Vaultic
Integrations

Terraform

Read a Vaultic secret's fully-resolved value as a Terraform data source.

vaultic/vaultic is a Terraform provider exposing a single data source, vaultic_secret, that reads one secret's fully-resolved value from a running Vaultic server — read secrets into Terraform, not manage them from it.

Built with the Terraform Plugin Framework as a standalone Go module (not part of the Node/TS workspace, since Terraform providers are separate binaries speaking Terraform's plugin protocol).

What it does

  • One data source: vaultic_secret, identified by workspace / project / environment / key.
  • Calls the same reveal endpoint vaultic secrets get --reveal and vaultic export use, with a service-token bearer auth header — so you get the same inheritance fall-through and ${...} reference resolution Terraform-side.
  • Auth via VAULTIC_TOKEN (or the provider's token attribute) — create a read-scoped token with vaultic tokens create terraform --read-only.
  • No resources — Vaultic is the source of truth for secret values; this provider only reads.

Usage

terraform {
  required_providers {
    vaultic = { source = "vaultic/vaultic" }
  }
}

provider "vaultic" {
  endpoint = "https://vaultic.example.com" # or VAULTIC_API_URL
  token    = var.vaultic_token             # or VAULTIC_TOKEN
}

data "vaultic_secret" "database_url" {
  workspace   = "acme"
  project     = "backend-api"
  environment = "production"
  key         = "DATABASE_URL"
}

value is marked Sensitive in the schema, so Terraform redacts it from plan/apply output — but it still lands in terraform.tfstate in plaintext, which is inherent to how Terraform data sources work. Use a state backend with encryption at rest and tight access control if you use this for real secrets, same as you would for any other Terraform-managed sensitive value.

Building and testing locally

cd terraform-provider-vaultic
go build -o terraform-provider-vaultic .

Requires Go 1.22+. To iterate without publishing to a registry, point Terraform's dev_overrides at your local binary:

# dev.tfrc
provider_installation {
  dev_overrides {
    "vaultic/vaultic" = "/absolute/path/to/terraform-provider-vaultic"
  }
  direct {}
}
export TF_CLI_CONFIG_FILE=/absolute/path/to/dev.tfrc
export VAULTIC_API_URL=http://localhost:4000
export VAULTIC_TOKEN=<a service token from `vaultic tokens create`>

# no `terraform init` needed/allowed with dev_overrides in effect — go straight to plan/apply
terraform plan

A warning that development overrides are in effect is expected here, not an error.

This provider isn't published to the public Terraform Registry yet — use dev_overrides as shown above until it is.

On this page