Skip to content

Commit 16710c7

Browse files
committed
feat(postgresql): add tencentcloud_postgres_audit_log_file resource
1 parent 8a109d5 commit 16710c7

17 files changed

Lines changed: 2556 additions & 124 deletions

File tree

go.mod

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -73,7 +73,7 @@ require (
7373
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/monitor v1.3.101
7474
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/mps v1.3.45
7575
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/organization v1.3.89
76-
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/postgres v1.3.63
76+
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/postgres v1.3.89
7777
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/privatedns v1.1.42
7878
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/pts v1.0.762
7979
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/redis v1.3.73

go.sum

Lines changed: 2 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -837,8 +837,6 @@ github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/apm v1.3.8 h1:v/G/D3bqU
837837
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/apm v1.3.8/go.mod h1:DarTPk6LPu4LtKwDRbF2V2Af4KKXVXnzyteNhAifWm8=
838838
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/as v1.3.16 h1:0YPLYvTF/Jb2kzLQPTE9+SUHoOTinqxzLJpQNOg4Gcc=
839839
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/as v1.3.16/go.mod h1:1JNwb292Pt2CuxQOsgwdXFs2a79nLdwiFRXT0xKACkg=
840-
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/bh v1.3.68 h1:yyH8702x16BIh46K6vEeHoQiIHuKsYCye2Lj4lmtX98=
841-
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/bh v1.3.68/go.mod h1:ernIVPt8moCpVWvuoFsJ2OU29Gm6q0XCsY9gemtcR/0=
842840
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/bh v1.3.93 h1:6tYneudwMIvczAIH+6UT4A6DUKF9VPm6er+TIVGMyKg=
843841
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/bh v1.3.93/go.mod h1:4VE2PmQ0iUVzFkamod4wE2eKjW95NkfqP/sWymsReR4=
844842
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/bi v1.0.824 h1:DVKvZ6h+qd7tadUrCjVAkCCmE3TsbK2ZmwGd3AJcpWc=
@@ -944,7 +942,6 @@ github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.3.49/go.mod h
944942
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.3.58/go.mod h1:r5r4xbfxSaeR04b166HGsBa/R4U3SueirEUpXGuw+Q0=
945943
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.3.61/go.mod h1:r5r4xbfxSaeR04b166HGsBa/R4U3SueirEUpXGuw+Q0=
946944
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.3.62/go.mod h1:r5r4xbfxSaeR04b166HGsBa/R4U3SueirEUpXGuw+Q0=
947-
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.3.63/go.mod h1:r5r4xbfxSaeR04b166HGsBa/R4U3SueirEUpXGuw+Q0=
948945
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.3.65/go.mod h1:r5r4xbfxSaeR04b166HGsBa/R4U3SueirEUpXGuw+Q0=
949946
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.3.68/go.mod h1:r5r4xbfxSaeR04b166HGsBa/R4U3SueirEUpXGuw+Q0=
950947
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.3.69/go.mod h1:r5r4xbfxSaeR04b166HGsBa/R4U3SueirEUpXGuw+Q0=
@@ -1031,8 +1028,8 @@ github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/oceanus v1.0.831 h1:oya
10311028
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/oceanus v1.0.831/go.mod h1:2WuTlTnKCnZoa6l0JxY9GNfo0UG6nU7AEsljF8rMMsM=
10321029
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/organization v1.3.89 h1:blUboAc01iSj9pcQzHi1dazs8ZzZdchJLFUKr9TbAtQ=
10331030
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/organization v1.3.89/go.mod h1:S8liS/iJfdFylZjaw2KFxR3uIZlMPSCTTfvLdXfvxIo=
1034-
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/postgres v1.3.63 h1:Rp1k+hiuwz7Fk7mDcwA16CnuD/zZ0dLnuJEvz/7qmvc=
1035-
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/postgres v1.3.63/go.mod h1:I/76hHp9qIyl8MpmikfSc0YK0fGfokDXdDMPsBqVqXY=
1031+
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/postgres v1.3.89 h1:4HdSGx6XJb0/HVLKzWp7YdqvdeiISPAYsMjL9IJaXPI=
1032+
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/postgres v1.3.89/go.mod h1:7JNIsh6G2GmRhPIYUM4Sa/x1t57cWIBAempwHoMDMp4=
10361033
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/privatedns v1.1.42 h1:iTpAHqJrenwbFF1kE4DqYeuOMcm50L0YEoVTOQ3n/Ck=
10371034
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/privatedns v1.1.42/go.mod h1:nhF6hHhT7CJZC03MMwL1/QYDI/0q9rAcW/4tf0nhfFc=
10381035
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/pts v1.0.762 h1:rZDKucVVtTnmnbZFDyh6t47dHswkb2oSuOxOHTTkygA=
