All Products
Search
Document Center

Terraform:Create a RAM user and user group with Terraform

Last Updated:Sep 18, 2026

Terraform is an open-source tool that allows you to securely and efficiently preview, provision, and manage cloud resources. This topic describes how to use Terraform to create a RAM user and a RAM user group, and then add the RAM user to the RAM user group.

Note

You can run the sample code in this tutorial with a single click. Run the code

Prerequisites

  • To reduce security risks, we recommend using a RAM user with the minimum required permissions for this tutorial. For more information, see Create a RAM user and Grant permissions to a RAM user. The following policy grants the minimum permissions required for this tutorial:

    {
      "Version": "1",
      "Statement": [
        {
          "Effect": "Allow",
          "Action": [
            "ram:GetUser",
            "ram:ListGroupsForUser",
            "ram:ListUsers",
            "ram:ListUsersForGroup",
            "ram:CreateUser",
            "ram:RemoveUserFromGroup",
            "ram:ListGroups",
            "ram:GetGroup",
            "ram:CreateGroup",
            "ram:DeleteGroup",
            "ram:GetLoginProfile",
            "ram:CreateAccessKey",
            "ram:DeleteAccessKey",
            "ram:ListAccessKeys",
            "ram:DeleteLoginProfile",
            "ram:CreateLoginProfile",
            "ram:UpdateLoginProfile",
            "ram:DeleteUser",
            "ram:UpdateAccessKey",
            "ram:AddUserToGroup"
          ],
          "Resource": "*"
        },
        {
          "Effect": "Allow",
          "Action": "ram:ListPoliciesForGroup",
          "Resource": "*"
        },
        {
          "Effect": "Allow",
          "Action": "ram:AttachPolicyToGroup",
          "Resource": "*"
        }
      ]
    }
  • Terraform runtime environment (choose one):

    Option

    Best for

    Terraform Explorer

    Browser-based setup, no installation

    Cloud Shell

    Terraform pre-installed with credentials configured

    Local machine

    Unstable networks or custom environments

Resources used

Step 1: Create a RAM user

  1. Create a working directory and a configuration file named main.tf in the directory. Copy the following code into the main.tf file. The code creates a RAM user, sets its logon password, and creates an AccessKey pair.

    # The logon password for the RAM user.
    variable "password" {
      default = "Test@123456!"
    }
    # The name of the file to store the AccessKey pair.
    variable "accesskey_txt_name" {
      default = "accesskey.txt"
    }
    resource "random_integer" "default" {
      min = 10000
      max = 99999
    }
    # A RAM user.
    resource "alicloud_ram_user" "user" {
      name = "tf_user_${random_integer.default.result}"
    }
    # The logon password for the RAM user.
    resource "alicloud_ram_login_profile" "profile" {
      user_name = alicloud_ram_user.user.name
      password  = var.password
    }
    # The AccessKey pair for the RAM user.
    resource "alicloud_ram_access_key" "ak" {
      user_name   = alicloud_ram_user.user.name
      secret_file = var.accesskey_txt_name
    }
  2. Run the following command to initialize the Terraform runtime environment.

    terraform init

    The following output indicates that Terraform was successfully initialized.

    Terraform has been successfully initialized!
    You may now begin working with Terraform. Try running "terraform plan" to see
    any changes that are required for your infrastructure. All Terraform commands
    should now work.
    If you ever set or change modules or backend configuration for Terraform,
    rerun this command to reinitialize your working directory. If you forget, other
    commands will detect it and remind you to do so if necessary.
  3. Run the following command to apply the configuration.

    terraform apply

    When prompted, enter yes and press Enter. Wait for the command to complete. The following output indicates that the configuration was applied.

    Important

    After you apply the configuration, Terraform creates a file in the current directory that contains the AccessKey pair. Keep this file confidential to prevent data leaks.

    You can apply this plan to save these new output values to the Terraform state, without changing any real infrastructure.
    Do you want to perform these actions?
      Terraform will perform the actions described above.
      Only 'yes' will be accepted to approve.
      Enter a value: yes
    Apply complete! Resources: 4 added, 0 changed, 0 destroyed.
  4. Verify the result.

