Skip to content

fix(snippets): switch Atlas Terraform template to service accounts and advanced_cluster - #1370

Merged
Anemy merged 2 commits into
mongodb-js:mainfrom
xargom:sa-auth-atlas-terraform-snippet
Oct 5, 2026
Merged

Anemy merged 2 commits into
mongodb-js:mainfrom
xargom:sa-auth-atlas-terraform-snippet

Conversation

@xargom

@xargom xargom commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Changes

  1. Authentication — the atlas snippet now configures client_id/client_secret (service accounts), the provider's recommended authentication method, with a comment noting that API keys (public_key/private_key) remain supported. See the provider authentication guide.
  2. Cluster resource — the snippet now uses mongodbatlas_advanced_cluster to create the Flex cluster (provider_name = "FLEX", priority = 7), following the recommendation on the flex_cluster resource docs: advanced_cluster also supports dedicated clusters, making migration between cluster types easier. The connection_strings output is adjusted accordingly.

Follow-up to #1363.

Verification

The snippet's exact emitted text (tab stops filled, only the credential lines wired to variables) was run through terraform init and terraform plan against a live Atlas deployment with provider v2.18.0: Plan: 4 to add, 0 to change, 0 to destroy with no errors or warnings. The same configuration was also applied end-to-end: the Flex cluster was created in ~11 seconds and cleanly destroyed afterwards. All runs authenticated with a service account.

The provider's own docs recommend service accounts as the authentication
method, with API keys still supported. Update the snippet to configure
client_id/client_secret and note the API-key alternative with a link to
the provider's authentication guide.
@xargom
xargom requested a review from a team as a code owner September 25, 2026 17:15
@xargom
xargom requested review from paula-stacho and a lite review from Copilot September 25, 2026 17:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The remaining API access-list documentation gap is a minor, non-blocking nit.

Review effort: Lite
Findings: None

What changed in this PR

Updates the Atlas Terraform snippet to use recommended service-account authentication while retaining API-key guidance.

Changes:

  • Replaces API-key credentials with client_id and client_secret.
  • Updates authentication documentation and links.
  • Configures the provider with service-account credentials.
File Summary
snippets/​atlas-terraform.json Updates Atlas authentication guidance, credential placeholders, and provider configuration.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@xargom
xargom marked this pull request as draft September 29, 2026 17:18
…the Flex cluster

The provider's flex_cluster documentation recommends using
mongodbatlas_advanced_cluster to create and manage Flex clusters, since
it also supports dedicated clusters and makes migrating between cluster
types easier. Update the snippet to use the advanced_cluster resource
with provider_name = "FLEX" and priority = 7, and adjust the
connection_strings output accordingly.
@xargom xargom changed the title Switch Atlas Terraform template auth to service accounts Update Atlas Terraform template: service account auth and advanced_cluster resource Sep 29, 2026
@xargom
xargom marked this pull request as ready for review September 29, 2026 18:18
@xargom
xargom marked this pull request as draft September 29, 2026 18:51
@xargom
xargom marked this pull request as ready for review September 29, 2026 18:54
@xargom xargom changed the title Update Atlas Terraform template: service account auth and advanced_cluster resource fix(snippets): switch Atlas Terraform template to service accounts and advanced_cluster Oct 2, 2026
@johnjackweir johnjackweir added the no-title-validation Skips validation of PR titles (conventional commit adherence + JIRA ticket inclusion) label Oct 5, 2026
@Anemy
Anemy merged commit e5af67b into mongodb-js:main Oct 5, 2026
21 of 26 checks passed
mongodb-server-docs-sync-bot Bot pushed a commit to mongodb/docs that referenced this pull request Oct 5, 2026
… v1 provider syntax (#24273)

## DESCRIPTION

Updates the "Create an Atlas Cluster from a Template using Terraform"
tutorial to match the extension's current Terraform template, fixed by
mongodb-js/vscode PRs #1363 and #1370: the deprecated M2 shared-tier
cluster is replaced with a Flex cluster created through the
provider-recommended `mongodbatlas_advanced_cluster` resource, and
API-key auth is replaced with service accounts. All three sample
terminal outputs are regenerated from a live Terraform run against
provider v2.18.0 (plan/apply verified end-to-end).

