Terraform provider

Manage hostd Public Cloud projects, SSH keys, and virtual machines with Terraform.

The hostd Terraform provider manages your Public Cloud as code: projects, SSH keys, and virtual machines. It uses the same API and the same API key.

Provider: hostdcloud/hostd in the Terraform Registry, where every resource and argument is documented.

Connect

Create an API key in the portal under Settings → API Keys and export it:

export HOSTD_API_KEY=<your-api-key>
terraform {
  required_providers {
    hostd = {
      source = "hostdcloud/hostd"
    }
  }
}

provider "hostd" {}

Access

The provider works with your API key, so it has the same access as the key (details):

  • hostd_ssh_key needs Write access to SSH keys.
  • hostd_project needs a key that is allowed to create projects; the key gets Full access to the projects it creates. To use an existing project, set its UUID as project_id.
  • hostd_vm needs Write access to the project; destroying a VM needs Full.
  • Reading state and hostd_os_images need Read.

Example

resource "hostd_project" "main" {
  name         = "production"
  cluster_name = "waw-1"
}

resource "hostd_ssh_key" "admin" {
  name           = "admin"
  public_ssh_key = file("~/.ssh/id_ed25519.pub")
}

data "hostd_os_images" "available" {
  project_id = hostd_project.main.id
}

resource "hostd_vm" "web" {
  project_id  = hostd_project.main.id
  hostname    = "web-01"
  os_image    = "debian-12-amd64.qcow2"
  ssh_key_ids = [hostd_ssh_key.admin.id]
  cores       = 2
  ram_gb      = 4
  os_disk_gb  = 20
}

output "web_ipv4" {
  value = hostd_vm.web.ipv4
}

Image names depend on the cluster: hostd_os_images returns the ones available in a project. You sign in to the VM with the SSH keys you attach; the provider sets a random password and does not expose it.

Resources

NameWhat it manages
hostd_projectA project in a cluster (zone)
hostd_ssh_keyAn SSH public key on your account
hostd_vmA VM: CPU, RAM, disk, CPU class, public and private networks
hostd_os_images (data source)OS images available in a project

Limits

  • The provider follows the API limits: when a limit is reached it waits for the Retry-After time and retries.
  • A VM's CPU or RAM can be lowered only while the VM is stopped (stop it in the portal first), and 24 hours after it was created or last increased.
  • Switching a VM's public network between ipv4, ipv6, and dual goes through off.
  • Private networks are attached by name (lan_vnets); create them in the portal first.

On this page