Terraform

Overview

HPE Morpheus Software provides Terraform integration as both a provisioning engine and a management tool. The Tools-level Terraform features focus on state management, drift detection, and operational commands for Terraform-managed infrastructure within HPE Morpheus Software.

Terraform state and operations are accessible from App and Instance detail pages for resources provisioned using Terraform blueprints or Terraform Instance Types.

Terraform State Management

HPE Morpheus Software stores and manages Terraform state for all Terraform-provisioned resources:

State Storage

  • Terraform state is stored within HPE Morpheus Software (no external backend required)

  • State is encrypted at rest in the HPE Morpheus Software database

  • State versioning is maintained for rollback capability

  • State can be viewed and edited from the App or Instance detail page

Viewing State

To view the current Terraform state:

  1. Navigate to the App or Instance provisioned with Terraform

  2. Select the State tab

  3. The current state JSON is displayed with syntax highlighting

Editing State

Warning

Editing Terraform state directly is an advanced operation that can cause infrastructure inconsistencies. Only modify state when necessary (e.g., importing existing resources, removing orphaned entries).

To edit state:

  1. Navigate to the App or Instance State tab

  2. Click EDIT STATE

  3. Modify the state JSON as needed

  4. Click SAVE

Role permission Provisioning: State with Full access is required for state editing.

Drift Detection

HPE Morpheus Software can detect drift between the declared Terraform configuration and the actual infrastructure state:

  • Drift is identified by running terraform plan against the current state

  • Resources that have changed outside of Terraform management are flagged

  • Drift information helps identify configuration issues and unauthorized changes

Running Terraform Commands

From the App or Instance detail page, Terraform commands can be executed:

  1. Navigate to the App or Instance provisioned with Terraform

  2. Open the Console or Terraform tab

  3. Enter Terraform commands in the command field:

    • plan — Preview changes without applying

    • apply — Apply the current configuration

    • destroy — Destroy managed resources

    • refresh — Update state to match real infrastructure

    • output — Display output values

    • state list — List resources in state

    • state show <resource> — Show details of a specific resource

  4. Click EXECUTE

Command output is displayed in real-time and stored in execution history.

Note

Terraform commands are prefixed with terraform automatically. Enter only the subcommand (e.g., plan not terraform plan).

Terraform Settings

Global Terraform settings are configured in Administration ‣ Settings ‣ Provisioning (Administration > Settings > Provisioning):

Terraform Runtime

  • TERRAFORM RUNTIME: Select the Terraform runtime version (e.g., 1.5.x, 1.6.x)

  • This sets the default Terraform version used for new deployments

  • Individual Apps/Instances may specify version constraints in their configuration

State Backend

  • By default, HPE Morpheus Software acts as the state backend

  • Remote backends (S3, Azure Blob, GCS, Consul) can be configured in the Terraform configuration files

Terraform Providers

HPE Morpheus Software supports all Terraform providers available in the Terraform Registry. Provider plugins are downloaded automatically during terraform init based on the configuration’s required_providers block.

Terraform Variables

Variables for Terraform plans can be supplied from multiple sources:

  • Instance configuration: Variables set during provisioning

  • Cypher secrets: Sensitive values pulled from HPE Morpheus Software Cypher (tfvars mount)

  • Input variables: User-supplied values at execution time

  • Environment variables: TF_VAR_* environment variables

To store Terraform variable files securely:

  1. Navigate to Tools > Cypher (Tools > Cypher)

  2. Create a key with the tfvars mount point: tfvars/myapp/variables

  3. Store the tfvars content as the value

  4. Reference in your Terraform configuration

Workspaces

Terraform workspaces allow managing multiple environments with a single configuration:

  • HPE Morpheus Software tracks the active workspace for each Terraform deployment

  • Workspace selection can be part of the provisioning configuration

  • State is maintained per-workspace

Execution History

All Terraform command executions are tracked:

  1. Navigate to the App or Instance detail page

  2. Select the History tab

  3. View past Terraform operations including:

    • Command executed

    • Execution timestamp

    • User who initiated the command

    • Exit code and output

    • Execution duration

Role Permissions

Terraform operations are controlled by the following role permissions:

  • Provisioning: State — None, Read, Full

    • None: Cannot access Terraform state

    • Read: Can view state and execution history

    • Full: Can edit state and execute Terraform commands

  • Provisioning: Apps or Provisioning: Instances — Required to access the parent resource