**Hold merge until the next MongoDB for VS Code extension release ships
[mongodb-js/vscode#1370](mongodb-js/vscode#1370
Current state (2026-10-05): #1363 is shipped in extension release
v1.18.0 (published 2026-09-25); #1370 merged 2026-10-05 and is not yet
in any released version. Until that release ships, the snippet generates
`mongodbatlas_flex_cluster` with API-key locals, while this tutorial
documents `mongodbatlas_advanced_cluster` with
`client_id`/`client_secret` — the tutorial's variable names would not
match the generated file.

Changes per file:

- **create-cluster-terraform.txt** — Prerequisites now require a service
account (with link to the service-account docs) instead of an API key.
Intro and meta description now say Flex cluster instead of Shared Tier.
Refreshed the dead Terraform install link.
- **index.txt** — The two landing-page bullets about this tutorial now
say "Flex cluster" instead of "Shared Tier cluster".
- **steps-atlas-terraform-file-from-template.yaml** — The cluster
configuration table now covers `mongodbatlas_advanced_cluster` (`.name`,
`.replication_specs.region_configs.backing_provider_name`,
`.replication_specs.region_configs.region_name`). The locals table and
input-variables example use `client_id`/`client_secret`, with a note
that API keys remain supported but service accounts are the recommended
method (links the provider's authentication guide). Added a pointer to
the official cluster module for production deployments. Also fixed a
`vars.` → `var.` Terraform syntax error, dead HashiCorp links, and
retargeted the limitations note to the Flex limitations page.
- **steps-create-atlas-cluster-terraform.yaml** — The init/plan/apply
steps now use `io-code-block` (inline command as input, existing output
includes collapsed by default) per review feedback, keeping the page
condensed; "displayed connection strings" made singular.
- **steps-delete-atlas-cluster-terraform.yaml** — Fixed the destroy step
title, which incorrectly said "to install the required providers".
- **terraform-init-output.sh** — Regenerated from a live `terraform
init` (Terraform 1.13, provider v2.18.0 under the `~> 2.0` pin).
- **terraform-plan-output.sh** — Regenerated from a live `terraform
plan` of the `advanced_cluster` Flex configuration (4 resources,
`provider_name = "FLEX"`, `priority = 7`,
`mongodbatlas_project_ip_access_list`, no deprecation warnings).
- **terraform-apply-output.sh** — Regenerated from a live `terraform
apply` tail, showing the single-string `connection_strings` output.

## STAGING

- [Create an Atlas Cluster from a Template using
Terraform](https://deploy-preview-24273--mongodb-vscode-docs.netlify.app/docs/mongodb-vscode/create-cluster-terraform/)
— Check that all procedure steps render correctly and the sample
init/plan/apply outputs match the described Flex cluster (via
`mongodbatlas_advanced_cluster`) and service-account flow.
- [MongoDB for VS Code
Extension](https://deploy-preview-24273--mongodb-vscode-docs.netlify.app/docs/mongodb-vscode/)
— Check that the two Terraform bullets now say "Flex cluster".

## JIRA

[DOCSP-64461](https://jira.mongodb.org/browse/DOCSP-64461)

## SELF-REVIEW CHECKLIST

- [ ] Does each file have 3-5 taxonomy facet tags?
See the [taxonomy tagging
instructions](https://wiki.corp.mongodb.com/display/DE/Taxonomy+tagging+instructions)
and this [example
PR](https://github.com/10gen/cloud-docs/pull/5042/files)
- [ ] Is this free of any warnings or errors in the RST?
- [ ] Is this free of spelling errors?
- [ ] Is this free of grammatical errors?
- [ ] Is this free of staging / rendering issues?
- [ ] Are all the links working?

## EXTERNAL REVIEW REQUIREMENTS

[What's expected of an external
reviewer?](https://wiki.corp.mongodb.com/display/DE/Reviewing+Guidelines+for+the+MongoDB+Server+Documentation)

---------

Co-authored-by: osharaf-mdb <omar.sharaf@mongodb.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-title-validation Skips validation of PR titles (conventional commit adherence + JIRA ticket inclusion)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants