Terraform Provider Resources Implementation Guide
Overview
This guide covers developing Terraform Provider resources and data sources. Resources represent infrastructure objects that Terraform manages through Create, Read, Update, and Delete (CRUD) operations.
Use the Plugin Framework
for all net-new resources and data sources. Plugin SDKv2 is for maintaining
resources that already exist on it; do not write new code against it. A
provider can serve both during migration by muxing
(terraform-plugin-mux),
so adopting the Framework never requires a big-bang rewrite. To tell which
mode an existing provider is in, check go.mod: terraform-plugin-mux
present means it serves both SDKv2 and Framework code; only
terraform-plugin-sdk/v2 means SDKv2-only; only
terraform-plugin-framework means Framework-only. Be cautious about
migrating existing SDKv2 resources: the Framework distinguishes null from
zero values, so naive migrations change behavior for existing users (use the
provider-framework-migration skill, if available).
References (load when needed):
references/design-principles.md— what should (and should not) become a resource; data source semantics; relationship and async-task modelingreferences/retries-and-waiters.md— eventual consistency, retry patterns, and status/wait function structure
File Structure
Most providers keep every resource in a single package:
Large multi-service providers (e.g. terraform-provider-aws) split into
internal/service/<service>/ packages instead, with an idiomatic file
taxonomy worth adopting once a package grows: consts.go, find.go
(finders), status.go (status functions), wait.go (waiters), sweep.go
(test sweepers), exports_test.go.
Documentation lives in docs/ and is generated with tfplugindocs:
(Hand-written website/docs/r/*.html.markdown trees exist in some older,
large providers — follow the target repo's convention when editing one.)
Resource Structure
A Framework resource is a struct holding the API client, with interface assertions making the implemented behaviors explicit:
How the provider's Configure produces that client — schema, credential
resolution, validation — is covered by the provider-configuration skill
(if available).
On id: SDKv2 required a magic id attribute; the Framework does not.
If the API has its own identifier, expose it under its real meaning and do
not add a second, redundant id. Only keep id when it is the API's
identifier (as above).
CRUD Operations
Create
Read
Read must handle out-of-band deletion by removing the resource from state so the next plan recreates it, rather than erroring forever:
Update
Only call the API for attributes that actually changed; compare plan against state:
Delete
Treat "already gone" as success — the desired end state is reached:
Import
With ResourceWithImportState asserted, passthrough of the identifier is
one line:
For multi-part identifiers, parse a delimited import ID (commonly comma-separated) and set each attribute explicitly.
Resource Design Principles
Before implementing, check the shape of the thing being modeled (full
treatment in references/design-principles.md):
- A resource is the smallest useful building block; if the API offers CRUD for it, it likely deserves its own resource.
- A resource should talk to one API/service only — cross-service resources break permissions, auditing, and endpoint configuration.
- Data sources are read-only and side-effect free. A singular data source errors on zero or multiple matches; a plural data source (plural noun name) returns zero-or-more as a collection and errors on neither.
- Attached policies/rules, long-running task invocations, and versioned artifacts usually deserve their own resources rather than attributes on the parent.
- Start/stop or enable/disable state belongs as an attribute in the resource, not as a separate resource.
Schema Design
Attribute Types
Give every attribute a MarkdownDescription — tfplugindocs publishes it,
and it is the primary user-facing documentation.
Plan Modifiers
Validators
Sensitive Attributes
State Management
Finders
Centralize "get one thing or a typed not-found" in a finder so Read, Delete, waiters, and tests all share identical not-found semantics:
Waiting for Resource States
Many APIs return from Create/Delete before the resource is usable/gone. Use
retry.StateChangeConf (from
github.com/hashicorp/terraform-plugin-sdk/v2/helper/retry — usable from
Framework providers), with a status function built on the finder and
timeouts in named constants:
The full status/wait function pairs (create and delete waiters, failure-state
handling, post-create not-found retries, eventual-consistency patterns) are
in references/retries-and-waiters.md — read it whenever the API is
asynchronous or eventually consistent.
Testing
Every resource ships with, at minimum:
_basic— create with minimal config, assert attributes, then an import step (ImportState: true,ImportStateVerify: true)_disappears— delete the object out-of-band mid-test; the next plan must propose recreation, not error- Per-attribute tests — exercise updates for each non-trivial argument
Naming grammar: tests TestAcc{Resource}_{group?}_{description}, helpers
testAccCheck{Resource}Exists / testAccCheck{Resource}Destroy, config
functions testAcc{Resource}Config_{description}. Keep configs
self-contained, randomize real resource names, and never hardcode
environment-specific values (account IDs, zones, versions).
Use the provider-test-patterns skill (if available) for the full testing
treatment: config helper style (%[1]q indexed verbs), statecheck/plancheck,
CompareValue, custom StateCheck implementations for exists/disappears
helpers, sweepers, and ephemeral resource testing. Use the
run-acceptance-tests skill for executing and debugging test runs.
Error Handling
Match API errors by type, not message text, and wrap with context:
Diagnostics follow a consistent grammar — summary names the operation and type, detail carries identifier and cause:
Documentation
Write attribute MarkdownDescriptions first — they are the source of
truth. Then generate Registry documentation with tfplugindocs
(go generate ./... where wired up), adding docs/**/*.md.tmpl templates
only for prose and examples the generator cannot derive. Use the
provider-docs skill (if available) for the full documentation workflow and
Registry publication rules.
Pre-Submission Checklist
- Plugin Framework used (no new SDKv2 code)
- Resource has all CRUD operations implemented
- Read removes missing resources from state; Delete tolerates already-deleted
- No redundant
idattribute (real API identifier exposed instead) - Import implemented and covered by an
ImportStateVerifystep -
_basic,_disappears, and per-attribute tests present - Waiters used where the API is eventually consistent
- Error messages name the operation, type, and identifier
- Sensitive attributes marked; every attribute has a description
- Docs generated with
tfplugindocs - Changelog entry added, if the repo tracks release notes (check CONTRIBUTING)
