clusternest_prometheus (Resource)
Example Usage
resource "clusternest_prometheus" "test" {
name = "metrics"
tier = "standard"
organization_id = 123
# Optional: let your own identity provider authenticate directly against
# this cluster's Prometheus-compatible endpoint, alongside the static
# admin/readonly/write credentials below. Here, only a token whose "sub"
# claim matches grants push-only access - a broader, claims-free grant
# would give every token from this source that same access instead.
jwt_auth_sources = [
{
name = "idp"
issuer = "https://idp.example.com"
jwks_url = "https://idp.example.com/jwks"
grants = [
{ role = "write", claims = { sub = "remote-write-agent" } },
]
},
]
}
data "clusternest_prometheus_credentials" "test" {
cluster_id = clusternest_prometheus.test.id
}
output "prometheus_url" {
value = clusternest_prometheus.test.url
}
output "admin_password" {
value = data.clusternest_prometheus_credentials.test.admin
}
output "readonly_password" {
value = data.clusternest_prometheus_credentials.test.readonly
sensitive = true
}
output "write_password" {
value = data.clusternest_prometheus_credentials.test.write
sensitive = true
}
Schema
Required
name(String) Cluster name, unique within the organization. Lowercase letters, digits, and hyphens only.organization_id(Number) Organization the cluster is created in.
Optional
capacity_multiplier(Number) Scaling multiplier for cluster capacity. Values above 3 are only available on the advanced tier.custom_hostname(String) Custom domain to serve the Prometheus-compatible endpoint on, instead of the generated default hostname.ip_allowlist(List of String) IP addresses or subnets allowed to reach the Prometheus endpoint.jwt_auth_sources(Attributes List) Trusted JWT issuers that may authenticate directly against this cluster's Prometheus-compatible endpoint, each granted its own access level. (see below for nested schema)maintenance_window(Attributes) Weekly recurring window (UTC) during which maintenance may be performed on this cluster. Must be at least 2 hours (120 minutes) long. Leave unset to allow maintenance at any time. (see below for nested schema)retention_period(String) The following optional suffixes are supported: h (hour), d (day), w (week), y (year). If suffix isn't set, then the duration is counted in monthstier(String) Sizing/pricing tier the cluster runs at.version(String) Cortex version to run.
Read-Only
id(Number) Unique identifier of the cluster.url(String) URL of the Prometheus-compatible endpoint.
Nested Schema for jwt_auth_sources
Required:
grants(Attributes List) Access levels this source can grant. A token verified by this source receives every grant whose claims requirements it satisfies; its effective access is the union of those (e.g. a token matching both a write grant and a broader admin grant gets admin access). A grant with no claims matches any token this source verifies. (see below for nested schema)issuer(String) The trusted token issuer (the JWT'sissclaim).name(String) Identifies this source in the access-control list and in error logs. Must be unique within the cluster's list of sources.
Optional:
audiences(List of String) Allowedaudclaim values; a token matching any one of these is accepted. Empty means any audience is accepted.ca_cert(String) Base64-encoded PEM CA bundle to trust when fetching this source's JWKS/discovery document over TLS, replacing (not extending) the system trust store for that fetch only.jwks_url(String) Static JWKS endpoint (https:// only) to fetch signing keys from. Exactly one of jwks_url or oidc_discovery_url is required.oidc_discovery_url(String) OIDC discovery document URL (https:// only); its advertised JWKS endpoint is resolved once and used from then on. Exactly one of jwks_url or oidc_discovery_url is required.
Nested Schema for jwt_auth_sources.grants
Required:
role(String) Access level granted to a token matching this grant: admin (full access), readonly (read-only), or write (push-only).
Optional:
claims(Map of String) Claims a token must carry to receive this grant, as exact-match claim name -> required value pairs. The subject is just another claim here: match it with{"sub": "..."}. Omit to match any token verified by the source.
Nested Schema for maintenance_window
Required:
day_of_week(String) Day of the week the window recurs on, UTC.end_time(String) Before start_time means the window wraps past midnight into the next day (e.g. start_time='23:00', end_time='01:00' is a 2-hour window). Equal to start_time means the full 24 hours are available on day_of_week - distinct from leaving maintenance_window unset entirely, which means every day, any time.start_time(String) Start of the window, 24h "HH:MM", UTC.