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
schema: spec-driven
2+
created: 2026-06-03
Lines changed: 55 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,55 @@
1+
## Context
2+
3+
TencentCloud PostgreSQL provides audit log file management through three cloud APIs:
4+
- `CreateAuditLogFile`: Creates an audit log file asynchronously (returns only RequestId, no FileName)
5+
- `DescribeAuditLogFiles`: Queries audit log files with pagination and optional FileName filter
6+
- `DeleteAuditLogFile`: Deletes an audit log file by FileName
7+
8+
The existing provider already has PostgreSQL resources under `tencentcloud/services/postgresql/`. The SDK package `github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/postgres/v20170312` is already vendored with all three APIs available.
9+
10+
Key constraint: `CreateAuditLogFile` is asynchronous - it does not return a FileName. After creation, we must poll `DescribeAuditLogFiles` to discover the newly created file and wait for its status to become `success`.
11+
12+
## Goals / Non-Goals
13+
14+
**Goals:**
15+
- Provide a Terraform resource `tencentcloud_postgres_audit_log_file` to manage audit log file lifecycle (create, read, delete)
16+
- Support filter conditions (AuditLogFilter) during file creation
17+
- Handle the asynchronous nature of file creation by polling until completion
18+
- Follow existing provider patterns for error handling, retry, and composite IDs
19+
20+
**Non-Goals:**
21+
- No Update operation (API does not support it)
22+
- No data source for listing audit log files (out of scope for this change)
23+
- No download functionality (DownloadUrl is exposed as computed attribute only)
24+
25+
## Decisions
26+
27+
### 1. Composite ID Format
28+
**Decision**: Use `instance_id + tccommon.FILED_SP + file_name` as the resource ID.
29+
**Rationale**: Both `instance_id` and `file_name` are required to uniquely identify and operate on an audit log file (Delete and Describe both require them). This follows the existing provider pattern for composite IDs.
30+
31+
### 2. Handling Asynchronous Creation
32+
**Decision**: After calling `CreateAuditLogFile`, poll `DescribeAuditLogFiles` (without FileName filter, sorted by creation time) to find the newly created file, then wait for its status to become `success`.
33+
**Rationale**: The Create API returns no FileName. We must list all files for the instance and identify the new one. Since we know the creation time window, we can find the most recently created file. Once identified, we set the resource ID and continue polling until status is `success`.
34+
**Alternative considered**: Using a fixed sleep - rejected because file creation time is unpredictable.
35+
36+
### 3. All Input Fields as ForceNew
37+
**Decision**: All user-provided input fields (`instance_id`, `start_time`, `end_time`, `product`, `filter`) are marked as `ForceNew: true`.
38+
**Rationale**: There is no Update API. Any change to input parameters requires destroying and recreating the resource. This is the standard Terraform pattern for immutable resources.
39+
40+
### 4. Schema Timeouts
41+
**Decision**: Declare `Create` and `Delete` timeouts in the schema. Create timeout is used for polling the async file creation.
42+
**Rationale**: File creation is asynchronous and may take variable time. Timeouts allow users to control how long to wait.
43+
44+
### 5. Read Implementation
45+
**Decision**: In the Read function, call `DescribeAuditLogFiles` with `FileName` filter to retrieve the specific file's metadata.
46+
**Rationale**: The API supports filtering by FileName, which efficiently retrieves a single file's status without pagination.
47+
48+
## Risks / Trade-offs
49+
50+
- [Risk] CreateAuditLogFile returns no identifier → We must discover the file by listing. If multiple files are created simultaneously, there's a small window for ambiguity.
51+
→ Mitigation: Poll immediately after creation and match by the most recent file that wasn't present before.
52+
53+
- [Risk] File creation may fail asynchronously (status becomes `failed`) → Mitigation: Check status during polling; if `failed`, return error with ErrMsg from the API response.
54+
55+
- [Trade-off] ForceNew on all fields means any parameter change destroys the file → This is acceptable because audit log files are inherently immutable once created.
Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
## Why
2+
3+
