Cover what Dokploy v0.30 added
build / build (push) Successful in 3m56s
release / release (push) Successful in 15m2s

Six new resources, all backed by endpoints that did not exist before v0.30.0
and verified end-to-end against a live v0.30.2 instance:

  dokploy_network         Docker networks, now first-class. Services attach
                          through network_ids, which is what deprecates
                          Compose's isolated_deployment upstream.
  dokploy_dns_provider    Cloudflare or Route53, so adding a domain creates
                          its DNS record.
  dokploy_vault_provider  Env values resolved from HashiCorp Vault, Infisical,
                          AWS, Doppler, Azure or Scaleway at deploy time, so
                          the secret never lands in Dokploy or in state.
  dokploy_schedule        Cron jobs in a container, a stack, or on a server.
  dokploy_volume_backup   Scheduled backups of a named volume — the companion
                          to a mount that persists.
  dokploy_libsql          The sixth managed database engine.

libsql.create is the strictest endpoint in the API: eleven keys required to
be present, several only meaningfully null, no generated service name, and it
returns `true` rather than the row. CreateDefaults and ListIDs absorb all
three so the resource behaves like every other database.

Also filled the gaps a field-by-field diff against the live schema turned up:
domain gains `enabled` (the v0.30.0 park-a-domain toggle), compose gains
create_env_file, icon and service_networks, application gains icon and
preview_require_collaborator_permissions, and mounts accept libsql.

DNS and vault credentials are masked by Dokploy on read, so `config` is
tagged noread and keeps the configured value, as the basic-auth password
already does.
This commit is contained in:
max-voitcov
2026-08-26 00:40:27 +03:00
parent 3ddce62647
commit 2d1caf6e73
23 changed files with 1297 additions and 12 deletions
+2 -2
View File
@@ -2,12 +2,12 @@
# generated by https://github.com/hashicorp/terraform-plugin-docs
page_title: "dokploy Provider"
description: |-
Manage Dokploy https://dokploy.com projects, environments, applications, compose stacks, databases and networking with Terraform.
Manage Dokploy https://dokploy.com projects, environments, applications, compose stacks, databases, Docker networks and networking with Terraform.
---
# dokploy Provider
Manage [Dokploy](https://dokploy.com) projects, environments, applications, compose stacks, databases and networking with Terraform.
Manage [Dokploy](https://dokploy.com) projects, environments, applications, compose stacks, databases, Docker networks and networking with Terraform.
+2
View File
@@ -78,6 +78,7 @@ Dokploy's `application.create` endpoint accepts only a handful of fields, so thi
- `gitlab_repository` (String) GitLab repository name.
- `health_check_swarm` (String) Docker Swarm health check configuration, as a JSON object.
- `heroku_version` (String) Heroku buildpack stack version.
- `icon` (String) Icon shown next to the service in the Dokploy UI.
- `is_preview_deployments_active` (Boolean) Build a preview deployment for each pull request.
- `is_static_spa` (Boolean) Serve a static build as a single-page application.
- `labels_swarm` (String) Docker Swarm service labels, as a JSON object.
@@ -99,6 +100,7 @@ Dokploy's `application.create` endpoint accepts only a handful of fields, so thi
- `preview_limit` (Number) Maximum number of concurrent preview deployments.
- `preview_path` (String) Base path for preview deployments.
- `preview_port` (Number) Container port exposed by preview deployments.
- `preview_require_collaborator_permissions` (Boolean) Only build previews for pull requests opened by users with repository collaborator permissions.
- `preview_wildcard` (String) Wildcard domain used to expose preview deployments.
- `publish_directory` (String) Directory served when `build_type` is `static`.
- `railpack_version` (String) Railpack version.
+3
View File
@@ -40,6 +40,7 @@ Set `compose_file` to manage the stack definition inline (with `source_type = "r
- `compose_file` (String) Inline Compose file contents. Used when `source_type` is `raw`.
- `compose_path` (String) Path to the Compose file within the repository.
- `compose_type` (String) Whether to run the stack with Docker Compose or Docker Swarm. Valid values: `docker-compose`, `stack`.
- `create_env_file` (Boolean) Write the environment variables to a `.env` file next to the Compose file.
- `custom_git_branch` (String) Branch to deploy for a custom Git remote.
