files located in a single directory. Even a simple configuration in a single directory with one or more .tf files is a module. Modules are the primary way to reuse code in Terraform. You can reuse modules by specifying a source where Terraform can retrieve the code. The source can be local or remote. You can use open source modules from the HashiCorp Module Registry or create your own.