TencentCloud PostgreSQL supports audit log file management through cloud APIs (CreateAuditLogFile, DescribeAuditLogFiles, DeleteAuditLogFile). Currently, there is no Terraform resource to manage the lifecycle of audit log files. Users need a Terraform resource to create, query, and delete audit log files for their PostgreSQL instances in an infrastructure-as-code workflow.
4+
5+
## What Changes
6+
7+
- Add a new Terraform resource `tencentcloud_postgres_audit_log_file` (RESOURCE_KIND_ATTACHMENT) that manages the creation and deletion of PostgreSQL audit log files.
8+
- The resource supports:
9+
- Creating an audit log file with time range and optional filter conditions
10+
- Reading the audit log file status and metadata via DescribeAuditLogFiles
11+
- Deleting the audit log file via DeleteAuditLogFile
12+
- The resource uses a composite ID of `instance_id` + `file_name` (separated by `tccommon.FILED_SP`)
13+
- Since CreateAuditLogFile is asynchronous (returns no FileName), the Create function will poll DescribeAuditLogFiles until the file status becomes `success`
14+
- Only CRD operations are supported (no Update API), so all input fields are ForceNew
15+
16+
## Capabilities
17+
18+
### New Capabilities
19+
- `postgres-audit-log-file`: Terraform resource to create, read, and delete PostgreSQL audit log files with filter support
20+
21+
### Modified Capabilities
22+
23+
## Impact
24+
25+
- New file: `tencentcloud/services/postgresql/resource_tc_postgres_audit_log_file_attachment.go`
26+
- New file: `tencentcloud/services/postgresql/resource_tc_postgres_audit_log_file_attachment_test.go`
27+
- New file: `tencentcloud/services/postgresql/resource_tc_postgres_audit_log_file.md`
28+
- Modified: `tencentcloud/provider.go` (register new resource)
29+
- Modified: `tencentcloud/provider.md` (add resource entry)
30+
- Service layer: may extend existing `tencentcloud/services/postgresql/service_tencentcloud_postgresql.go`
31+
- Dependencies: uses existing `github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/postgres/v20170312` package (already vendored)
Lines changed: 71 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,71 @@
1+
## ADDED Requirements
2+
3+
### Requirement: Create audit log file
4+
The system SHALL provide a Terraform resource `tencentcloud_postgres_audit_log_file` that creates a PostgreSQL audit log file by calling the `CreateAuditLogFile` API with the specified instance ID, time range, product name, and optional filter conditions.
5+
6+
#### Scenario: Successful creation with all parameters
7+
- **WHEN** user applies a Terraform configuration with `tencentcloud_postgres_audit_log_file` specifying `instance_id`, `start_time`, `end_time`, `product`, and `filter` block
8+
- **THEN** the system SHALL call `CreateAuditLogFile` API with all provided parameters, poll `DescribeAuditLogFiles` until the file status becomes `success`, and set the resource ID as `instance_id#file_name`
9+
10+
#### Scenario: Successful creation without filter
11+
- **WHEN** user applies a Terraform configuration with `tencentcloud_postgres_audit_log_file` specifying only `instance_id`, `start_time`, `end_time`, and `product` (no filter)
12+
- **THEN** the system SHALL call `CreateAuditLogFile` API without the Filter parameter and poll until completion
13+
14+
#### Scenario: Creation fails asynchronously
15+
- **WHEN** the audit log file creation results in a `failed` status during polling
16+
- **THEN** the system SHALL return an error containing the ErrMsg from the API response
17+
18+
### Requirement: Read audit log file
19+
The system SHALL support reading the audit log file metadata by calling `DescribeAuditLogFiles` with the `InstanceId`, `Product`, and `FileName` parameters extracted from the resource ID.
20+
21+
#### Scenario: File exists and is readable
22+
- **WHEN** Terraform performs a refresh on an existing `tencentcloud_postgres_audit_log_file` resource
23+
- **THEN** the system SHALL call `DescribeAuditLogFiles` with the FileName filter and populate computed attributes (`file_name`, `status`, `file_size`, `create_time`, `download_url`, `err_msg`, `progress`, `finish_time`) from the response Items
24+
25+
#### Scenario: File no longer exists
26+
- **WHEN** Terraform performs a refresh and `DescribeAuditLogFiles` returns no matching items
27+
- **THEN** the system SHALL remove the resource from state (call `d.SetId("")`)
28+
29+
### Requirement: Delete audit log file
30+
