Skip to main content

Terraform and OpenTofu Operations

Updated on
Oct 06, 2026

Protect state and credentials​

Set QUICKNODE_API_KEY through your shell or CI secret store. The provider reads it from the environment, so it does not need to appear in your .tf files. Terraform state can still contain resource values, destination credentials, and token-bearing endpoint URLs. Store state in a backend with encryption and access controls, and do not commit local state files.

The quicknode_endpoint resource exposes redacted safe_http_url and safe_wss_url attributes. When you need a working RPC URL, use the sensitive values from data.quicknode_endpoint_urls or the endpoint token resource. See the provider overview for the distinction.

Decide who owns a Key-Value Store list​

Use quicknode_kv_list when Terraform should own every item in a list. A later apply removes items added outside the configuration.

Use quicknode_kv_list_items when a Stream filter or another tool also writes to the list. Terraform then manages only the configured items and leaves the others alone. Do not manage the same key with both resources. List items are case-sensitive, including wallet addresses.

Use quicknode_kv_value for a setting that Terraform owns. If a Stream filter writes to the same value, the next apply sets it back to the configured value. Keep runtime counters and cursors outside Terraform-managed values.

Import existing resources​

If a resource already exists in Quicknode, define it in HCL and import it before applying changes. For example, add this resource to a configuration that already declares the quicknode/quicknode provider. Set value to the value currently stored in your account:

resource "quicknode_kv_value" "threshold" {
key = "alert-threshold"
value = "100"
}

Import the existing value by its key, then review the plan:

terraform import quicknode_kv_value.threshold alert-threshold
terraform plan

Use tofu import and tofu plan with OpenTofu. Review the first plan closely: the configuration may differ from the live resource. Lists are also imported by key. For a partially managed list, use the list-items import instructions rather than importing the whole list.

Check Stream lifecycle changes​

The quicknode_stream resource declares status as active or paused. Quicknode may terminate a Stream after repeated delivery failures or when the account plan no longer allows it. On the next plan, the provider proposes the configured status again. A Stream that has completed its end_range cannot be resumed; changing it creates a replacement. Review the plan before applying either change.

For a new Stream, Quicknode tests filter_function against start_range during creation. Keep the filter in a versioned file, as in the KV-backed Stream example, and test the filter and destination before applying to a production pipeline.