- `custom_git_ssh_key_id` (String) SSH key used to clone a private custom Git remote.
- `custom_git_url` (String) Git remote URL, when `source_type` is `git`.
@@ -58,12 +59,14 @@ Set `compose_file` to manage the stack definition inline (with `source_type = "r
- `gitlab_path_namespace` (String) Full GitLab namespace path.
- `gitlab_project_id` (Number) Numeric GitLab project ID.
- `gitlab_repository` (String) GitLab repository name.
- `icon` (String) Icon shown next to the stack in the Dokploy UI.
- `isolated_deployment` (Boolean) Run the stack on its own isolated Docker network.
- `isolated_deployments_volume` (Boolean) Prefix volume names for isolated deployments. Retained for backwards compatibility.
- `owner` (String) GitHub repository owner.
- `randomize` (Boolean) Append a random suffix to service and volume names.
- `repository` (String) GitHub repository name.
- `server_id` (String) Remote server to deploy on. Omit to use the Dokploy host itself.
- `service_networks` (String) Per-service Docker network attachments, as a JSON object mapping each service name in the stack to an array of network IDs.
- `source_type` (String) Where the Compose file comes from. Valid values: `git`, `github`, `gitlab`, `bitbucket`, `gitea`, `raw`.
- `suffix` (String) Suffix appended to generated resource names.
- `trigger_type` (String) What triggers an automatic deployment. Valid values: `push`, `tag`.
+57
View File
@@ -0,0 +1,57 @@
---
# generated by https://github.com/hashicorp/terraform-plugin-docs
page_title: "dokploy_dns_provider Resource - dokploy"
subcategory: ""
description: |-
A DNS provider connection Dokploy uses to create records for domains automatically.
config is a JSON object whose shape depends on providerType:
# Cloudflare
config = jsonencode({ providerType = "cloudflare", apiToken = var.cloudflare_token })
# AWS Route53
config = jsonencode({
providerType = "route53"
accessKeyId = var.aws_access_key_id
secretAccessKey = var.aws_secret_access_key
})
~> Dokploy masks the credentials when reading a provider back, so Terraform keeps the value you configured. Drift in config is not detected.
---
# dokploy_dns_provider (Resource)
A DNS provider connection Dokploy uses to create records for domains automatically.
`config` is a JSON object whose shape depends on `providerType`:
```hcl
# Cloudflare
config = jsonencode({ providerType = "cloudflare", apiToken = var.cloudflare_token })
# AWS Route53
config = jsonencode({
providerType = "route53"
accessKeyId = var.aws_access_key_id
secretAccessKey = var.aws_secret_access_key
})
```
~> Dokploy masks the credentials when reading a provider back, so Terraform keeps the value you configured. Drift in `config` is not detected.
<!-- schema generated by tfplugindocs -->
## Schema
### Required
- `config` (String, Sensitive) Provider credentials as a JSON object, including the `providerType` discriminator.
- `name` (String) Name of the connection. Must be unique within the organization and may contain only letters, digits, `-` and `_`.
### Read-Only
- `created_at` (String) RFC 3339 timestamp of when the connection was created.
- `id` (String) Unique DNS provider identifier.
- `organization_id` (String) Organization that owns the connection.
- `provider_type` (String) Provider kind derived from `config`: `cloudflare` or `route53`.
+1
View File
@@ -30,6 +30,7 @@ Set exactly one of `application_id` or `compose_id`. When targeting a Compose st
- `custom_cert_resolver` (String) Traefik certificate resolver name, when `certificate_type` is `custom`.
- `custom_entrypoint` (String) Traefik entrypoint to bind, when not using the defaults.
- `domain_type` (String) What kind of target this domain points at. Valid values: `compose`, `application`, `preview`.
- `enabled` (Boolean) Whether the domain is served. Setting this to `false` removes the route from Traefik but keeps the certificate, path and middleware configuration intact, so the domain can be brought back without reconfiguring it.
- `forward_auth_enabled` (Boolean) Protect this domain with Dokploy's forward auth.
- `https` (Boolean) Serve the domain over HTTPS and redirect HTTP traffic to it.
- `internal_path` (String) Path the request is rewritten to before it reaches the container, defaults to `/`.