The system SHALL support deleting the audit log file by calling `DeleteAuditLogFile` with `InstanceId`, `Product`, and `FileName` extracted from the resource ID.
31+
32+
#### Scenario: Successful deletion
33+
- **WHEN** user destroys a `tencentcloud_postgres_audit_log_file` resource
34+
- **THEN** the system SHALL call `DeleteAuditLogFile` API with the correct parameters and remove the resource from state
35+
36+
### Requirement: Resource schema definition
37+
The system SHALL define the resource schema with the following fields:
38+
39+
#### Scenario: Required input fields
40+
- **WHEN** the resource schema is defined
41+
- **THEN** the following fields SHALL be Required and ForceNew: `instance_id` (String), `start_time` (String), `end_time` (String), `product` (String)
42+
43+
#### Scenario: Optional input fields
44+
- **WHEN** the resource schema is defined
45+
- **THEN** the `filter` field SHALL be Optional and ForceNew, containing a nested block with fields: `affect_rows` (Int, Optional), `db_name` (List of String, Optional), `exec_time` (Int, Optional), `host` (List of String, Optional), `sql` (String, Optional), `user` (List of String, Optional), `sql_type` (List of String, Optional)
46+
47+
#### Scenario: Computed output fields
48+
- **WHEN** the resource schema is defined
49+
- **THEN** the following fields SHALL be Computed: `file_name` (String), `status` (String), `file_size` (Int), `create_time` (String), `download_url` (String), `err_msg` (String), `progress` (Int), `finish_time` (String)
50+
51+
### Requirement: Import support
52+
The system SHALL support importing existing audit log files using the composite ID format `instance_id#file_name`.
53+
54+
#### Scenario: Import by composite ID
55+
- **WHEN** user runs `terraform import tencentcloud_postgres_audit_log_file.example instance_id#file_name`
56+
- **THEN** the system SHALL parse the composite ID, call `DescribeAuditLogFiles` to read the file metadata, and populate the state
57+
58+
### Requirement: Retry and error handling
59+
The system SHALL wrap all API calls with retry logic using `tccommon.ReadRetryTimeout` and `tccommon.RetryError()`.
60+
61+
#### Scenario: Transient API failure during creation
62+
- **WHEN** `CreateAuditLogFile` API returns a transient error
63+
- **THEN** the system SHALL retry the call within the configured timeout
64+
65+
#### Scenario: Transient API failure during read
66+
- **WHEN** `DescribeAuditLogFiles` API returns a transient error
67+
- **THEN** the system SHALL retry the call within the configured timeout
68+
69+
#### Scenario: Transient API failure during deletion
70+
- **WHEN** `DeleteAuditLogFile` API returns a transient error
71+
- **THEN** the system SHALL retry the call within the configured timeout
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
## 1. Resource Implementation
2+
3+
- [x] 1.1 Create resource file `tencentcloud/services/postgresql/resource_tc_postgres_audit_log_file_attachment.go` with schema definition (Required+ForceNew: instance_id, start_time, end_time, product; Optional+ForceNew: filter block; Computed: file_name, status, file_size, create_time, download_url, err_msg, progress, finish_time; Timeouts: Create, Delete)
4+
- [x] 1.2 Implement Create function: call CreateAuditLogFile API with retry, then poll DescribeAuditLogFiles until file status is `success`, set composite ID (instance_id#file_name)
5+
- [x] 1.3 Implement Read function: parse composite ID, call DescribeAuditLogFiles with FileName filter, populate computed attributes (check nil before setting), remove from state if not found
6+
- [x] 1.4 Implement Delete function: parse composite ID, call DeleteAuditLogFile API with retry
7+
8+
## 2. Provider Registration
9+
10+
- [x] 2.1 Register `tencentcloud_postgres_audit_log_file` resource in `tencentcloud/provider.go`
11+
- [x] 2.2 Add resource entry in `tencentcloud/provider.md`
12+
13+
## 3. Documentation
14+
15+
- [x] 3.1 Create example documentation file `tencentcloud/services/postgresql/resource_tc_postgres_audit_log_file.md` with Example Usage and Import sections
16+
17+
## 4. Unit Tests
18+
19+
- [x] 4.1 Create test file `tencentcloud/services/postgresql/resource_tc_postgres_audit_log_file_attachment_test.go` with gomonkey-based unit tests for Create, Read, and Delete functions
20+
- [x] 4.2 Run unit tests with `go test -gcflags=all=-l` to verify they pass

0 commit comments

Comments
 (0)