From b5b99124d2e4b0a355553e7925fb4ad284c2e9ba Mon Sep 17 00:00:00 2001
From: "mintlify[bot]" <109931778+mintlify[bot]@users.noreply.github.com>
Date: Mon, 6 Apr 2026 09:13:47 +0000
Subject: [PATCH 1/3] docs: add April 6 changelog and update Terraform
reference docs
Generated-By: mintlify-agent
---
changelog/index.mdx | 45 +++++++++++
docs.json | 2 +
.../data-sources/environment.mdx | 28 +++++--
terraform-reference/data-sources/flow.mdx | 52 +++++++++++++
.../data-sources/logical_environment.mdx | 6 ++
terraform-reference/resources/environment.mdx | 23 ++++--
terraform-reference/resources/flow.mdx | 77 +++++++++++++++++++
.../resources/logical_environment.mdx | 18 +++++
8 files changed, 236 insertions(+), 15 deletions(-)
create mode 100644 terraform-reference/data-sources/flow.mdx
create mode 100644 terraform-reference/resources/flow.mdx
diff --git a/changelog/index.mdx b/changelog/index.mdx
index 1a5dc38e..8f29e958 100644
--- a/changelog/index.mdx
+++ b/changelog/index.mdx
@@ -4,6 +4,51 @@ description: "Release notes for Kosli products."
rss: true
---
+
+
+## New features
+
+- **`kosli_flow` resource and data source** — manage Kosli [flows](/getting_started/flows) as Terraform resources. Define name, description, and YAML template inline or via `file()`. The data source lets you query existing flows and reuse their templates. See the [resource](/terraform-reference/resources/flow) and [data source](/terraform-reference/data-sources/flow) reference.
+- **Tags support for environments** — the [`kosli_environment`](/terraform-reference/resources/environment) and [`kosli_logical_environment`](/terraform-reference/resources/logical_environment) resources and data sources now support a `tags` attribute for applying key-value metadata to your environments.
+
+[View on GitHub](https://github.com/kosli-dev/terraform-provider-kosli/releases/tag/v0.5.0)
+
+
+
+
+
+## New features
+
+- **`kosli evaluate input`** — evaluate a local JSON file (or stdin) against a Rego policy with no API dependency. Enables local policy development and fast iteration without a running Kosli server. See the [evaluate input](/client_reference/kosli_evaluate_input) reference.
+- **`--params` flag for policy evaluation** — pass configuration data (thresholds, expected counts, etc.) to Rego policies via `--params` on [`kosli evaluate trail`](/client_reference/kosli_evaluate_trail), [`kosli evaluate trails`](/client_reference/kosli_evaluate_trails), and [`kosli evaluate input`](/client_reference/kosli_evaluate_input). Accepts inline JSON or a file reference. Parameters are available as `data.params` in the policy.
+- **npm installation** — the Kosli CLI is now available as an npm package (`@kosli/cli`), making it easy to install in JavaScript/Node.js toolchains.
+
+## Bug fixes
+
+- Fixed Docker API version negotiation — the CLI now automatically negotiates the Docker API version with the host daemon, preventing compatibility errors after SDK upgrades.
+- Fixed AWS API rate limiting — snapshot commands for ECS, S3, and Lambda environments now use adaptive retry with up to 10 attempts, preventing failures under heavy API load.
+- Fixed git HEAD resolution in linked worktrees.
+
+
+
+
+
+## New features
+
+- **Deployment list** — the repository releases page now includes a deployments tab showing a paginated list of deployments with artifact details, commit links, replaced artifacts, and compliance status.
+- **Filter deployments by environment** — filter the deployment list and metrics by specific environments on the repository releases page.
+- **SCIM provisioning** — Kosli now supports SCIM-based user provisioning, enabling automated user lifecycle management through your identity provider.
+
+## Updates
+
+- Redesigned the repository run page with improved layout, hover states, and rich tooltips showing artifact fingerprints, snapshot references, and commit details.
+
+## Bug fixes
+
+- Fixed an error when viewing deployment details for artifacts with a missing replaced snapshot index.