    CLI

    In the working directory, run the following command to view the details of the resources created by Terraform:

    terraform show
    shell@Alicloud:~/ram$ terraform show
    # alicloud_ram_access_key.ak:
    resource "alicloud_ram_access_key" "ak" {
        id          = "LTAI5tCvkExxx"
        secret      = (sensitive value)
        secret_file = "accesskey.txt"
        status      = "Active"
        user_name   = "tf_user_xxx"
    }
    # alicloud_ram_login_profile.profile:
    resource "alicloud_ram_login_profile" "profile" {
        id                      = "tf_user_xxx"
        mfa_bind_required       = true
        password                = (sensitive value)
        password_reset_required = false
        user_name               = "tf_user_xxx"
    }
    # alicloud_ram_user.user:
    resource "alicloud_ram_user" "user" {
        id   = "xxx"
        name = "tf_user_xxx"
    }
    # random_integer.default:
    resource "random_integer" "default" {
        id     = "xxx"
        max    = 99999
        min    = 10000
        result = xxx
    }

    Console

    Log on to the RAM console. In the left-side navigation pane, choose Identities > Users. On the page that appears, view the newly created RAM user.

Step 2: Create a user group and add the user

  1. Add the following code to the main.tf file.

    # A RAM user group.
    resource "alicloud_ram_group" "group" {
      name  = "test_ram_group_${random_integer.default.result}"
      force = true
    }
    # Add the RAM user to the RAM user group.
    resource "alicloud_ram_group_membership" "membership" {
      group_name = alicloud_ram_group.group.name
      user_names = [alicloud_ram_user.user.name]
    }
  2. Create an execution plan and preview the changes.

    terraform plan
  3. Run the following command to apply the configuration.

    terraform apply

    When prompted, enter yes and press Enter. Wait for the command to complete. The following output indicates that the configuration was applied.

    Apply complete! Resources: 2 added, 0 changed, 0 destroyed.
  4. Verify the result.

    CLI

    In the working directory, run the following command to view the details of the resources created by Terraform:

    terraform show
    # alicloud_ram_group.group:
    resource "alicloud_ram_group" "group" {
        force = true
        id    = "test_ram_group_xxx"
        name  = "test_ram_group_xxx"
    }
    # alicloud_ram_group_membership.membership:
    resource "alicloud_ram_group_membership" "membership" {
        group_name = "test_ram_group_xxx"
        id         = "test_ram_group_xxx"
        user_names = [
            "tf_user_xxx",
        ]
    }

    Console

    1. Log on to the RAM console. In the left-side navigation pane, choose Identities > Groups. On the page that appears, view the newly created RAM user group.

    2. Click the name of the RAM user group to view its members.

Clean up resources

When you no longer need the resources created by Terraform, run the following command to release them. For more information about the terraform destroy command, see Common commands.

terraform destroy

Complete example

Note

You can run the sample code in this tutorial with a single click. Run the code

Sample code

# The logon password for the RAM user.
variable "password" {
  default = "Test@123456!"
}
# The name of the file to store the AccessKey pair.
variable "accesskey_txt_name" {
  default = "accesskey.txt"
}
resource "random_integer" "default" {
  min = 10000
  max = 99999
}
# A RAM user.
resource "alicloud_ram_user" "user" {
  name = "tf_user_${random_integer.default.result}"
}
# The logon password for the RAM user.
resource "alicloud_ram_login_profile" "profile" {
  user_name = alicloud_ram_user.user.name
  password  = var.password
}
# The AccessKey pair for the RAM user.
resource "alicloud_ram_access_key" "ak" {
  user_name   = alicloud_ram_user.user.name
  secret_file = var.accesskey_txt_name
}
# A RAM user group.
resource "alicloud_ram_group" "group" {
  name  = "test_ram_group_${random_integer.default.result}"
  force = true
}
# Add the RAM user to the RAM user group.
resource "alicloud_ram_group_membership" "membership" {
  group_name = alicloud_ram_group.group.name
  user_names = [alicloud_ram_user.user.name]
}

For more examples, go to the More Complete Examples page and open the folder for the relevant product.