Files
terraform-provider-dokploy/docs/resources/vault_provider.md
T
max-voitcov 2d1caf6e73
build / build (push) Successful in 3m56s
release / release (push) Successful in 15m2s
Cover what Dokploy v0.30 added
Six new resources, all backed by endpoints that did not exist before v0.30.0
and verified end-to-end against a live v0.30.2 instance:

  dokploy_network         Docker networks, now first-class. Services attach
                          through network_ids, which is what deprecates
                          Compose's isolated_deployment upstream.
  dokploy_dns_provider    Cloudflare or Route53, so adding a domain creates
                          its DNS record.
  dokploy_vault_provider  Env values resolved from HashiCorp Vault, Infisical,
                          AWS, Doppler, Azure or Scaleway at deploy time, so
                          the secret never lands in Dokploy or in state.
  dokploy_schedule        Cron jobs in a container, a stack, or on a server.
  dokploy_volume_backup   Scheduled backups of a named volume — the companion
                          to a mount that persists.
  dokploy_libsql          The sixth managed database engine.

libsql.create is the strictest endpoint in the API: eleven keys required to
be present, several only meaningfully null, no generated service name, and it
returns `true` rather than the row. CreateDefaults and ListIDs absorb all
three so the resource behaves like every other database.

Also filled the gaps a field-by-field diff against the live schema turned up:
domain gains `enabled` (the v0.30.0 park-a-domain toggle), compose gains
create_env_file, icon and service_networks, application gains icon and
preview_require_collaborator_permissions, and mounts accept libsql.

DNS and vault credentials are masked by Dokploy on read, so `config` is
tagged noread and keeps the configured value, as the basic-auth password
already does.
2026-08-26 00:40:27 +03:00

2.4 KiB

page_title, subcategory, description
page_title subcategory description
dokploy_vault_provider Resource - dokploy An external secret manager Dokploy resolves environment variables from at deploy time. Reference a secret from any env value with ${{vault.<scope>.<key>}}. The value is fetched when the deployment runs and is never stored in Dokploy — so rotating it in the vault takes effect on the next deploy with no Terraform change. Supported providerType values: hashicorp (Vault/OpenBao), infisical, aws (Secrets Manager), doppler, azure (Key Vault) and scaleway. config = jsonencode({ providerType = "hashicorp" url = "https://vault.example.com" token = var.vault_token mount = "secret" }) ~> Dokploy masks the credentials when reading a provider back, so Terraform keeps the value you configured. Drift in config is not detected.

dokploy_vault_provider (Resource)

An external secret manager Dokploy resolves environment variables from at deploy time.

Reference a secret from any env value with ${{vault.<scope>.<key>}}. The value is fetched when the deployment runs and is never stored in Dokploy — so rotating it in the vault takes effect on the next deploy with no Terraform change.

Supported providerType values: hashicorp (Vault/OpenBao), infisical, aws (Secrets Manager), doppler, azure (Key Vault) and scaleway.

config = jsonencode({
  providerType = "hashicorp"
  url          = "https://vault.example.com"
  token        = var.vault_token
  mount        = "secret"
})

~> Dokploy masks the credentials when reading a provider back, so Terraform keeps the value you configured. Drift in config is not detected.

Schema

Required

  • assignments (String) JSON array scoping which projects or environments may resolve secrets from this provider. Pass jsonencode([]) to leave it unscoped.
  • config (String, Sensitive) Provider credentials as a JSON object, including the providerType discriminator.
  • name (String) Name of the connection, unique within the organization.

Read-Only

  • created_at (String) RFC 3339 timestamp of when the connection was created.
  • id (String) Unique vault provider identifier.
  • organization_id (String) Organization that owns the connection.
  • provider_type (String) Provider kind derived from config.