+
+
+
## Updates
diff --git a/docs.json b/docs.json
index f06e0904..4a354d79 100644
--- a/docs.json
+++ b/docs.json
@@ -498,6 +498,7 @@
"pages": [
"terraform-reference/resources/environment",
"terraform-reference/resources/logical_environment",
+ "terraform-reference/resources/flow",
"terraform-reference/resources/custom_attestation_type",
"terraform-reference/resources/action",
"terraform-reference/resources/policy",
@@ -509,6 +510,7 @@
"pages": [
"terraform-reference/data-sources/environment",
"terraform-reference/data-sources/logical_environment",
+ "terraform-reference/data-sources/flow",
"terraform-reference/data-sources/custom_attestation_type",
"terraform-reference/data-sources/action",
"terraform-reference/data-sources/policy"
diff --git a/terraform-reference/data-sources/environment.mdx b/terraform-reference/data-sources/environment.mdx
index 8b0eb410..0e0e0c40 100644
--- a/terraform-reference/data-sources/environment.mdx
+++ b/terraform-reference/data-sources/environment.mdx
@@ -24,16 +24,21 @@ terraform {
}
}
-# Query an existing environment
-data "kosli_environment" "production" {
- name = "production-k8s"
+# Create an environment with tags
+resource "kosli_environment" "production" {
+ name = "production-k8s"
+ type = "K8S"
+ description = "Production Kubernetes cluster"
+ tags = {
+ managed-by = "terraform"
+ environment = "production"
+ team = "platform"
+ }
}
-# Use the data source to create a similar environment
-resource "kosli_environment" "staging" {
- name = "staging-k8s"
- type = data.kosli_environment.production.type
- description = "Staging environment similar to ${data.kosli_environment.production.name}"
+# Query the environment via data source to read back its attributes and tags
+data "kosli_environment" "production" {
+ name = kosli_environment.production.name
}
# Reference environment metadata for monitoring
@@ -57,6 +62,12 @@ output "production_includes_scaling" {
value = data.kosli_environment.production.include_scaling
}
+# Access tags applied to the environment
+output "production_tags" {
+ description = "Tags applied to the production environment"
+ value = data.kosli_environment.production.tags
+}
+
# Conditional logic based on environment metadata
locals {
# Check if environment has never reported a snapshot
@@ -99,4 +110,5 @@ Data sources provide read-only access to environment metadata. To modify environ
- `include_scaling` (Boolean) Whether the environment includes scaling events in snapshots.
- `last_modified_at` (Number) Unix timestamp (with fractional seconds) of when the environment was last modified.
- `last_reported_at` (Number) Unix timestamp (with fractional seconds) of when the environment was last reported. May be null if never reported.
+- `tags` (Map of String) Key-value pairs tagging the environment.
- `type` (String) The environment type (e.g., K8S, ECS, S3, docker, server, lambda).
diff --git a/terraform-reference/data-sources/flow.mdx b/terraform-reference/data-sources/flow.mdx
new file mode 100644
index 00000000..54570561
--- /dev/null
+++ b/terraform-reference/data-sources/flow.mdx
@@ -0,0 +1,52 @@
+---
+title: "kosli_flow data source"
+description: "Fetches details of an existing Kosli flow. Use this data source to reference flow configurations and templates."
+icon: "database"
+---
+
+Fetches details of an existing Kosli flow. A flow represents a business or software process that requires change tracking.
+
+## Example usage
+
+```terraform
+terraform {
+ required_providers {
+ kosli = {
+ source = "kosli-dev/kosli"
+ }
+ }
+}
+
+# Query an existing flow
+data "kosli_flow" "example" {
+ name = "my-application-flow"
+}
+
+# Create a new flow reusing the template from an existing one
+resource "kosli_flow" "copy" {
+ name = "my-application-flow-copy"
+ description = data.kosli_flow.example.description
+ template = data.kosli_flow.example.template
+}
+
+output "flow_name" {
+ description = "The name of the flow"
+ value = data.kosli_flow.example.name
+}
+
+output "flow_template" {
+ description = "The YAML template of the flow"
+ value = data.kosli_flow.example.template
+}
+```
+
+## Schema
+
+### Required
+
+- `name` (String) The name of the flow to query.
+
+### Read-only
+
+- `description` (String) The description of the flow.
