# Resources and data sources

[View in Terraform Registry](https://registry.terraform.io/providers/aziontech/azion/latest/docs)

The Azion Terraform Provider v2.0 configures the Azion Platform with two kinds of block. A resource creates, updates, and deletes an object on Azion, and a data source queries information about objects that already exist. A singular name such as `azion_workload` is often both a resource and the data source that reads one object, and its plural, `azion_workloads`, is the data source that lists them.

Each section below covers one product: its resources, its data sources, and a configuration block that uses them. Every name links its Terraform Registry page.

---

## Workloads

These resources and data sources manage workloads and their deployments. For more information, refer to [Workloads resources](/en/documentation/devtools/terraform/workloads/).

| Resource                                                                                                                         | Description                                |
| -------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| [`azion_workload`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/workload)                       | Creates and manages a workload.            |
| [`azion_workload_deployment`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/workload_deployment) | Creates and manages a workload deployment. |

| Data source                                                                                                                           | Description                 |
| ------------------------------------------------------------------------------------------------------------------------------------- | --------------------------- |
| [`azion_workloads`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/workloads)                       | Lists workloads.            |
| [`azion_workload`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/workload)                         | Reads one workload.         |
| [`azion_workload_deployments`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/workload_deployments) | Lists workload deployments. |
| [`azion_workload_deployment`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/workload_deployment)   | Reads one deployment.       |

This block creates a workload and a deployment of it, then queries the existing workloads:

```hcl
# Create a workload
resource "azion_workload" "example" {
  name = "my-workload"
  
  application_id = azion_application_main_setting.app.id
  
  active = true
}

# Create a deployment
resource "azion_workload_deployment" "example" {
  workload_id = azion_workload.example.id
  
  active = true
}

# Query existing workloads
data "azion_workloads" "all" {}
```

---

## Connectors

These resources and data sources manage connectors, which link an application to an external origin. For more information, refer to [Connectors resources](/en/documentation/devtools/terraform/connectors/).

| Resource                                                                                                     | Description                      |
| ------------------------------------------------------------------------------------------------------------ | -------------------------------- |
| [`azion_connector`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/connector) | Creates and manages a connector. |

| Data source                                                                                                       | Description          |
| ----------------------------------------------------------------------------------------------------------------- | -------------------- |
| [`azion_connectors`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/connectors) | Lists connectors.    |
| [`azion_connector`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/connector)   | Reads one connector. |

This block creates a connector to an HTTPS origin, then queries the existing connectors:

```hcl
# Create a connector
resource "azion_connector" "example" {
  name = "my-connector"
  
  origin = {
    address = "origin.example.com"
    protocol = "https"
  }
}

# Query existing connectors
data "azion_connectors" "all" {}
```

---

## Applications

These resources and data sources manage applications and their settings: cache settings, device groups, Rules Engine rules, and function instances. For more information, refer to [Applications resources](/en/documentation/devtools/terraform/applications/).

| Resource                                                                                                                                               | Description                                                |
| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------- |
| [`azion_application_main_setting`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/application_main_setting)             | Creates and manages the main settings of an application.   |
| [`azion_application_cache_setting`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/application_cache_setting)           | Creates and manages a cache setting.                       |
| [`azion_application_device_group`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/application_device_group)             | Creates and manages a device group.                        |
| [`azion_application_rule_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/application_rule_engine)               | Creates and manages a Rules Engine rule.                   |
| [`azion_application_functions_instance`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/application_functions_instance) | Creates and manages a function instance in an application. |

| Data source                                                                                                                                                | Description                                |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| [`azion_application_main_settings`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_main_settings)            | Queries the main settings of applications. |
| [`azion_application_cache_settings`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_cache_settings)          | Lists cache settings.                      |
| [`azion_application_cache_setting`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_cache_setting)            | Reads one cache setting.                   |
| [`azion_application_device_groups`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_device_groups)            | Lists device groups.                       |
| [`azion_application_device_group`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_device_group)              | Reads one device group.                    |
| [`azion_application_rules_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_rules_engine)              | Lists Rules Engine rules.                  |
| [`azion_application_rule_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_rule_engine)                | Reads one Rules Engine rule.               |
| [`azion_application_functions_instances`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_functions_instance) | Lists function instances.                  |
| [`azion_application_functions_instance`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/application_functions_instance)  | Reads one function instance.               |

