clusternest_opensearch (Resource)
Example Usage
resource "clusternest_opensearch" "test" {
name = "logs"
tier = "standard"
organization_id = 123
auth_sources = [
{
name = "corp"
type = "oidc"
connect_url = "https://idp.example.com/.well-known/openid-configuration"
client_id = "opensearch"
client_secret = var.oidc_client_secret
dashboards_login = true
},
]
}
variable "oidc_client_secret" {
type = string
sensitive = true
}
data "clusternest_opensearch_credentials" "test" {
cluster_id = clusternest_opensearch.test.id
}
output "opensearch_url" {
value = clusternest_opensearch.test.url
}
output "username" {
value = data.clusternest_opensearch_credentials.test.username
}
output "password" {
value = data.clusternest_opensearch_credentials.test.password
sensitive = true
}
Schema
Required
name(String) Cluster name, unique within the organization. Lowercase letters, digits, and hyphens only.organization_id(Number) Organization the cluster is created in.
Optional
auth_sources(Attributes List) External identity providers (OpenID Connect or SAML) the cluster accepts logins from, alongside the built-in internal user. Omitted means none. (see below for nested schema)custom_hostname(String) Custom domain to serve the OpenSearch endpoint on, instead of the generated default hostname.dashboards_custom_hostname(String) Custom domain to serve OpenSearch Dashboards on, instead of the generated default hostname.dashboards_ip_allowlist(List of String) IP addresses or subnets allowed to reach OpenSearch Dashboards.data_node_count(Number) Number of data nodes in the cluster. Only Advanced tier supports more than 3 data nodes upto a maximum of 10.ip_allowlist(List of String) IP addresses or subnets allowed to reach the OpenSearch API.maintenance_window(Attributes) Weekly recurring window (UTC) during which maintenance may be performed on this cluster. Must be at least 2 hours (120 minutes) long. Leave unset to allow maintenance at any time. (see below for nested schema)repo_config(Attributes) S3 snapshot repository configuration for cluster backups. Leave unset to disable snapshots. (see below for nested schema)tier(String) Sizing/pricing tier the cluster runs at.version(String) OpenSearch version to run.
Read-Only
id(Number) Unique identifier of the cluster.opensearch_dashboards_url(String) URL of the OpenSearch Dashboards endpoint.url(String) URL of the OpenSearch endpoint.
Nested Schema for auth_sources
Required:
name(String) Identifies this source within the cluster. Lowercase letters, digits and hyphens, at most 32 characters. Must be unique within the cluster's auth_sources.type(String) Kind of identity provider: oidc (OpenID Connect) or saml. A cluster can have at most one saml source.
Optional:
audience(String) Audience the access token must be issued for, matched against the token's aud claim. Unset accepts a token minted for any audience by the identity provider. oidc sources only.ca_cert(String) Base64-encoded PEM CA bundle to trust when contacting the identity provider, for one behind a private CA.client_id(String) OAuth client ID registered with the identity provider. Optional, except for a source with dashboards_login. oidc sources only.client_secret(String, Sensitive) OAuth client secret registered with the identity provider. Required for an oidc source with dashboards_login. Write-only: the API never returns it, and Terraform keeps the configured value.connect_url(String) OpenID Connect discovery/well-known endpoint of the identity provider (https:// only). oidc sources only.dashboards_login(Boolean) Offer this source as a login option on OpenSearch Dashboards, next to the built-in internal user. At most one oidc source can enable it. Without it the source only authenticates direct API requests that carry a token from the identity provider. oidc sources only.idp_entity_id(String) Entity ID of the identity provider. saml sources only.idp_metadata_url(String) URL of the identity provider's SAML metadata document (https:// only). saml sources only.logout_url(String) URL to redirect to after logout, if any. oidc sources only.roles_key(String) Claim (oidc) or attribute (saml) whose values become the user's backend roles. Unset uses the default for the source type.scope(String) Space-separated OAuth scopes to request during login. oidc sources only.sp_entity_id(String) Entity ID this OpenSearch cluster identifies itself as to the identity provider. saml sources only.subject_key(String) Claim (oidc) or attribute (saml) to use as the OpenSearch username. Unset uses the default for the source type.
Nested Schema for maintenance_window
Required:
day_of_week(String) Day of the week the window recurs on, UTC.end_time(String) Before start_time means the window wraps past midnight into the next day (e.g. start_time='23:00', end_time='01:00' is a 2-hour window). Equal to start_time means the full 24 hours are available on day_of_week - distinct from leaving maintenance_window unset entirely, which means every day, any time.start_time(String) Start of the window, 24h "HH:MM", UTC.
Nested Schema for repo_config
Optional:
access_key_id(String) AWS access key ID. Required when enable_access_keys is true.enable_access_keys(Boolean) Authenticate snapshot backups to S3 via static access keys instead of an IAM role.enable_iam_role(Boolean) Authenticate snapshot backups to S3 via an IAM role instead of static access keys.secret_access_key(String, Sensitive) AWS secret access key. Required when enable_access_keys is true.
Read-Only:
aws_role_arn(String) ARN of the IAM role used for snapshot backups. Managed automatically when enable_iam_role is true.