Limitations
Terraform Limitations
The provider covers the resources you build pipelines from, but not everything you can do in the Monad UI or API. This page lists what it does not manage today, so you can plan around it. The changelog records when a gap is closed.
Platform and Version Requirements
- Terraform 1.11 or later is required, because secret values are write-only arguments.
- The provider is pre-1.0. Breaking changes ship as minor version bumps; see Pin the Provider's Minor Version.
Resources It Does Not Manage
The provider manages inputs, transforms, enrichments, outputs, pipelines, secrets and alert rules. It does not manage:
- Organizations or teams
- Users, roles or SSO configuration
- API keys
- Resource sharing between organizations
- Billing
Configure these in the Monad UI or through the Monad API.
No Data Sources
The provider has no data sources, so a configuration cannot look up a component, secret or pipeline that Terraform does not manage, or list what exists in an organization. To use a component that was created outside Terraform, import it so Terraform manages it, or pass its ID in as a variable.
Settings It Does Not Carry
A few settings the Monad UI and API support have no Terraform equivalent yet:
| Setting | What happens |
|---|---|
| Disabling an individual pipeline edge | Edges are always created enabled. Disable a whole pipeline with enabled = false instead. |
Nested logical conditions (for example an or inside an and) | An edge condition is one logical operator over a list of leaf rules. Rewrite nested logic as a single level, or split it across several edges. |
| Choosing a connector version | A component Terraform creates gets its connector type's latest version. A version pinned outside Terraform is kept when Terraform updates or imports the component, but a component Terraform destroys and re-creates gets the latest version again. |
Secret Values Are Not Compared
Monad never returns secret values, so Terraform cannot see a secret value that was changed in the Monad UI and will not report it as drift. It re-sends a secret only when the value in your configuration changes. A value changed in the UI therefore stays in effect, and Terraform overwrites it the next time the value in your configuration changes. Rotate Terraform-managed secrets in your configuration, not in the UI.
The first plan after importing a secret, or a component that has secrets, shows a one-time update that re-sends the values from your configuration. Applying it is expected.