Skip to main content
Terraform starts managing the resources already set up in dev, exactly as they are. Nothing in the tenant changes.

Prerequisites

1. Add the imports

Create envs/dev/imports.tf with the same five imports as the scratch folder. Resources inside a module have addresses that start with module. and the module’s name from main.tf, so the addresses now start with module.authsignal..

2. Plan

The plan should end with:
If the module has a secret value, expect 1 to change on the Email OTP configuration. Applying it sends the key. If it shows any other changes, the module doesn’t match the tenant yet. Update the module, not the tenant, and plan again. If an attribute comes from a variable, update its value in envs/dev/terraform.tfvars instead. Reading a plan explains how to read the differences.

3. Apply

The import blocks have done their job once applied. Deleting them keeps them from being copied into the next environment. The import is written to state on apply. A plan on its own doesn’t write anything. Applying the saved plan means Terraform does exactly what you reviewed, even if someone changed the tenant in between. Don’t commit tfplan. It contains the full state of every resource in the plan.

Verify

It should report No changes. Commit the module and the envs/dev files. Dev is now managed by Terraform.