forge_resource_credential (Resource)
A credential Forge uses to connect to one HTTP, PostgreSQL, MySQL, or Redis Resource. Forge keeps stored credential material server-side; clients and managed devices never receive it. The Resource must be assigned to a Resource Gateway before the credential can be used for routed traffic. Assignments select a credential in service account, user, group, then default order. If no assignment or default matches, Forge rejects the connection. It does not pass caller credentials through to the destination. Terraform 1.11 or newer is required.secret is write-only and sensitive, so
Terraform does not store its planned or state value. Supply it through a
sensitive ephemeral variable to keep the value out of saved plan configuration
too. To rotate the credential, increment secret_version and provide the
replacement secret in the same configuration change.
RDS and Aurora PostgreSQL or MySQL can instead use the Resource Gateway’s AWS
workload identity. This stores no database password:
aws_role_arn, the Gateway workload identity needs rds-db:connect
for the intended database user. With aws_role_arn, that role needs
rds-db:connect, while the Gateway identity needs sts:AssumeRole for the
exact role. Do not provide AWS access keys to Forge.
HTTP APIs can use OAuth 2.0 client credentials. The Gateway requests and caches
a short-lived bearer token only after Resource Policy and approval succeed:
secret_version at 1. Leave
secret unset and use version 1 until the next planned rotation.
Schema
Required
kind(String) Authentication method:username_passwordoraws_rds_iamfor PostgreSQL and MySQL,username_passwordfor Redis, andbearer_token,header,oauth2_client_credentials, oroauth2_token_exchangefor HTTP.name(String)resource_id(String) Resource that uses this credential.
Optional
default(Boolean) Use when no identity-specific credential is assigned. (default:false)aws_region(String) AWS Region foraws_rds_iam. The Gateway uses its AWS workload identity.aws_role_arn(String) Optional exact IAM role the Gateway assumes foraws_rds_iam.groups(Set of String) Group IDs assigned to this credential.header_name(String) Destination header name forheadercredentials.oauth_audience(String) Optional audience for OAuth client credentials or token exchange.oauth_client_id(String) OAuth client ID. Required for client credentials and optional for token exchange.oauth_scopes(Set of String) Optional scopes requested for OAuth client credentials or token exchange.oauth_token_endpoint(String) HTTPS token endpoint for OAuth client credentials or token exchange.secret(String, Sensitive, Write-only) Credential secret forusername_password,bearer_token,header, oroauth2_client_credentials. Required on create and whensecret_versionchanges for those methods.secret_version(Number) For stored-secret methods, increase this value and providesecretto rotate the credential. (default:1)service_accounts(Set of String) Service account IDs assigned to this credential.username(String) Destination username forusername_passwordoraws_rds_iam.users(Set of String) User IDs assigned to this credential.
Read-Only
id(String)management_mode(String) Where this credential is managed.manager_id(String) Terraform manager that owns this credential.manager_instance(String) Terraform workspace that owns this credential.