Terraform
The official Casdoor Terraform provider manages the objects of a Casdoor server as code, so that the configuration can be reviewed, versioned, and applied to several environments.
- Terraform Registry:
casdoor/casdoor - GitHub repository: casdoor/terraform-provider-casdoor
It works with Terraform and OpenTofu.
Resources
| Resource | Casdoor object | Import ID |
|---|---|---|
casdoor_organization | Organization | name |
casdoor_application | Application, with its providers | name |
casdoor_user | User | organization/name |
casdoor_provider | Provider | owner/name |
casdoor_cert | Cert | owner/name |
casdoor_role | Role | organization/name |
casdoor_permission | Permission | organization/name |
casdoor_group | Group | organization/name |
The owner of a provider or cert is admin for a global object shared by all organizations, or the name of an organization.
Configure the provider
The provider calls the Casdoor API as an application, using its client ID and client secret. To manage every organization, use an application of the built-in organization, e.g. app-built-in: open Applications → app-built-in in the Casdoor UI and copy its Client ID and Client secret.
terraform {
required_providers {
casdoor = {
source = "casdoor/casdoor"
}
}
}
provider "casdoor" {
endpoint = "https://door.casdoor.com"
client_id = var.casdoor_client_id
client_secret = var.casdoor_client_secret
}
The settings can also be passed with the CASDOOR_ENDPOINT, CASDOOR_CLIENT_ID and CASDOOR_CLIENT_SECRET environment variables, which keeps the secret out of the configuration:
export CASDOOR_ENDPOINT=https://door.casdoor.com
export CASDOOR_CLIENT_ID=<client ID>
export CASDOOR_CLIENT_SECRET=<client secret>
terraform init