Terraform is an open-source tool that allows you to securely and efficiently preview, provision, and manage cloud resources. This topic describes how to use Terraform to create a RAM user and a RAM user group, and then add the RAM user to the RAM user group.
You can run the sample code in this tutorial with a single click. Run the code
Prerequisites
To reduce security risks, we recommend using a RAM user with the minimum required permissions for this tutorial. For more information, see Create a RAM user and Grant permissions to a RAM user. The following policy grants the minimum permissions required for this tutorial:
{ "Version": "1", "Statement": [ { "Effect": "Allow", "Action": [ "ram:GetUser", "ram:ListGroupsForUser", "ram:ListUsers", "ram:ListUsersForGroup", "ram:CreateUser", "ram:RemoveUserFromGroup", "ram:ListGroups", "ram:GetGroup", "ram:CreateGroup", "ram:DeleteGroup", "ram:GetLoginProfile", "ram:CreateAccessKey", "ram:DeleteAccessKey", "ram:ListAccessKeys", "ram:DeleteLoginProfile", "ram:CreateLoginProfile", "ram:UpdateLoginProfile", "ram:DeleteUser", "ram:UpdateAccessKey", "ram:AddUserToGroup" ], "Resource": "*" }, { "Effect": "Allow", "Action": "ram:ListPoliciesForGroup", "Resource": "*" }, { "Effect": "Allow", "Action": "ram:AttachPolicyToGroup", "Resource": "*" } ] }-
Terraform runtime environment (choose one):
Option
Best for
Browser-based setup, no installation
Terraform pre-installed with credentials configured
Unstable networks or custom environments
Resources used
alicloud_ram_user: a RAM user.
alicloud_ram_login_profile: the logon settings for a RAM user.
alicloud_ram_access_key: the AccessKey pair for a RAM user.
alicloud_ram_group: a RAM user group.
alicloud_ram_group_membership: adds a RAM user to a RAM user group.
Step 1: Create a RAM user
Create a working directory and a configuration file named main.tf in the directory. Copy the following code into the main.tf file. The code creates a RAM user, sets its logon password, and creates an AccessKey pair.
# The logon password for the RAM user. variable "password" { default = "Test@123456!" } # The name of the file to store the AccessKey pair. variable "accesskey_txt_name" { default = "accesskey.txt" } resource "random_integer" "default" { min = 10000 max = 99999 } # A RAM user. resource "alicloud_ram_user" "user" { name = "tf_user_${random_integer.default.result}" } # The logon password for the RAM user. resource "alicloud_ram_login_profile" "profile" { user_name = alicloud_ram_user.user.name password = var.password } # The AccessKey pair for the RAM user. resource "alicloud_ram_access_key" "ak" { user_name = alicloud_ram_user.user.name secret_file = var.accesskey_txt_name }Run the following command to initialize the Terraform runtime environment.
terraform initThe following output indicates that Terraform was successfully initialized.
Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure. All Terraform commands should now work. If you ever set or change modules or backend configuration for Terraform, rerun this command to reinitialize your working directory. If you forget, other commands will detect it and remind you to do so if necessary.Run the following command to apply the configuration.
terraform applyWhen prompted, enter
yesand press Enter. Wait for the command to complete. The following output indicates that the configuration was applied.ImportantAfter you apply the configuration, Terraform creates a file in the current directory that contains the AccessKey pair. Keep this file confidential to prevent data leaks.
You can apply this plan to save these new output values to the Terraform state, without changing any real infrastructure. Do you want to perform these actions? Terraform will perform the actions described above. Only 'yes' will be accepted to approve. Enter a value: yes Apply complete! Resources: 4 added, 0 changed, 0 destroyed.Verify the result.
CLI
In the working directory, run the following command to view the details of the resources created by Terraform:
terraform showshell@Alicloud:~/ram$ terraform show # alicloud_ram_access_key.ak: resource "alicloud_ram_access_key" "ak" { id = "LTAI5tCvkExxx" secret = (sensitive value) secret_file = "accesskey.txt" status = "Active" user_name = "tf_user_xxx" } # alicloud_ram_login_profile.profile: resource "alicloud_ram_login_profile" "profile" { id = "tf_user_xxx" mfa_bind_required = true password = (sensitive value) password_reset_required = false user_name = "tf_user_xxx" } # alicloud_ram_user.user: resource "alicloud_ram_user" "user" { id = "xxx" name = "tf_user_xxx" } # random_integer.default: resource "random_integer" "default" { id = "xxx" max = 99999 min = 10000 result = xxx }Console
Log on to the RAM console. In the left-side navigation pane, choose . On the page that appears, view the newly created RAM user.
Step 2: Create a user group and add the user
Add the following code to the
main.tffile.# A RAM user group. resource "alicloud_ram_group" "group" { name = "test_ram_group_${random_integer.default.result}" force = true } # Add the RAM user to the RAM user group. resource "alicloud_ram_group_membership" "membership" { group_name = alicloud_ram_group.group.name user_names = [alicloud_ram_user.user.name] }Create an execution plan and preview the changes.
terraform planRun the following command to apply the configuration.
terraform applyWhen prompted, enter
yesand press Enter. Wait for the command to complete. The following output indicates that the configuration was applied.Apply complete! Resources: 2 added, 0 changed, 0 destroyed.Verify the result.
CLI
In the working directory, run the following command to view the details of the resources created by Terraform:
terraform show# alicloud_ram_group.group: resource "alicloud_ram_group" "group" { force = true id = "test_ram_group_xxx" name = "test_ram_group_xxx" } # alicloud_ram_group_membership.membership: resource "alicloud_ram_group_membership" "membership" { group_name = "test_ram_group_xxx" id = "test_ram_group_xxx" user_names = [ "tf_user_xxx", ] }Console
Log on to the RAM console. In the left-side navigation pane, choose . On the page that appears, view the newly created RAM user group.
Click the name of the RAM user group to view its members.
Clean up resources
When you no longer need the resources created by Terraform, run the following command to release them. For more information about the terraform destroy command, see Common commands.
terraform destroyComplete example
You can run the sample code in this tutorial with a single click. Run the code
Sample code
For more examples, go to the More Complete Examples page and open the folder for the relevant product.