This repository contains the Terraform provider for managing Nerdio Manager for Enterprise (NME) resources.
Important
This provider is currently under heavy development. Review the current limitations and coverage gaps in the AVD coverage matrix before using a release.
GitHub Actions currently packages the provider for Linux amd64 and Windows amd64. Provider configuration and representative resources are available under examples.
- Terraform CLI
- Go 1.25.8 for source builds
- Git for source builds and release creation
- An NME API URL and Microsoft Entra client credentials
Declare the provider in your Terraform configuration. Use the release version without the leading v from its Git tag.
terraform {
required_providers {
nme = {
source = "nerdio/nme"
version = "0.1.0"
}
}
}
provider "nme" {}The provider accepts the following attributes or their corresponding environment variables. Values set directly in the provider block take precedence over environment variables.
| Attribute | Environment variable | Description |
|---|---|---|
base_url |
NME_BASE_URL |
Base URL for the NME API. |
tenant_id |
NME_TENANT_ID |
Microsoft Entra tenant ID used for OAuth client credentials. |
client_id |
NME_CLIENT_ID |
Client ID used for OAuth client credentials. |
client_secret |
NME_CLIENT_SECRET |
Client secret used for OAuth client credentials. |
scope |
NME_SCOPE |
OAuth scope, usually api://<application-id>/.default. |
Environment variables keep credentials out of Terraform configuration files. For example, in PowerShell:
$env:NME_BASE_URL = "https://example.invalid"
$env:NME_TENANT_ID = "<tenant-id>"
$env:NME_CLIENT_ID = "<client-id>"
$env:NME_CLIENT_SECRET = "<client-secret>"
$env:NME_SCOPE = "api://<application-id>/.default"In a POSIX shell:
export NME_BASE_URL="https://example.invalid"
export NME_TENANT_ID="<tenant-id>"
export NME_CLIENT_ID="<client-id>"
export NME_CLIENT_SECRET="<client-secret>"
export NME_SCOPE="api://<application-id>/.default"See the provider example for direct configuration and the main example for representative usage. Do not commit secrets or populated variable files.
Generated API client code and provider documentation are not committed. Generate them before testing or building a clean checkout:
go generate ./...
go test ./...Build a development executable into a dedicated directory.
PowerShell on Windows:
New-Item -ItemType Directory -Force bin\nme | Out-Null
go build -trimpath -ldflags "-s -w -X main.version=dev" -o bin\nme\terraform-provider-nme.exe .POSIX shell on Linux:
mkdir -p bin/nme
go build -trimpath -ldflags "-s -w -X main.version=dev" -o bin/nme/terraform-provider-nme .
chmod +x bin/nme/terraform-provider-nmeTerraform CLI development overrides load a provider executable directly from a local directory. Configure the override once, then point it at either a source build or an extracted GitHub artifact.
Create or update %APPDATA%\terraform.rc:
provider_installation {
dev_overrides {
"registry.terraform.io/nerdio/nme" = "D:/src/NMW-Terraform-Provider/bin/nme"
}
direct {}
}The target directory must contain terraform-provider-nme.exe.
Create or update ~/.terraformrc:
provider_installation {
dev_overrides {
"registry.terraform.io/nerdio/nme" = "/home/user/src/NMW-Terraform-Provider/bin/nme"
}
direct {}
}The target directory must contain an executable named terraform-provider-nme.
Run Terraform commands with the override active:
terraform planTerraform prints a warning when a development override is active. This is expected. terraform init still attempts to find a published provider version and can therefore fail even though subsequent commands use the override. If the configuration requires other providers, initialize those dependencies before enabling the override or retain an existing dependency lock file. Rebuild the executable to test code changes; Terraform starts a new provider process on the next command.
- Download the ZIP for the required platform and
SHA256SUMSfrom the matching GitHub Release. - Verify the archive checksum.
- Extract the archive into a dedicated provider directory.
- Rename the extracted executable to
terraform-provider-nme.exeon Windows orterraform-provider-nmeon Linux. - On Linux, run
chmod +x terraform-provider-nme. - Point the development override described above at that directory.
For example, verify and extract version v0.1.0 on Windows from the directory containing the downloaded files:
$archive = "terraform-provider-nme_v0.1.0_windows_amd64.zip"
$expected = (Select-String -Path SHA256SUMS -Pattern " $([regex]::Escape($archive))$").Line.Split()[0]
$actual = (Get-FileHash $archive -Algorithm SHA256).Hash.ToLowerInvariant()
if ($actual -ne $expected) { throw "Checksum verification failed for $archive" }
New-Item -ItemType Directory -Force "$HOME\.terraform.d\dev-overrides\nme" | Out-Null
Expand-Archive -Force $archive "$HOME\.terraform.d\dev-overrides\nme"
Rename-Item -Force "$HOME\.terraform.d\dev-overrides\nme\terraform-provider-nme_v0.1.0_windows_amd64.exe" "terraform-provider-nme.exe"Set the Windows override path to the corresponding directory using forward slashes, for example C:/Users/user/.terraform.d/dev-overrides/nme.
On Linux:
sha256sum --check SHA256SUMS --ignore-missing
mkdir -p "$HOME/.terraform.d/dev-overrides/nme"
unzip terraform-provider-nme_v0.1.0_linux_amd64.zip -d "$HOME/.terraform.d/dev-overrides/nme"
mv "$HOME/.terraform.d/dev-overrides/nme/terraform-provider-nme_v0.1.0_linux_amd64" \
"$HOME/.terraform.d/dev-overrides/nme/terraform-provider-nme"
chmod +x "$HOME/.terraform.d/dev-overrides/nme/terraform-provider-nme"Set the Linux override path to /home/user/.terraform.d/dev-overrides/nme, adjusted for the current user.
| Path | Purpose |
|---|---|
internal/provider |
Provider schemas, resources, data sources, and tests. |
internal/client/api.json |
OpenAPI source used to generate the API client. |
examples/resources |
Resource examples used by documentation generation. |
examples/data-sources |
Data-source examples used by documentation generation. |
.github/workflows |
Validation, packaging, and tagged-release automation. |
Run go generate ./... whenever the API specification, provider schemas, or examples change.