AnkraDocs
Console

Tools

Terraform provider

Manage Ankra Cloud servers, storage, networks, routers, floating IPs and firewalls as code with the ankraio/ankracloud Terraform provider.

The ankraio/ankracloud provider manages Ankra Cloud resources through the same API as the console, with an API token. Every write that starts an operation waits for it to finish, so terraform apply returns once your infrastructure is really there.

Install#

The provider speaks plugin protocol 6 (Terraform 1.0 or later). Until it is published to the Terraform Registry, build it from the Ankra Cloud repository and point Terraform at the binary with a development override:

bash
cd terraform-provider-ankracloud
go build -o "$(go env GOPATH)/bin/terraform-provider-ankracloud" .
hcl
# ~/.terraformrc
provider_installation {
  dev_overrides {
    "ankraio/ankracloud" = "/Users/you/go/bin"
  }
  direct {}
}

With an override in place, skip terraform init for this provider and run terraform plan and apply directly.

Configure#

hcl
terraform {
  required_providers {
    ankracloud = {
      source = "ankraio/ankracloud"
    }
  }
}

provider "ankracloud" {
  endpoint = "https://cloud.ankra.app"   # or ANKRA_CLOUD_ENDPOINT
  token    = var.ankra_cloud_token       # or ANKRA_CLOUD_TOKEN
}
Argument Environment variable
endpoint ANKRA_CLOUD_ENDPOINT The API's base URL. Required.
token ANKRA_CLOUD_TOKEN An API token (act_…) whose user can operate resources. Required, sensitive.
certificate_authority_file ANKRA_CLOUD_CERTIFICATE_AUTHORITY A PEM file for a control plane with a privately signed certificate.

A value in the configuration wins over the environment. A token with the read scope can use the data sources, but every write answers 403.

Resources and data sources#

Type Notes
ankracloud_server IPv6-first: public_ipv6 (default true) gives a routed /64, exported as public_ipv6_prefix and public_ipv6_address; public_ipv4 (default false) adds the IPv4 add-on, exported as public_ipv4_address. Only power_state (running or stopped) changes in place; other changes replace the server. Destroying deletes the server with its storages.
ankracloud_storage In a zone that keeps one copy of every volume a storage without backup_rule is backed up daily by the zone (Terraform does not manage that schedule); acknowledge_single_copy_without_backup = true opts out and lets a configured backup_rule be removed there. title and backup_rule update in place; growing size_gibibytes resizes, shrinking replaces. source_storage_id clones, source_backup_id restores a backup, also from another zone.
ankracloud_network A private network. Every attribute replaces it.
ankracloud_router nat_enabled toggles the NAT gateway; network_ids is authoritative.
ankracloud_floating_ip Set server_id (and optionally target) to assign, unset it to unassign.
ankracloud_firewall The whole firewall of one server. Destroying it leaves the server with a disabled, accept-all firewall.
data.ankracloud_zones The zones.
data.ankracloud_plans Plans with cores, memory, included storage and monthly price.
data.ankracloud_templates Public templates and your custom images.

Writes accept a timeouts attribute, for example timeouts = { create = "45m" }. Every resource can be imported by its id (a firewall by its server's id):

bash
terraform import ankracloud_server.app <server-id>

Example#

An IPv6-only application server on a private network behind a NAT router, with a firewall and a data volume with nightly backups:

hcl
provider "ankracloud" {}

variable "ssh_public_key" {
  type = string
}

resource "ankracloud_network" "backend" {
  zone = "de-fsn1"
  name = "backend"
  cidr = "10.40.0.0/24"
}

resource "ankracloud_router" "edge" {
  zone        = "de-fsn1"
  name        = "edge"
  nat_enabled = true
  network_ids = [ankracloud_network.backend.id]
}

resource "ankracloud_server" "app" {
  zone     = "de-fsn1"
  hostname = "app-1"
  plan     = "premium-2c-4g"
  template = "debian-13"
  ssh_keys = [var.ssh_public_key]

  networks = [{
    network_id = ankracloud_network.backend.id
    address    = "10.40.0.20"
  }]

  depends_on = [ankracloud_router.edge]
}

resource "ankracloud_firewall" "app" {
  server_id        = ankracloud_server.app.id
  default_inbound  = "drop"
  default_outbound = "accept"

  rules = [
    { direction = "inbound", action = "accept", protocol = "tcp", port_start = 443, port_end = 443, comment = "https" },
    { direction = "inbound", action = "accept", protocol = "icmp" },
  ]
}

resource "ankracloud_storage" "data" {
  zone           = "de-fsn1"
  title          = "app data"
  tier           = "standard"
  size_gibibytes = 100

  backup_rule = {
    interval       = "daily"
    time           = "0230"
    retention_days = 14
  }
}

output "app_ipv6_address" {
  value = ankracloud_server.app.public_ipv6_address
}

Network edges, load balancers, databases and object storage are not Terraform resources yet; manage them with the API or the CLI's ankra-cloud api.