Skip to main content

clusternest_opensearch (Resource)

Example Usage​

resource "clusternest_opensearch" "test" {
name = "logs"
tier = "standard"
organization_id = 123

auth_sources = [
{
name = "corp"
type = "oidc"
connect_url = "https://idp.example.com/.well-known/openid-configuration"
client_id = "opensearch"
client_secret = var.oidc_client_secret
dashboards_login = true
},
]
}

variable "oidc_client_secret" {
type = string
sensitive = true
}

data "clusternest_opensearch_credentials" "test" {
cluster_id = clusternest_opensearch.test.id
}

output "opensearch_url" {
value = clusternest_opensearch.test.url
}

output "username" {
value = data.clusternest_opensearch_credentials.test.username
}

output "password" {
value = data.clusternest_opensearch_credentials.test.password
sensitive = true
}

Schema​

Required​

  • name (String) Cluster name, unique within the organization. Lowercase letters, digits, and hyphens only.
  • organization_id (Number) Organization the cluster is created in.

Optional​

  • auth_sources (Attributes List) External identity providers (OpenID Connect or SAML) the cluster accepts logins from, alongside the built-in internal user. Omitted means none. (see below for nested schema)
  • custom_hostname (String) Custom domain to serve the OpenSearch endpoint on, instead of the generated default hostname.
  • dashboards_custom_hostname (String) Custom domain to serve OpenSearch Dashboards on, instead of the generated default hostname.
  • dashboards_ip_allowlist (List of String) IP addresses or subnets allowed to reach OpenSearch Dashboards.
  • data_node_count (Number) Number of data nodes in the cluster. Only Advanced tier supports more than 3 data nodes upto a maximum of 10.
  • ip_allowlist (List of String) IP addresses or subnets allowed to reach the OpenSearch API.
  • maintenance_window (Attributes) Weekly recurring window (UTC) during which maintenance may be performed on this cluster. Must be at least 2 hours (120 minutes) long. Leave unset to allow maintenance at any time. (see below for nested schema)
  • repo_config (Attributes) S3 snapshot repository configuration for cluster backups. Leave unset to disable snapshots. (see below for nested schema)
  • tier (String) Sizing/pricing tier the cluster runs at.
  • version (String) OpenSearch version to run.

Read-Only​

  • id (Number) Unique identifier of the cluster.
  • opensearch_dashboards_url (String) URL of the OpenSearch Dashboards endpoint.
  • url (String) URL of the OpenSearch endpoint.

Nested Schema for auth_sources​

Required:

  • name (String) Identifies this source within the cluster. Lowercase letters, digits and hyphens, at most 32 characters. Must be unique within the cluster's auth_sources.
  • type (String) Kind of identity provider: oidc (OpenID Connect) or saml. A cluster can have at most one saml source.

Optional:

  • audience (String) Audience the access token must be issued for, matched against the token's aud claim. Unset accepts a token minted for any audience by the identity provider. oidc sources only.
  • ca_cert (String) Base64-encoded PEM CA bundle to trust when contacting the identity provider, for one behind a private CA.
  • client_id (String) OAuth client ID registered with the identity provider. Optional, except for a source with dashboards_login. oidc sources only.
  • client_secret (String, Sensitive) OAuth client secret registered with the identity provider. Required for an oidc source with dashboards_login. Write-only: the API never returns it, and Terraform keeps the configured value.
  • connect_url (String) OpenID Connect discovery/well-known endpoint of the identity provider (https:// only). oidc sources only.
  • dashboards_login (Boolean) Offer this source as a login option on OpenSearch Dashboards, next to the built-in internal user. At most one oidc source can enable it. Without it the source only authenticates direct API requests that carry a token from the identity provider. oidc sources only.
  • idp_entity_id (String) Entity ID of the identity provider. saml sources only.
  • idp_metadata_url (String) URL of the identity provider's SAML metadata document (https:// only). saml sources only.
  • logout_url (String) URL to redirect to after logout, if any. oidc sources only.
  • roles_key (String) Claim (oidc) or attribute (saml) whose values become the user's backend roles. Unset uses the default for the source type.
  • scope (String) Space-separated OAuth scopes to request during login. oidc sources only.
  • sp_entity_id (String) Entity ID this OpenSearch cluster identifies itself as to the identity provider. saml sources only.
  • subject_key (String) Claim (oidc) or attribute (saml) to use as the OpenSearch username. Unset uses the default for the source type.

Nested Schema for maintenance_window​

Required:

  • day_of_week (String) Day of the week the window recurs on, UTC.
  • end_time (String) Before start_time means the window wraps past midnight into the next day (e.g. start_time='23:00', end_time='01:00' is a 2-hour window). Equal to start_time means the full 24 hours are available on day_of_week - distinct from leaving maintenance_window unset entirely, which means every day, any time.
  • start_time (String) Start of the window, 24h "HH:MM", UTC.

Nested Schema for repo_config​

Optional:

  • access_key_id (String) AWS access key ID. Required when enable_access_keys is true.
  • enable_access_keys (Boolean) Authenticate snapshot backups to S3 via static access keys instead of an IAM role.
  • enable_iam_role (Boolean) Authenticate snapshot backups to S3 via an IAM role instead of static access keys.
  • secret_access_key (String, Sensitive) AWS secret access key. Required when enable_access_keys is true.

Read-Only:

  • aws_role_arn (String) ARN of the IAM role used for snapshot backups. Managed automatically when enable_iam_role is true.