Terraform
Read a Vaultic secret's fully-resolved value as a Terraform data source.
vaultic/vaultic is a Terraform provider exposing a single data source,
vaultic_secret, that reads one secret's fully-resolved value from a running Vaultic server —
read secrets into Terraform, not manage them from it.
Built with the Terraform Plugin Framework as a standalone Go module (not part of the Node/TS workspace, since Terraform providers are separate binaries speaking Terraform's plugin protocol).
What it does
- One data source:
vaultic_secret, identified byworkspace/project/environment/key. - Calls the same reveal endpoint
vaultic secrets get --revealandvaultic exportuse, with a service-token bearer auth header — so you get the same inheritance fall-through and${...}reference resolution Terraform-side. - Auth via
VAULTIC_TOKEN(or the provider'stokenattribute) — create a read-scoped token withvaultic tokens create terraform --read-only. - No resources — Vaultic is the source of truth for secret values; this provider only reads.
Usage
terraform {
required_providers {
vaultic = { source = "vaultic/vaultic" }
}
}
provider "vaultic" {
endpoint = "https://vaultic.example.com" # or VAULTIC_API_URL
token = var.vaultic_token # or VAULTIC_TOKEN
}
data "vaultic_secret" "database_url" {
workspace = "acme"
project = "backend-api"
environment = "production"
key = "DATABASE_URL"
}value is marked Sensitive in the schema, so Terraform redacts it from plan/apply output —
but it still lands in terraform.tfstate in plaintext, which is inherent to how Terraform data
sources work. Use a state backend with encryption at rest and tight access control if you use
this for real secrets, same as you would for any other Terraform-managed sensitive value.
Building and testing locally
cd terraform-provider-vaultic
go build -o terraform-provider-vaultic .Requires Go 1.22+. To iterate without publishing to a registry, point Terraform's
dev_overrides at your local binary:
# dev.tfrc
provider_installation {
dev_overrides {
"vaultic/vaultic" = "/absolute/path/to/terraform-provider-vaultic"
}
direct {}
}export TF_CLI_CONFIG_FILE=/absolute/path/to/dev.tfrc
export VAULTIC_API_URL=http://localhost:4000
export VAULTIC_TOKEN=<a service token from `vaultic tokens create`>
# no `terraform init` needed/allowed with dev_overrides in effect — go straight to plan/apply
terraform planA warning that development overrides are in effect is expected here, not an error.
This provider isn't published to the public Terraform Registry yet — use dev_overrides as
shown above until it is.
Cloud secret store sync
Push secrets to AWS Secrets Manager, AWS SSM Parameter Store, GCP Secret Manager, or Azure Key Vault — on demand from the CLI, or automatically from the web app.
Kubernetes
A controller-runtime operator that materializes a Vaultic environment as a native v1.Secret, refreshed on an interval.