Deploy Workspace
Application Scenario
Security Master (SecMaster) is a security situation awareness and security operations platform provided by Huawei Cloud, supporting unified management, analysis, and response of security events, helping you achieve automation and intelligence in security operations. Workspace is a fundamental resource of SecMaster, used to isolate and manage security resources for different business scenarios. By creating workspaces, independent security operations environments can be created under specified projects, achieving unified management and isolation of security resources. This best practice introduces how to use Terraform to automatically deploy workspaces, including workspace basic information, project configuration, enterprise project configuration, and tag configuration.
Related Resources/Data Sources
This best practice involves the following main resources and data sources:
Resources
Resource/Data Source Dependencies
huaweicloud_secmaster_workspaceOperation Steps
1. Script Preparation
Prepare the TF file (such as main.tf) for writing the current best practice script in the specified workspace, ensuring that it (or other TF files in the same directory) contains the provider version declaration and Huawei Cloud authentication information required for deploying resources. For configuration details, refer to the introduction in Preparation Before Deploying Huawei Cloud Resources.
2. Create Workspace
Add the following script to the TF file (such as main.tf) to create a workspace:
Parameter Description:
name: Workspace name, assigned by referencing the input variable
workspace_nameproject_name: Project name, assigned by referencing the input variable
workspace_project_name, used to specify the project in which to create the workspacedescription: Workspace description, assigned by referencing the input variable
workspace_description, optional parameterenterprise_project_id: Enterprise project ID, assigned by referencing the input variable
enterprise_project_id, used to specify the enterprise project to which the workspace belongs, optional parametertags: Tags, assigned by referencing the input variable
workspace_tags, used to add key-value pair tags to the workspace, optional parameter
Note: Workspaces must be created under specified projects. Enterprise project IDs are used to achieve unified management and isolation of resources. If not specified, the default enterprise project is used. Tags can be used for resource classification and management.
3. Preset Input Parameters Required for Resource Deployment (Optional)
In this practice, some resources and data sources use input variables to assign configuration content. These input parameters need to be manually entered during subsequent deployment. Terraform also provides a method to preset these configurations through tfvars files, which can avoid repeated input each time.
Create a terraform.tfvars file in the working directory with the following example content:
Usage:
Save the above content as a
terraform.tfvarsfile in the working directory (this filename allows Terraform to automatically import the variable values in thistfvarsfile when executing terraform commands. For other names, you need to add.autobefore tfvars, such asvariables.auto.tfvars)Modify parameter values according to actual needs
When executing
terraform planorterraform apply, Terraform will automatically read the variable values in this file
In addition to using the terraform.tfvars file, you can also set variable values through the following methods:
Command-line parameters:
terraform apply -var="workspace_name=tf_test_workspace" -var="workspace_project_name=cn-north-4"Environment variables:
export TF_VAR_workspace_name=tf_test_workspaceCustom-named variable files:
terraform apply -var-file="custom.tfvars"
Note: If the same variable is set through multiple methods, Terraform will use variable values according to the following priority: command-line parameters > variable files > environment variables > default values.
4. Initialize and Apply Terraform Configuration
After completing the above script configuration, execute the following steps to create resources:
Run
terraform initto initialize the environmentRun
terraform planto view the resource creation planAfter confirming that the resource plan is correct, run
terraform applyto start creating the workspaceRun
terraform showto view the created workspace
Reference Information
Last updated