Six new resources, all backed by endpoints that did not exist before v0.30.0
and verified end-to-end against a live v0.30.2 instance:
dokploy_network Docker networks, now first-class. Services attach
through network_ids, which is what deprecates
Compose's isolated_deployment upstream.
dokploy_dns_provider Cloudflare or Route53, so adding a domain creates
its DNS record.
dokploy_vault_provider Env values resolved from HashiCorp Vault, Infisical,
AWS, Doppler, Azure or Scaleway at deploy time, so
the secret never lands in Dokploy or in state.
dokploy_schedule Cron jobs in a container, a stack, or on a server.
dokploy_volume_backup Scheduled backups of a named volume — the companion
to a mount that persists.
dokploy_libsql The sixth managed database engine.
libsql.create is the strictest endpoint in the API: eleven keys required to
be present, several only meaningfully null, no generated service name, and it
returns `true` rather than the row. CreateDefaults and ListIDs absorb all
three so the resource behaves like every other database.
Also filled the gaps a field-by-field diff against the live schema turned up:
domain gains `enabled` (the v0.30.0 park-a-domain toggle), compose gains
create_env_file, icon and service_networks, application gains icon and
preview_require_collaborator_permissions, and mounts accept libsql.
DNS and vault credentials are masked by Dokploy on read, so `config` is
tagged noread and keeps the configured value, as the basic-auth password
already does.
4.3 KiB
Changelog
All notable changes to this provider are documented here.
The format follows Keep a Changelog, and this project adheres to Semantic Versioning.
0.2.0 — 2026-08-26
Tracks Dokploy v0.30.x. Verified against a live v0.30.2 instance (597 API operations).
Fixed
-
dokploy_mountcould silently create a volume that never persisted anything. Atype = "volume"mount with novolume_namewas accepted by Dokploy and by this provider. Dokploy renders such a mount as{Source: "", Target: <mount_path>}, and Docker reads an empty source as an anonymous volume: every deploy created a brand-new volume and orphaned the previous one, so data never survived a redeploy and disk usage grew on every deployment.The provider now rejects that configuration at plan time, before anything is created, with an error explaining the consequence. The same check covers the two neighbouring cases —
type = "bind"withouthost_pathandtype = "file"withoutfile_path— and flags a field set for the wrongtype, which Dokploy would otherwise ignore silently.If you already have such a mount, add a
volume_name, apply, and redeploy the service. The data in the current anonymous volume is not migrated; copy it off first if you need it.
Added
New resources, all from Dokploy v0.30.0:
dokploy_network— Docker networks as first-class objects:bridgeoroverlay, withinternal,attachable, IPv4/IPv6,mtuand customipam. Docker networks are immutable, so every attribute forces replacement.dokploy_dns_provider— a Cloudflare or AWS Route53 connection that lets Dokploy create DNS records for domains automatically.dokploy_vault_provider— resolve environment variables from an external secret manager at deploy time with${{vault.<scope>.<key>}}. Supports HashiCorp Vault/OpenBao, Infisical, AWS Secrets Manager, Doppler, Azure Key Vault and Scaleway.dokploy_schedule— cron jobs running in an application container, a Compose service, a remote server, or on the Dokploy host.dokploy_volume_backup— scheduled backups of a Docker volume to adokploy_destination. The natural companion to a nameddokploy_mount.dokploy_libsql— the sixth managed database engine, withprimaryandreplicasqldnodes and libSQL namespaces.
New attributes on existing resources:
dokploy_domaingainsenabled, the v0.30.0 enable/disable toggle. It pulls a route out of Traefik while keeping certificates, paths and middleware intact, so a domain can be parked and restored without reconfiguring it.dokploy_composegainscreate_env_file,iconandservice_networks, which attaches individual services in a stack to specific Docker networks.dokploy_applicationgainsiconandpreview_require_collaborator_permissions.dokploy_mountanddokploy_volume_backupacceptlibsqlas aservice_type.
Changed
network_idsanddetach_dokploy_networkare now documented as the supported way to control service networking. Compose'sisolated_deploymentis deprecated upstream in v0.30.0 — attaching networks per service covers the same ground and survives restarts. The attribute still exists and still works; prefernetwork_idsfor new configurations.
Notes
- Dokploy's
libsql.createrequires eleven keys to be present even when null is the only sensible value, and does not generate a service name. The provider fills both in, soapp_namestays optional as it is for every other database. configondokploy_dns_provideranddokploy_vault_provideris masked by Dokploy on read. Terraform keeps the value you configured and does not detect drift in those credentials.
0.1.0 — 2026-08-09
Initial release. Projects, environments, applications, Compose stacks, five
managed databases (PostgreSQL, MySQL, MariaDB, MongoDB, Redis), domains,
mounts, ports, redirects, basic auth, registries, SSH keys, certificates and
backup destinations, plus five data sources and a web-service module.