Skip to main content

clusternest_prometheus (Resource)

Example Usage​

resource "clusternest_prometheus" "test" {
name = "metrics"
tier = "standard"
organization_id = 123

# Optional: let your own identity provider authenticate directly against
# this cluster's Prometheus-compatible endpoint, alongside the static
# admin/readonly/write credentials below. Here, only a token whose "sub"
# claim matches grants push-only access - a broader, claims-free grant
# would give every token from this source that same access instead.
jwt_auth_sources = [
{
name = "idp"
issuer = "https://idp.example.com"
jwks_url = "https://idp.example.com/jwks"
grants = [
{ role = "write", claims = { sub = "remote-write-agent" } },
]
},
]
}

data "clusternest_prometheus_credentials" "test" {
cluster_id = clusternest_prometheus.test.id
}

output "prometheus_url" {
value = clusternest_prometheus.test.url
}

output "admin_password" {
value = data.clusternest_prometheus_credentials.test.admin
}

output "readonly_password" {
value = data.clusternest_prometheus_credentials.test.readonly
sensitive = true
}

output "write_password" {
value = data.clusternest_prometheus_credentials.test.write
sensitive = true
}

Schema​

Required​

  • name (String) Cluster name, unique within the organization. Lowercase letters, digits, and hyphens only.
  • organization_id (Number) Organization the cluster is created in.

Optional​

  • capacity_multiplier (Number) Scaling multiplier for cluster capacity. Values above 3 are only available on the advanced tier.
  • custom_hostname (String) Custom domain to serve the Prometheus-compatible endpoint on, instead of the generated default hostname.
  • ip_allowlist (List of String) IP addresses or subnets allowed to reach the Prometheus endpoint.
  • jwt_auth_sources (Attributes List) Trusted JWT issuers that may authenticate directly against this cluster's Prometheus-compatible endpoint, each granted its own access level. (see below for nested schema)
  • maintenance_window (Attributes) Weekly recurring window (UTC) during which maintenance may be performed on this cluster. Must be at least 2 hours (120 minutes) long. Leave unset to allow maintenance at any time. (see below for nested schema)
  • retention_period (String) The following optional suffixes are supported: h (hour), d (day), w (week), y (year). If suffix isn't set, then the duration is counted in months
  • tier (String) Sizing/pricing tier the cluster runs at.
  • version (String) Cortex version to run.

Read-Only​

  • id (Number) Unique identifier of the cluster.
  • url (String) URL of the Prometheus-compatible endpoint.

Nested Schema for jwt_auth_sources​

Required:

  • grants (Attributes List) Access levels this source can grant. A token verified by this source receives every grant whose claims requirements it satisfies; its effective access is the union of those (e.g. a token matching both a write grant and a broader admin grant gets admin access). A grant with no claims matches any token this source verifies. (see below for nested schema)
  • issuer (String) The trusted token issuer (the JWT's iss claim).
  • name (String) Identifies this source in the access-control list and in error logs. Must be unique within the cluster's list of sources.

Optional:

  • audiences (List of String) Allowed aud claim values; a token matching any one of these is accepted. Empty means any audience is accepted.
  • ca_cert (String) Base64-encoded PEM CA bundle to trust when fetching this source's JWKS/discovery document over TLS, replacing (not extending) the system trust store for that fetch only.
  • jwks_url (String) Static JWKS endpoint (https:// only) to fetch signing keys from. Exactly one of jwks_url or oidc_discovery_url is required.
  • oidc_discovery_url (String) OIDC discovery document URL (https:// only); its advertised JWKS endpoint is resolved once and used from then on. Exactly one of jwks_url or oidc_discovery_url is required.

Nested Schema for jwt_auth_sources.grants​

Required:

  • role (String) Access level granted to a token matching this grant: admin (full access), readonly (read-only), or write (push-only).

Optional:

  • claims (Map of String) Claims a token must carry to receive this grant, as exact-match claim name -> required value pairs. The subject is just another claim here: match it with {"sub": "..."}. Omit to match any token verified by the source.

Nested Schema for maintenance_window​

Required:

  • day_of_week (String) Day of the week the window recurs on, UTC.
  • end_time (String) Before start_time means the window wraps past midnight into the next day (e.g. start_time='23:00', end_time='01:00' is a 2-hour window). Equal to start_time means the full 24 hours are available on day_of_week - distinct from leaving maintenance_window unset entirely, which means every day, any time.
  • start_time (String) Start of the window, 24h "HH:MM", UTC.