# Terraform

Costfluent publishes a Terraform provider and three modules on the public Terraform Registry. The registry holds the full reference for each; this page says what each is for and how they fit together.

## Before you start

<PlanAvailability feature="Terraform" plan="Optimize" />

- The provider authenticates with a Public API token; see [API authentication](/api/authentication). Give the token only the capabilities the configuration manages.
- Keep the token out of source control: pass it through the `COSTFLUENT_API_KEY` environment variable or a sensitive variable.

## The provider

[`costfluent/costfluent`](https://registry.terraform.io/providers/costfluent/costfluent/latest/docs) manages Costfluent objects as code: workspaces, connections, cost reports, dashboards, folders, budgets, cost alerts, segments and allocation rules. Data sources read workspaces, connections, cost data, cost summaries, anomalies and your plan's entitlements.

```hcl
terraform {
  required_providers {
    costfluent = {
      source = "costfluent/costfluent"
    }
  }
}

provider "costfluent" {
  # Reads COSTFLUENT_API_KEY. Optionally set a default workspace:
  # workspace = "wsp_example"
}
```

Pin a version in `required_providers`; the registry lists the current one.

## The cost-access modules

Each module creates, in your own cloud account, the read-only access Costfluent needs, so a connection can be set up in the same pipeline as the rest of your infrastructure:

- [`costfluent/cost-access/aws`](https://registry.terraform.io/modules/costfluent/cost-access/aws/latest): the IAM role Costfluent assumes and, in a management account, the cost export it reads.
- [`costfluent/cost-access/azure`](https://registry.terraform.io/modules/costfluent/cost-access/azure/latest): read access to one subscription's cost data.
- [`costfluent/cost-access/gcp`](https://registry.terraform.io/modules/costfluent/cost-access/gcp/latest): read access to one billing export.

The modules do not embed the Costfluent provider, so no Costfluent token enters your cloud pipeline unless you add one. To register the connection in the same run, combine a module with the provider's data sources and `costfluent_provider` resource, as each module's registry page shows. The provider pages describe the same access without Terraform: [AWS](/connect/aws), [Azure](/connect/azure), [Google Cloud](/connect/gcp).

## How it behaves

- The provider calls the Public API with your token, so it can do what the token's capabilities allow and nothing more.
- A change made in the product to an object Terraform manages shows up as drift on the next plan.

## Related

- [API authentication](/api/authentication)
- [API reference](/api)
- [Manage connections](/connect/manage-connections)
