Terraform Cloud
GOV.UK uses Terraform Cloud as a centralised interface for running Terraform.
Getting Terraform Cloud access
You can sign up for HashiCorp Cloud Platform (HCP) account, and then sign into Terraform Cloud using Single Sign On and join the GOV.UK organisation yourself. You will need to be a member of the GOV.UK Terraform Cloud Access group (or of a group that is a member of that group, such as GOV.UK Technical On-Call Comms).
Note: You must create the account in step 1 below since SSO does not automatically provision HCP user accounts, and you must not create an HCP account using GitHub or SSO authentication, you must use a username and password.
- Create a HashiCorp Cloud Platform (HCP) account from the HCP sign-in page (do not use GitHub authentication or SSO here, instead create a username and password)
- HCP will email the address on your account, follow the link in that email to verify your email.
- Follow this link to join the GOV.UK Terraform Cloud organisation. By connecting your digital.cabinet-office.gov.uk Google account, you’ll be granted access to the GOV.UK organisation.
- After connecting Google, you’ll be asked to sign into an HCP account, you should enter the username and password you set up in step 1. this will link your Google Account to your HCP account as a login for the GOV.UK Terraform Cloud organisation. Once the SSO identity is linked, you’ll only log in to the GOV.UK organization using SSO with the linked Google account.
- You must enable Two-factor Authentication in Terraform Cloud before you are able to access the GOV.UK organisation.
- You should now have access to workspaces in the GOV.UK organisation.
If you have problems following any of the above steps, you might be missing from the required Google Group. Ask over in the #govuk-ask-platform-engineering Slack channel for help.