Terraform provider for managing IncidentRelay configuration as code: access groups, users, teams, notification channels, alert routes, on-call rotations, escalation and notification policies, service catalog objects, silences, incident priority policies, maintenance windows, heartbeats, business services, Event Orchestration, reusable orchestration webhooks, and OIDC/SAML SSO.
The provider talks to the IncidentRelay HTTP API and supports both personal/API Bearer tokens and username/password login.
- Terraform 1.7+
- Go 1.22.5+ to build locally
- IncidentRelay API access with permissions for the resources you manage
The current provider code is tested against IncidentRelay 2.3. It supports the 2.3 alert-source set, including New Relic, Nagios, Azure Monitor, Cloud.ru, Uptime Kuma, and Datadog; Slack and Feishu/Lark channels; SSO profile-claim mapping; notification-policy filters; and the current Event Orchestration JSON DSL. The provider preserves API-masked channel, SSO, route, and orchestration webhook secrets during refresh so masking does not cause perpetual Terraform drift.
Operational Incidents and AlertGroups are runtime records rather than desired
infrastructure configuration, so the provider intentionally does not manage
their lifecycle as Terraform resources. Incident priority definitions remain
available through the incidentrelay_incident_priority data source.
terraform {
required_providers {
incidentrelay = {
source = "roxy-wi/incidentrelay"
version = "~> 0.7"
}
}
}
variable "incidentrelay_token" {
type = string
sensitive = true
}
provider "incidentrelay" {
base_url = "https://incidentrelay.example.com"
token = var.incidentrelay_token
}
resource "incidentrelay_group" "infra" {
slug = "infra"
name = "Infrastructure"
}
resource "incidentrelay_team" "platform" {
group_id = incidentrelay_group.infra.id
slug = "platform"
name = "Platform"
}Run:
export INCIDENTRELAY_TOKEN="..."
terraform init
terraform plan
terraform applyEnvironment variables are also supported:
INCIDENTRELAY_BASE_URLINCIDENTRELAY_TOKENINCIDENTRELAY_USERNAMEINCIDENTRELAY_PASSWORDINCIDENTRELAY_INSECURE_SKIP_TLS_VERIFY
Prefer INCIDENTRELAY_TOKEN for CI and automation. username and password
are useful for local development.
provider "incidentrelay" {
base_url = var.incidentrelay_base_url
username = var.incidentrelay_username
password = var.incidentrelay_password
}Set insecure_skip_tls_verify = true only for local development against a test
IncidentRelay instance with a self-signed certificate.
incidentrelay_groupincidentrelay_admin_userincidentrelay_group_membershipincidentrelay_sso_providerincidentrelay_sso_group_mappingincidentrelay_teamincidentrelay_team_membershipincidentrelay_channelincidentrelay_routeincidentrelay_rotationincidentrelay_rotation_layerincidentrelay_rotation_layer_memberincidentrelay_rotation_overrideincidentrelay_escalation_policyincidentrelay_escalation_policy_ruleincidentrelay_priority_policyincidentrelay_priority_policy_ruleincidentrelay_notification_policyincidentrelay_notification_policy_ruleincidentrelay_serviceincidentrelay_service_match_ruleincidentrelay_service_linkincidentrelay_service_runbookincidentrelay_service_dependencyincidentrelay_silenceincidentrelay_maintenance_windowincidentrelay_heartbeatincidentrelay_event_orchestrationincidentrelay_orchestration_webhook_actionincidentrelay_business_serviceincidentrelay_business_service_component
incidentrelay_versionincidentrelay_groupincidentrelay_teamincidentrelay_userincidentrelay_channelincidentrelay_serviceincidentrelay_rotationincidentrelay_incident_priorityincidentrelay_escalation_policyincidentrelay_notification_policyincidentrelay_service_match_rule
Nested API objects such as channel config, route matchers, service
labels, maintenance scopes, heartbeat metadata, orchestration rules,
and webhook headers are represented as validated JSON strings. This keeps the
provider compatible with IncidentRelay's nested DSLs without forcing every API
field into Terraform.
Channel config_json is marked sensitive because it can contain credentials.
Terraform still stores sensitive values in state, so use an encrypted remote
backend and restrict access to state files.
SSO client_secret and saml_sp_private_key are also marked sensitive. The
IncidentRelay API returns only flags indicating whether those secrets exist;
the provider preserves configured secret values during refresh.
Orchestration webhook url and headers_json are sensitive as well. Headers
are write-only, and URLs may be returned with embedded credentials redacted;
the provider preserves configured values in both cases.
Use jsonencode(...) for those fields:
matchers_json = jsonencode({
labels = {
service = "platform-api"
environment = "production"
}
})- Provider quickstart
- Authentication patterns
- Core on-call setup
- Service catalog
- Maintenance and silences
- Heartbeat monitoring
- IncidentRelay 1.2: Datadog and Slack Socket Mode
- IncidentRelay 2.0: Event Orchestration and Uptime Kuma
- IncidentRelay 2.3: Lark, Cloud.ru, SSO claims, and policy filters
- OIDC SSO and group mapping
- Data source lookups
- Terraform import blocks
- Provider docs
- Authentication guide
- Import guide
- JSON fields guide
- Modeling guide
- Resource reference
- Testing and release guide
make install-localThis installs the provider under:
~/.terraform.d/plugins/registry.terraform.io/roxy-wi/incidentrelay/0.7.0/<os>_<arch>/
See examples/provider/example.tf.
make fmt-check
make test-race
make buildThe CI workflow runs the same checks on pull requests and pushes to main.
Acceptance tests can be run against a live IncidentRelay instance:
export INCIDENTRELAY_ACC=1
export INCIDENTRELAY_BASE_URL="http://127.0.0.1:8080"
export INCIDENTRELAY_USERNAME="admin"
export INCIDENTRELAY_PASSWORD="change-me-123"
make test-accGitHub Actions also includes an Acceptance workflow that starts
IncidentRelay with Docker and runs this test layer. It tries to pull
ghcr.io/roxy-wi/incidentrelay:latest anonymously first, then retries after a
GHCR login with GITHUB_TOKEN. If GHCR is still unavailable, it builds the image
from roxy-wi/IncidentRelay@main on the runner and uses that local image.
The GitHub repository must be public and named terraform-provider-incidentrelay.
The release workflow builds Registry-compatible zip assets, adds
terraform-provider-incidentrelay_<version>_manifest.json, generates
terraform-provider-incidentrelay_<version>_SHA256SUMS, and signs checksums with
GPG.
The release workflow expects these GitHub Actions secrets, which are already
configured in the roxy-wi/terraform-provider-incidentrelay repository:
GPG_PRIVATE_KEY: ASCII-armored private key used only for provider releases.PASSPHRASE: passphrase for that key.
Add the corresponding ASCII-armored public key in Terraform Registry settings for
the roxy-wi namespace. Then create and push a semver tag:
git tag v0.7.0
git push origin v0.7.0After the GitHub release is published, use Terraform Registry's Publish > Provider flow and select roxy-wi/terraform-provider-incidentrelay.