This block creates an application and a cache setting that honors the cache policy of the origin:

```hcl
# Create an Application
resource "azion_application_main_setting" "app" {
  name = "my-application"
  
  active = true
}

# Configure cache
resource "azion_application_cache_setting" "cache" {
  application_id = azion_application_main_setting.app.id
  name = "cache-default"
  
  browser_cache_settings = "honor"
  cdn_cache_settings = "honor"
}
```

---

## Edge DNS

These resources and data sources manage [Edge DNS](/en/documentation/platform/edge-dns/) zones, records, and DNSSEC. The names keep the `intelligent_dns` form that the provider uses. For more information, refer to [Edge DNS resources](/en/documentation/devtools/terraform/dns/).

| Resource                                                                                                                               | Description                            |
| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------- |
| [`azion_intelligent_dns_zone`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/intelligent_dns_zone)     | Creates and manages a DNS zone.        |
| [`azion_intelligent_dns_record`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/intelligent_dns_record) | Creates and manages a DNS record.      |
| [`azion_intelligent_dns_dnssec`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/intelligent_dns_dnssec) | Manages the DNSSEC settings of a zone. |

| Data source                                                                                                                                 | Description                          |
| ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------ |
| [`azion_intelligent_dns_zones`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/intelligent_dns_zones)     | Lists DNS zones.                     |
| [`azion_intelligent_dns_zone`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/intelligent_dns_zone)       | Reads one DNS zone.                  |
| [`azion_intelligent_dns_records`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/intelligent_dns_records) | Lists DNS records.                   |
| [`azion_intelligent_dns_dnssec`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/intelligent_dns_dnssec)   | Reads the DNSSEC settings of a zone. |

This block creates a zone and an `A` record in it, then queries the existing zones:

```hcl
# Create a DNS zone
resource "azion_intelligent_dns_zone" "zone" {
  name = "example.com"
  domain = "example.com"
  
  active = true
}

# Create a DNS record
resource "azion_intelligent_dns_record" "www" {
  zone_id = azion_intelligent_dns_zone.zone.id
  name = "www"
  type = "A"
  ttl = 3600
  
  value = "192.0.2.1"
}

# Query existing DNS zones
data "azion_intelligent_dns_zones" "all" {}
```

---

## Security

These resources and data sources manage firewalls, their Rules Engine rules and function instances, Web Application Firewall (WAF) settings, and network lists. For more information, refer to [Security resources](/en/documentation/devtools/terraform/security/).

| Resource                                                                                                                                         | Description                                            |
| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------ |
| [`azion_firewall_main_setting`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/firewall_main_setting)             | Creates and manages the main settings of a firewall.   |
| [`azion_firewall_rule_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/firewall_rule_engine)               | Creates and manages a Rules Engine rule of a firewall. |
| [`azion_firewall_functions_instance`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/firewall_functions_instance) | Creates and manages a function instance in a firewall. |
| [`azion_network_list`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/network_list)                               | Creates and manages a network list.                    |
| [`azion_waf`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/waf)                                                 | Creates and manages a WAF.                             |
| [`azion_waf_rule_set`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/waf_rule_set)                               | Creates and manages a WAF rule set.                    |

| Data source                                                                                                                                         | Description                                |
| --------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| [`azion_firewall_main_settings`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_main_settings)           | Lists firewalls.                           |
| [`azion_firewall_main_setting`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_main_setting)             | Reads one firewall.                        |
| [`azion_firewall_rules_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_rules_engine)             | Lists the Rules Engine rules of firewalls. |
| [`azion_firewall_rule_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_rule_engine)               | Reads one Rules Engine rule of a firewall. |
| [`azion_firewall_function_instances`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_functions_instance) | Lists the function instances of firewalls. |
| [`azion_firewall_functions_instance`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_functions_instance) | Reads one function instance of a firewall. |
| [`azion_network_lists`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/network_lists)                             | Lists network lists.                       |
| [`azion_network_list`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/network_list)                               | Reads one network list.                    |
| [`azion_wafs`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/wafs)                                               | Lists WAFs.                                |
| [`azion_waf`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/waf)                                                 | Reads one WAF.                             |
| [`azion_waf_rule_sets`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/waf_rule_sets)                             | Lists WAF rule sets.                       |
| [`azion_waf_rule_set`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/waf_rule_set)                               | Reads one WAF rule set.                    |

This block creates a firewall in `waf` mode and a network list of two IP ranges:

```hcl
# Create a Firewall
resource "azion_firewall_main_setting" "firewall" {
  name = "my-firewall"
  
  active = true
  mode = "waf"
}

# Create a Network List
resource "azion_network_list" "allowlist" {
  name = "allowlist-ips"
  list_type = "ip_cidr"
  
  items = [
    "192.0.2.0/24",
    "10.0.0.0/8"
  ]
}
```

