Skip to content

Repository files navigation

Terraform Provider for IncidentRelay

Terraform provider for managing IncidentRelay configuration as code: access groups, users, teams, notification channels, alert routes, on-call rotations, escalation and notification policies, service catalog objects, silences, incident priority policies, maintenance windows, heartbeats, business services, Event Orchestration, reusable orchestration webhooks, and OIDC/SAML SSO.

The provider talks to the IncidentRelay HTTP API and supports both personal/API Bearer tokens and username/password login.

Requirements

  • Terraform 1.7+
  • Go 1.22.5+ to build locally
  • IncidentRelay API access with permissions for the resources you manage

IncidentRelay Compatibility

The current provider code is tested against IncidentRelay 2.3. It supports the 2.3 alert-source set, including New Relic, Nagios, Azure Monitor, Cloud.ru, Uptime Kuma, and Datadog; Slack and Feishu/Lark channels; SSO profile-claim mapping; notification-policy filters; and the current Event Orchestration JSON DSL. The provider preserves API-masked channel, SSO, route, and orchestration webhook secrets during refresh so masking does not cause perpetual Terraform drift.

Operational Incidents and AlertGroups are runtime records rather than desired infrastructure configuration, so the provider intentionally does not manage their lifecycle as Terraform resources. Incident priority definitions remain available through the incidentrelay_incident_priority data source.

Quick Start

terraform {
  required_providers {
    incidentrelay = {
      source  = "roxy-wi/incidentrelay"
      version = "~> 0.7"
    }
  }
}

variable "incidentrelay_token" {
  type      = string
  sensitive = true
}

provider "incidentrelay" {
  base_url = "https://incidentrelay.example.com"
  token    = var.incidentrelay_token
}

resource "incidentrelay_group" "infra" {
  slug = "infra"
  name = "Infrastructure"
}

resource "incidentrelay_team" "platform" {
  group_id = incidentrelay_group.infra.id
  slug     = "platform"
  name     = "Platform"
}

Run:

export INCIDENTRELAY_TOKEN="..."
terraform init
terraform plan
terraform apply

Provider Configuration

Environment variables are also supported:

  • INCIDENTRELAY_BASE_URL
  • INCIDENTRELAY_TOKEN
  • INCIDENTRELAY_USERNAME
  • INCIDENTRELAY_PASSWORD
  • INCIDENTRELAY_INSECURE_SKIP_TLS_VERIFY

Prefer INCIDENTRELAY_TOKEN for CI and automation. username and password are useful for local development.

provider "incidentrelay" {
  base_url = var.incidentrelay_base_url
  username = var.incidentrelay_username
  password = var.incidentrelay_password
}

Set insecure_skip_tls_verify = true only for local development against a test IncidentRelay instance with a self-signed certificate.

Supported Resources

  • incidentrelay_group
  • incidentrelay_admin_user
  • incidentrelay_group_membership
  • incidentrelay_sso_provider
  • incidentrelay_sso_group_mapping
  • incidentrelay_team
  • incidentrelay_team_membership
  • incidentrelay_channel
  • incidentrelay_route
  • incidentrelay_rotation
  • incidentrelay_rotation_layer
  • incidentrelay_rotation_layer_member
  • incidentrelay_rotation_override
  • incidentrelay_escalation_policy
  • incidentrelay_escalation_policy_rule
  • incidentrelay_priority_policy
  • incidentrelay_priority_policy_rule
  • incidentrelay_notification_policy
  • incidentrelay_notification_policy_rule
  • incidentrelay_service
  • incidentrelay_service_match_rule
  • incidentrelay_service_link
  • incidentrelay_service_runbook
  • incidentrelay_service_dependency
  • incidentrelay_silence
  • incidentrelay_maintenance_window
  • incidentrelay_heartbeat
  • incidentrelay_event_orchestration
  • incidentrelay_orchestration_webhook_action
  • incidentrelay_business_service
  • incidentrelay_business_service_component

Supported Data Sources

  • incidentrelay_version
  • incidentrelay_group
  • incidentrelay_team
  • incidentrelay_user
  • incidentrelay_channel
  • incidentrelay_service
  • incidentrelay_rotation
  • incidentrelay_incident_priority
  • incidentrelay_escalation_policy
  • incidentrelay_notification_policy
  • incidentrelay_service_match_rule

Nested API objects such as channel config, route matchers, service labels, maintenance scopes, heartbeat metadata, orchestration rules, and webhook headers are represented as validated JSON strings. This keeps the provider compatible with IncidentRelay's nested DSLs without forcing every API field into Terraform.

Channel config_json is marked sensitive because it can contain credentials. Terraform still stores sensitive values in state, so use an encrypted remote backend and restrict access to state files.

SSO client_secret and saml_sp_private_key are also marked sensitive. The IncidentRelay API returns only flags indicating whether those secrets exist; the provider preserves configured secret values during refresh.

Orchestration webhook url and headers_json are sensitive as well. Headers are write-only, and URLs may be returned with embedded credentials redacted; the provider preserves configured values in both cases.

Use jsonencode(...) for those fields:

matchers_json = jsonencode({
  labels = {
    service     = "platform-api"
    environment = "production"
  }
})

Examples

Documentation

Local Installation

make install-local

This installs the provider under:

~/.terraform.d/plugins/registry.terraform.io/roxy-wi/incidentrelay/0.7.0/<os>_<arch>/

Example

See examples/provider/example.tf.

Development

make fmt-check
make test-race
make build

The CI workflow runs the same checks on pull requests and pushes to main.

Acceptance tests can be run against a live IncidentRelay instance:

export INCIDENTRELAY_ACC=1
export INCIDENTRELAY_BASE_URL="http://127.0.0.1:8080"
export INCIDENTRELAY_USERNAME="admin"
export INCIDENTRELAY_PASSWORD="change-me-123"
make test-acc

GitHub Actions also includes an Acceptance workflow that starts IncidentRelay with Docker and runs this test layer. It tries to pull ghcr.io/roxy-wi/incidentrelay:latest anonymously first, then retries after a GHCR login with GITHUB_TOKEN. If GHCR is still unavailable, it builds the image from roxy-wi/IncidentRelay@main on the runner and uses that local image.

Publishing to the Terraform Registry

The GitHub repository must be public and named terraform-provider-incidentrelay. The release workflow builds Registry-compatible zip assets, adds terraform-provider-incidentrelay_<version>_manifest.json, generates terraform-provider-incidentrelay_<version>_SHA256SUMS, and signs checksums with GPG.

The release workflow expects these GitHub Actions secrets, which are already configured in the roxy-wi/terraform-provider-incidentrelay repository:

  • GPG_PRIVATE_KEY: ASCII-armored private key used only for provider releases.
  • PASSPHRASE: passphrase for that key.

Add the corresponding ASCII-armored public key in Terraform Registry settings for the roxy-wi namespace. Then create and push a semver tag:

git tag v0.7.0
git push origin v0.7.0

After the GitHub release is published, use Terraform Registry's Publish > Provider flow and select roxy-wi/terraform-provider-incidentrelay.

Releases

Packages

Contributors

Languages