Terraform
Costfluent publishes a Terraform provider and three modules on the public Terraform Registry. The registry holds the full reference for each; this page says what each is for and how they fit together.
Before you start
Available on the Optimize and Scale plans. Compare plans
- The provider authenticates with a Public API token; see API authentication. Give the token only the capabilities the configuration manages.
- Keep the token out of source control: pass it through the
COSTFLUENT_API_KEYenvironment variable or a sensitive variable.
The provider
costfluent/costfluent manages Costfluent objects as code: workspaces, connections, cost reports, dashboards, folders, budgets, cost alerts, segments and allocation rules. Data sources read workspaces, connections, cost data, cost summaries, anomalies and your plan's entitlements.
Code
Pin a version in required_providers; the registry lists the current one.
The cost-access modules
Each module creates, in your own cloud account, the read-only access Costfluent needs, so a connection can be set up in the same pipeline as the rest of your infrastructure:
costfluent/cost-access/aws: the IAM role Costfluent assumes and, in a management account, the cost export it reads.costfluent/cost-access/azure: read access to one subscription's cost data.costfluent/cost-access/gcp: read access to one billing export.
The modules do not embed the Costfluent provider, so no Costfluent token enters your cloud pipeline unless you add one. To register the connection in the same run, combine a module with the provider's data sources and costfluent_provider resource, as each module's registry page shows. The provider pages describe the same access without Terraform: AWS, Azure, Google Cloud.
How it behaves
- The provider calls the Public API with your token, so it can do what the token's capabilities allow and nothing more.
- A change made in the product to an object Terraform manages shows up as drift on the next plan.