# Azion Terraform Provider quickstart

This guide instructs you through your first infrastructure as code with the Azion Terraform Provider.

- Create a Terraform project that requires the provider.
- Give the provider your personal token.
- Declare four resources and create them with `terraform apply`.
- Check the resources in the Terraform state.

The configuration declares four independent resources, and no resource refers to another:

1. `azion_workload` creates a [workload](/en/documentation/platform/workloads/).
2. `azion_connector` creates a [connector](/en/documentation/platform/connectors/).
3. `azion_application_main_setting` creates an [application](/en/documentation/platform/applications/).
4. `azion_intelligent_dns_zone` creates an active zone in [Edge DNS](/en/documentation/platform/edge-dns/).

For more information about the provider, refer to [Azion Terraform Provider](/en/documentation/devtools/terraform/).

---

## Prerequisites

- [Terraform](https://developer.hashicorp.com/terraform/downloads) 1.0 or later.
- An Azion account. To create one, refer to [Create an account](/en/documentation/fundamentals/creating-account/).
- A personal token with the permissions that your resources require. For more information, refer to [Personal tokens](/en/documentation/fundamentals/personal-tokens/).

---

## Install Terraform

The Azion Terraform Provider needs Terraform Core on your machine. If Terraform is not installed, install it from the [Terraform downloads](https://developer.hashicorp.com/terraform/downloads) page.

Check the installed version:

```bash
terraform version
```

The command prints the version of Terraform Core. The provider needs version 1.0 or later.

---

## Create the project and declare the provider

Create a directory for the project and go to it:

```bash
mkdir azion-terraform
cd azion-terraform
```

In the `azion-terraform` directory, create a `main.tf` file with the following content. The `required_providers` block sets the provider source to `aziontech/azion` and pins version `2.0.0`:

```hcl
terraform {
  required_providers {
    azion = {
      source  = "aziontech/azion"
      version = "2.0.0"
    }
  }
}

provider "azion" {
  # Recommended: use AZION_API_TOKEN environment variable
  # api_token = var.api_token
}
```

The project declares the Azion Terraform Provider at a fixed version.

---

## Provide your personal token

The provider reads your personal token from the `AZION_API_TOKEN` environment variable, which is the recommended method. In the terminal that runs Terraform, set the variable. Replace `[TOKEN VALUE]` with your personal token:

```bash
export AZION_API_TOKEN="[TOKEN VALUE]"
```

The `provider "azion"` block in `main.tf` stays empty, and no file in the project holds the token.

To keep the token in a Terraform variable instead, the provider takes it in the `api_token` argument. Create a `variables.tf` file that declares `api_token` as a sensitive variable:

```hcl
variable "api_token" {
  type        = string
  description = "Azion Personal Token"
  sensitive   = true
}
```

Create a `terraform.tfvars` file that sets the variable. This file holds the token, so add `terraform.tfvars` to your `.gitignore` file:

```hcl
api_token = "[TOKEN VALUE]"
```

In `main.tf`, replace the `provider "azion"` block with a block that passes the variable to the provider:

```hcl
provider "azion" {
  api_token = var.api_token
}
```

The provider has your personal token, from the environment or from the `api_token` variable.

---

## Declare the resources

In the `azion-terraform` directory, create a `resources.tf` file. It declares a workload, a connector, an application, and a DNS zone:

```hcl
# Create a workload
resource "azion_workload" "my_workload" {
  name = "my-first-workload"
}

# Create a connector
resource "azion_connector" "my_connector" {
  name = "my-connector"
}

# Create an application
resource "azion_application_main_setting" "my_app" {
  name = "my-application"
}

# Create a DNS zone
resource "azion_intelligent_dns_zone" "my_zone" {
  name   = "example.com"
  active = true
}
```

Replace `example.com` with the domain of your zone. The project declares four resources that do not exist on your account yet.

---

## Create the resources

From the `azion-terraform` directory, initialize the Terraform project:

```bash
terraform init
```

Review the plan of the changes before you apply them:

```bash
terraform plan
```

Apply the configuration:

```bash
terraform apply
```

At the confirmation prompt, enter `yes`. Terraform creates the four resources on your Azion account.

If a command returns an error, refer to [Troubleshoot the Terraform Provider](/en/documentation/devtools/terraform/troubleshooting/).

---

## Check the resources

List the resources in the Terraform state, then show the details of the workload:

```bash
# List all resources
terraform state list

# View details of a specific resource
terraform state show azion_workload.my_workload
```

The state holds the four resources, and `terraform state show` displays the attributes that Terraform stores for the workload.

---

## Complete example

The following configuration for provider version `2.0.0` puts the provider and three resources in one file. It declares the provider itself, so use it in an empty directory, not next to another file that declares the provider. It reads the token from the `api_token` variable, so it needs a `variables.tf` file that declares `api_token` and a `terraform.tfvars` file that sets it. Each resource block marks where its other arguments go:

```hcl
terraform {
  required_providers {
    azion = {
      source  = "aziontech/azion"
      version = "2.0.0"
    }
  }
}

provider "azion" {
  api_token = var.api_token
}

# Create a workload
resource "azion_workload" "example" {
  name = "my-workload"
  # Additional configuration...
}

# Create a connector
resource "azion_connector" "example" {
  name = "my-connector"
  # Additional configuration...
}

# Create an application
resource "azion_application_main_setting" "example" {
  name = "my-application"
  # Additional configuration...
}
```

---

## Next steps

- [Workloads resources](/en/documentation/devtools/terraform/workloads.md): Create workloads and their deployments, and read them with data sources.
- [Applications resources](/en/documentation/devtools/terraform/applications.md): Configure applications with cache settings, rules, function instances, and device groups.
- [Security resources](/en/documentation/devtools/terraform/security.md): Manage firewalls, their function instances, WAF rule sets, and network lists.
- [Terraform Provider best practices](/en/documentation/devtools/terraform/best-practices.md): Organize files, store state remotely, keep secrets out of version control, and pin provider versions.