+70
View File
@@ -0,0 +1,70 @@
---
# generated by https://github.com/hashicorp/terraform-plugin-docs
page_title: "dokploy_libsql Resource - dokploy"
subcategory: ""
description: |-
A managed libSQL instance running on Dokploy.
~> Creating this resource provisions the service definition but does not start a deployment. Deploy it from the Dokploy UI or CLI.
~> Credentials are stored in Terraform state. Use a state backend with encryption at rest.
libSQL runs as a sqld server. A primary node owns the data; a replica node follows a primary named by sqld_primary_url.
---
# dokploy_libsql (Resource)
A managed libSQL instance running on Dokploy.
~> Creating this resource provisions the service definition but does **not** start a deployment. Deploy it from the Dokploy UI or CLI.
~> Credentials are stored in Terraform state. Use a state backend with encryption at rest.
libSQL runs as a `sqld` server. A `primary` node owns the data; a `replica` node follows a primary named by `sqld_primary_url`.
<!-- schema generated by tfplugindocs -->
## Schema
### Required
- `database_password` (String, Sensitive) Password for the database user.
- `database_user` (String) Database user to create.
- `docker_image` (String) libSQL server image to run, for example `ghcr.io/tursodatabase/libsql-server:latest`.
- `environment_id` (String) Environment this database belongs to.
- `name` (String) Display name of the database.
### Optional
- `app_name` (String) Unique Docker service name. Generated from `name` when omitted, because Dokploy's libSQL endpoint does not generate one. Changing it forces a new database.
- `command` (String) Override the container entrypoint command.
- `cpu_limit` (String) Hard CPU limit, for example `1`.
- `cpu_reservation` (String) Soft CPU reservation, for example `0.5`.
- `description` (String) Free-form description.
- `detach_dokploy_network` (Boolean) Detach the service from the shared `dokploy-network`.
- `enable_namespaces` (Boolean) Serve multiple logical databases from one instance through libSQL namespaces.
- `endpoint_spec_swarm` (String) Docker Swarm endpoint specification, as a JSON object.
- `env` (String) Environment variables in `KEY=value` format, one per line.
- `external_admin_port` (Number) Host port exposing the admin API.
- `external_grpc_port` (Number) Host port exposing the gRPC replication endpoint.
- `external_port` (Number) Host port exposing the HTTP API.
- `health_check_swarm` (String) Docker Swarm health check configuration, as a JSON object.
- `labels_swarm` (String) Docker Swarm service labels, as a JSON object.
- `memory_limit` (String) Hard memory limit, for example `512m`.
- `memory_reservation` (String) Soft memory reservation, for example `256m`.
- `mode_swarm` (String) Docker Swarm service mode, as a JSON object.
- `network_ids` (List of String) IDs of additional Docker networks to attach.
- `network_swarm` (String) Docker Swarm network attachments, as a JSON array.
- `placement_swarm` (String) Docker Swarm placement constraints, as a JSON object.
- `replicas` (Number) Number of replicas to run.
- `restart_policy_swarm` (String) Docker Swarm restart policy, as a JSON object.
- `rollback_config_swarm` (String) Docker Swarm rollback configuration, as a JSON object.
- `server_id` (String) Remote server to deploy on. Omit to use the Dokploy host itself.
- `sqld_node` (String) Role this node plays in a libSQL cluster. Valid values: `primary`, `replica`. Defaults to `primary`.
- `sqld_primary_url` (String) URL of the primary node, when `sqld_node` is `replica`.
- `stop_grace_period_swarm` (Number) Grace period in nanoseconds before a container is killed.
- `update_config_swarm` (String) Docker Swarm rolling update configuration, as a JSON object.
### Read-Only
- `application_status` (String) Current status reported by Dokploy: `idle`, `running`, `done` or `error`.
- `created_at` (String) RFC 3339 timestamp of when the database was created.
- `id` (String) Unique libSQL identifier.
+43
View File
@@ -0,0 +1,43 @@
---
# generated by https://github.com/hashicorp/terraform-plugin-docs
page_title: "dokploy_network Resource - dokploy"
subcategory: ""
description: |-
A Docker network managed by Dokploy.
Attach services to it with network_ids on dokploy_application, dokploy_compose and the database resources. Every service also joins the shared dokploy-network unless detach_dokploy_network is set.
~> Docker networks are immutable. Dokploy has no update endpoint, so changing any attribute replaces the network — which detaches the services currently using it until they redeploy.