---

## Certificates

These resources and data sources manage digital certificates. For more information, refer to [Certificates resources](/en/documentation/devtools/terraform/certificates/).

| Resource                                                                                                                         | Description                                |
| -------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| [`azion_digital_certificate`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/digital_certificate) | Creates and manages a digital certificate. |

| Data source                                                                                                                           | Description                    |
| ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------ |
| [`azion_digital_certificates`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/digital_certificates) | Lists digital certificates.    |
| [`azion_digital_certificate`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/digital_certificate)   | Reads one digital certificate. |

This block creates a certificate from a certificate file and a private key file in the module folder, then queries the existing certificates:

```hcl
# Create a certificate
resource "azion_digital_certificate" "cert" {
  name = "my-certificate"
  
  certificate = file("${path.module}/cert.pem")
  private_key = file("${path.module}/key.pem")
}

# Query existing certificates
data "azion_digital_certificates" "all" {}
```

---

## Functions

This resource and these data sources manage [Functions](/en/documentation/platform/functions/). No reference page of the provider covers them.

| Resource                                                                                                   | Description                     |
| ---------------------------------------------------------------------------------------------------------- | ------------------------------- |
| [`azion_function`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/function) | Creates and manages a function. |

| Data source                                                                                                     | Description         |
| --------------------------------------------------------------------------------------------------------------- | ------------------- |
| [`azion_functions`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/functions) | Lists functions.    |
| [`azion_function`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/function)   | Reads one function. |

---

## Custom pages

This resource and these data sources manage custom pages. No reference page of the provider covers them.

| Resource                                                                                                         | Description                        |
| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------- |
| [`azion_custom_page`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/custom_page) | Creates and manages a custom page. |

| Data source                                                                                                           | Description            |
| --------------------------------------------------------------------------------------------------------------------- | ---------------------- |
| [`azion_custom_pages`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/custom_pages) | Lists custom pages.    |
| [`azion_custom_page`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/custom_page)   | Reads one custom page. |

---

## Complete example

This configuration pins the provider to version 2.0.0 and creates an application with a cache setting, a connector, a workload with a deployment, and a firewall. It outputs the IDs of the application, the workload, and the connector, and reads your personal token from the `api_token` variable that the [Azion Terraform Provider quickstart](/en/documentation/devtools/terraform/getting-started/) declares.

```hcl
terraform {
  required_providers {
    azion = {
      source  = "aziontech/azion"
      version = "2.0.0"
    }
  }
}

provider "azion" {
  api_token = var.api_token
}

# Application
resource "azion_application_main_setting" "app" {
  name = "my-application"
  active = true
}

# Cache Setting
resource "azion_application_cache_setting" "cache" {
  application_id = azion_application_main_setting.app.id
  name = "cache-default"
  browser_cache_settings = "honor"
  cdn_cache_settings = "honor"
}

# Connector
resource "azion_connector" "origin" {
  name = "my-origin"
  origin = {
    address = "origin.example.com"
    protocol = "https"
  }
}

# Workload
resource "azion_workload" "main" {
  name = "my-workload"
  application_id = azion_application_main_setting.app.id
  active = true
}

# Workload Deployment
resource "azion_workload_deployment" "main" {
  workload_id = azion_workload.main.id
  active = true
}

# Firewall
resource "azion_firewall_main_setting" "firewall" {
  name = "my-firewall"
  active = true
  mode = "waf"
}

# Outputs
output "application_id" {
  value = azion_application_main_setting.app.id
}

output "workload_id" {
  value = azion_workload.main.id
}

output "connector_id" {
  value = azion_connector.origin.id
}
```

---

## Related resources

- [Azion Terraform Provider](/en/documentation/devtools/terraform.md): What the provider manages and how it reaches the Azion API.
- [Azion Terraform Provider quickstart](/en/documentation/devtools/terraform/getting-started.md): Install Terraform, configure the provider and your token, and apply a first configuration.
- [Terraform Provider best practices](/en/documentation/devtools/terraform/best-practices.md): How to organize code, store state, protect secrets, and pin provider versions.
- [Migrate from provider v1.x to v2.0](/en/documentation/devtools/terraform/terraform-migration-v3-to-v4.md): The resources v2.0 removes, renames, and adds, and how to move a v1.x configuration to it.
