API key support for Terraform provider
Currently the only automated way to create API keys is via the GraphQL API. While this can be made to work through custom scripting, if the remainder of the Spacelift configuration is done with terraform, it creates a disparity in overall system configuration.
The ability to configure API keys via terraform (both secret and OIDC) would allow for better consistently for teams who have strict requirements around manual changes to production deployment tooling and make it easier to implement long term sustainability with IAC around API tokens.
- Workaround
- Problem
Log in to comment and vote
Comments2
Jonah Kowall
Sep 23
This shipped. The Spacelift Terraform provider has a
spacelift_api_keyresource that manages both secret-based and OIDC-based API keys, including IdP group assignment: https://registry.terraform.io/providers/spacelift-io/spacelift/latest/docs/resources/api_keyOne thing to plan for: keys created this way are saved to the state file of the stack that manages them, so treat that state as sensitive.
Marking this completed. If something is missing for your setup, reply here and we will take a look.
Yellow Lamp
Jan 24, 2025
I also have a strong use case for having the ability to create specifically OIDC API keys. We already provision spacelift and attach to github repos in our automation and it would be nice to be able to create an OIDC API key scoped to the target repo. Currently we have to do this manually.