---
# dokploy_network (Resource)
A Docker network managed by Dokploy.
Attach services to it with `network_ids` on `dokploy_application`, `dokploy_compose` and the database resources. Every service also joins the shared `dokploy-network` unless `detach_dokploy_network` is set.
~> Docker networks are immutable. Dokploy has no update endpoint, so changing any attribute replaces the network — which detaches the services currently using it until they redeploy.
<!-- schema generated by tfplugindocs -->
## Schema
### Required
- `name` (String) Name of the Docker network.
### Optional
- `attachable` (Boolean) Allow standalone containers to attach to an overlay network.
- `driver` (String) Network driver. Use `overlay` for multi-node Swarm clusters and `bridge` for a single host. Valid values: `bridge`, `overlay`.
- `enable_ipv4` (Boolean) Enable IPv4 address allocation.
- `enable_ipv6` (Boolean) Enable IPv6 address allocation.
- `internal` (Boolean) Isolate the network from external access.
- `ipam` (String) Custom IP address management, as a JSON object with `subnet`, `gateway` and `ipRange` keys. Leave unset to let Docker choose a subnet.
- `mtu` (Number) Maximum transmission unit for the network. Leave unset to use Docker's default.
- `server_id` (String) Remote server to create the network on. Omit to use the Dokploy host itself.
### Read-Only
- `created_at` (String) RFC 3339 timestamp of when the network was created.
- `id` (String) Unique network identifier.
- `organization_id` (String) Organization that owns the network.
+53
View File
@@ -0,0 +1,53 @@
---
# generated by https://github.com/hashicorp/terraform-plugin-docs
page_title: "dokploy_schedule Resource - dokploy"
subcategory: ""
description: |-
A cron job Dokploy runs on a schedule.
schedule_type selects where the command runs:
application — inside a running application container; set application_id.compose — inside one service of a Compose stack; set compose_id and service_name.server — on a remote server; set server_id.dokploy-server — on the Dokploy host itself.
~> A schedule targeting an application runs inside its container, so the container has to be running when the cron fires.
---
# dokploy_schedule (Resource)
A cron job Dokploy runs on a schedule.
`schedule_type` selects where the command runs:
* `application` — inside a running application container; set `application_id`.
* `compose` — inside one service of a Compose stack; set `compose_id` and `service_name`.
* `server` — on a remote server; set `server_id`.
* `dokploy-server` — on the Dokploy host itself.
~> A schedule targeting an application runs inside its container, so the container has to be running when the cron fires.
<!-- schema generated by tfplugindocs -->
## Schema
### Required
- `command` (String) Command to run.
- `cron_expression` (String) Standard five-field cron expression, for example `0 3 * * *`.
- `name` (String) Display name of the schedule.
### Optional
- `app_name` (String) Docker service name the schedule targets. Derived by Dokploy when omitted.
- `application_id` (String) Application this schedule belongs to.
- `compose_id` (String) Compose stack this schedule belongs to.
- `description` (String) Free-form description.
- `enabled` (Boolean) Whether the schedule is active.
- `schedule_type` (String) Where the command runs. Valid values: `application`, `compose`, `server`, `dokploy-server`. Defaults to `application`.
- `script` (String) Multi-line script to run instead of a single command.
- `server_id` (String) Server this schedule runs on.
- `service_name` (String) Service inside a Compose stack to run the command in.
- `shell_type` (String) Shell used to interpret the command. Valid values: `bash`, `sh`. Defaults to `bash`.
- `timezone` (String) IANA timezone the cron expression is evaluated in, for example `Europe/Berlin`.
### Read-Only
- `created_at` (String) RFC 3339 timestamp of when the schedule was created.
- `id` (String) Unique schedule identifier.
+55
View File
@@ -0,0 +1,55 @@
---
# generated by https://github.com/hashicorp/terraform-plugin-docs
page_title: "dokploy_vault_provider Resource - dokploy"
subcategory: ""
description: |-
An external secret manager Dokploy resolves environment variables from at deploy time.
Reference a secret from any env value with ${{vault.<scope>.<key>}}. The value is fetched when the deployment runs and is never stored in Dokploy — so rotating it in the vault takes effect on the next deploy with no Terraform change.
