Terraform
Give the Sazabi agent the Terraform CLI (terraform) in its sandbox to plan and apply infrastructure changes, authenticated with Terraform Cloud.
About
This CLI connection makes the Terraform CLI (terraform) available in the Sazabi agent's sandbox. The tool is baked into the sandbox image; connecting it authenticates (or configures the connection for) the already-installed CLI.
Prerequisites
- A Sazabi project.
- A Terraform Cloud API token (
TF_TOKEN_app_terraform_io). Generate one in your Terraform Cloud account under User Settings > Tokens.
Set up in the dashboard
Configure the sandbox in the dashboard under Settings > Sandbox CLIs.
Find Terraform in the catalog
In Settings > Sandbox CLIs, find Terraform under Browse sandbox CLIs and choose to connect it.
Provide credentials
Enter the required value: TF_TOKEN_app_terraform_io (your Terraform Cloud API token). Terraform reads credentials for app.terraform.io from this exact variable name. Save to store it securely; Sazabi injects it into the sandbox when the agent runs.
Set up with the CLI
You can also configure the Terraform CLI connection with the Sazabi CLI (installed and authenticated — see CLI reference).
sazabi sandbox-clis set --type terraform --env TF_TOKEN_app_terraform_io=<your-terraform-token>To validate the credentials without saving, run the same command with test in place of set (the test command also requires the --env flags).
Verify
Ask the agent, in a thread, to run the terraform CLI (a read-only or status command) and confirm it returns real output. If the command is not found, the CLI connection may not be enabled; if it runs unauthenticated or cannot connect, recheck the credentials.
Troubleshooting
Command not found — Confirm the Terraform CLI connection is enabled for the project under Settings > Sandbox CLIs.
Authentication or connection fails — Recheck the credential/connection values under Settings > Sandbox CLIs.