Supported providerType values: hashicorp (Vault/OpenBao), infisical, aws (Secrets Manager), doppler, azure (Key Vault) and scaleway.
config = jsonencode({
providerType = "hashicorp"
url = "https://vault.example.com"
token = var.vault_token
mount = "secret"
})
~> Dokploy masks the credentials when reading a provider back, so Terraform keeps the value you configured. Drift in config is not detected.
---
# dokploy_vault_provider (Resource)
An external secret manager Dokploy resolves environment variables from at deploy time.
Reference a secret from any `env` value with `${{vault.<scope>.<key>}}`. The value is fetched when the deployment runs and is never stored in Dokploy — so rotating it in the vault takes effect on the next deploy with no Terraform change.
Supported `providerType` values: `hashicorp` (Vault/OpenBao), `infisical`, `aws` (Secrets Manager), `doppler`, `azure` (Key Vault) and `scaleway`.
```hcl
config = jsonencode({
providerType = "hashicorp"
url = "https://vault.example.com"
token = var.vault_token
mount = "secret"
})
```
~> Dokploy masks the credentials when reading a provider back, so Terraform keeps the value you configured. Drift in `config` is not detected.
<!-- schema generated by tfplugindocs -->
## Schema
### Required
- `assignments` (String) JSON array scoping which projects or environments may resolve secrets from this provider. Pass `jsonencode([])` to leave it unscoped.
- `config` (String, Sensitive) Provider credentials as a JSON object, including the `providerType` discriminator.
- `name` (String) Name of the connection, unique within the organization.
### Read-Only
- `created_at` (String) RFC 3339 timestamp of when the connection was created.
- `id` (String) Unique vault provider identifier.
- `organization_id` (String) Organization that owns the connection.
- `provider_type` (String) Provider kind derived from `config`.
+52
View File
@@ -0,0 +1,52 @@
---
# generated by https://github.com/hashicorp/terraform-plugin-docs
page_title: "dokploy_volume_backup Resource - dokploy"
subcategory: ""
description: |-
A scheduled backup of a Docker volume to a configured dokploy_destination.
This is the counterpart to a dokploy_mount with type = "volume": the mount gives the volume a stable name, and this resource copies its contents off the host on a schedule.
Set exactly one of the *_id attributes to say which service owns the volume.
---
# dokploy_volume_backup (Resource)
A scheduled backup of a Docker volume to a configured `dokploy_destination`.
This is the counterpart to a `dokploy_mount` with `type = "volume"`: the mount gives the volume a stable name, and this resource copies its contents off the host on a schedule.
Set exactly one of the `*_id` attributes to say which service owns the volume.
<!-- schema generated by tfplugindocs -->
## Schema
### Required
- `cron_expression` (String) Standard five-field cron expression, for example `0 4 * * *`.
- `destination_id` (String) Backup destination (S3-compatible bucket) to upload to.
- `name` (String) Display name of the backup job.
- `prefix` (String) Path prefix inside the destination bucket, for example `backups/shop/`.
- `volume_name` (String) Name of the Docker volume to back up.
### Optional
- `app_name` (String) Docker service name that owns the volume. Derived by Dokploy when omitted.
- `application_id` (String) Application that owns the volume.
- `compose_id` (String) Compose stack that owns the volume.
- `enabled` (Boolean) Whether the backup schedule is active.
- `keep_latest_count` (Number) Number of backups to retain. Older ones are pruned.
- `libsql_id` (String) libSQL instance that owns the volume.
- `mariadb_id` (String) MariaDB instance that owns the volume.
- `mongo_id` (String) MongoDB instance that owns the volume.
- `mysql_id` (String) MySQL instance that owns the volume.
- `postgres_id` (String) PostgreSQL instance that owns the volume.
- `redis_id` (String) Redis instance that owns the volume.
- `service_name` (String) Service inside a Compose stack that owns the volume.
- `service_type` (String) The kind of service that owns the volume. Valid values: `application`, `postgres`, `mysql`, `mariadb`, `mongo`, `redis`, `compose`, `libsql`. Defaults to `application`.
- `turn_off` (Boolean) Stop the service while the backup runs. Slower, but guarantees a consistent copy of data that is being written to.
### Read-Only
- `created_at` (String) RFC 3339 timestamp of when the backup job was created.
- `id` (String) Unique volume backup identifier.