+- `template` (String) YAML template defining the flow structure (trails, artifacts, attestations).
diff --git a/terraform-reference/data-sources/logical_environment.mdx b/terraform-reference/data-sources/logical_environment.mdx
index 6eb01bab..68bf7d18 100644
--- a/terraform-reference/data-sources/logical_environment.mdx
+++ b/terraform-reference/data-sources/logical_environment.mdx
@@ -90,6 +90,11 @@ output "production_includes_k8s" {
description = "Whether production aggregates a K8S environment"
value = local.includes_k8s
}
+
+output "production_tags" {
+ description = "Tags on the production logical environment"
+ value = data.kosli_logical_environment.production.tags
+}
```
## Type validation
@@ -183,4 +188,5 @@ locals {
- `description` (String) The description of the logical environment.
- `included_environments` (List of String) List of physical environment names aggregated by this logical environment.
- `last_modified_at` (Number) Unix timestamp (with fractional seconds) of when the logical environment was last modified.
+- `tags` (Map of String) Key-value pairs tagging the logical environment.
- `type` (String) The environment type (always `logical` for logical environments).
diff --git a/terraform-reference/resources/environment.mdx b/terraform-reference/resources/environment.mdx
index 74e69e34..17ff791e 100644
--- a/terraform-reference/resources/environment.mdx
+++ b/terraform-reference/resources/environment.mdx
@@ -6,9 +6,9 @@ icon: "cube"
Manages a Kosli environment. Environments represent deployment targets where artifacts are deployed. Supports physical environment types: K8S, ECS, S3, docker, server, and lambda.
-
-This resource manages the environment configuration only. Environment tags are managed through a separate Kosli API. To attach compliance policies, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment). For querying environment metadata such as `last_modified_at`, `last_reported_at`, and `archived` status, use the [`kosli_environment` data source](/terraform-reference/data-sources/environment).
-
+
+To attach compliance policies, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment). For querying environment metadata such as `last_modified_at`, `last_reported_at`, and `archived` status, use the [`kosli_environment` data source](/terraform-reference/data-sources/environment).
+
Kosli environments track deployments and provide visibility into what's running in your infrastructure. Physical environments represent actual runtime locations such as:
@@ -23,10 +23,6 @@ Kosli environments track deployments and provide visibility into what's running
For aggregating multiple physical environments into logical groups, use the [`kosli_logical_environment` resource](/terraform-reference/resources/logical_environment).
-
-Environment tags are managed through a separate Kosli API and are not included in this Terraform resource.
-
-
To attach compliance policies to environments, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment).
@@ -84,6 +80,18 @@ resource "kosli_environment" "serverless_functions" {
type = "lambda"
description = "AWS Lambda functions"
}
+
+# K8S environment with tags for IaC traceability
+resource "kosli_environment" "tagged" {
+ name = "production-k8s-tagged"
+ type = "K8S"
+ description = "Production cluster managed by Terraform"
+ tags = {
+ managed-by = "terraform"
+ environment = "production"
+ team = "platform"
+ }
+}
```
## Environment types
@@ -133,3 +141,4 @@ For querying environment metadata such as `last_modified_at` and `last_reported_
- `description` (String) Description of the environment. Explains the purpose and characteristics of this deployment target.
- `include_scaling` (Boolean) Whether to include scaling information when reporting environment snapshots. Defaults to `false`.
+- `tags` (Map of String) Key-value pairs to tag the environment.
diff --git a/terraform-reference/resources/flow.mdx b/terraform-reference/resources/flow.mdx
new file mode 100644
index 00000000..4faa0c10
--- /dev/null
+++ b/terraform-reference/resources/flow.mdx
@@ -0,0 +1,77 @@
+---
+title: "kosli_flow resource"
+description: "Manages a Kosli flow. Flows represent business or software processes that require change tracking."
+icon: "cube"
+---
+
+Manages a Kosli flow. A flow represents a business or software process that requires change tracking. It lets you monitor changes across all steps within a process or focus on a subset of critical steps.
+
+
+The `template` attribute accepts a YAML string defining the flow template structure. You can load it from a file using the `file()` function: `template = file("template.yml")`. Minor YAML formatting differences between what you provide and what the API returns may result in a no-op change being shown in plans.
+
+
+## Example usage
+
+```terraform
+terraform {
+ required_providers {
+ kosli = {
+ source = "kosli-dev/kosli"
+ }
+ }
+}
+
+# Minimal flow with only a name
+resource "kosli_flow" "minimal" {
+ name = "my-service"
+}
+
+# Flow with description
+resource "kosli_flow" "with_description" {
+ name = "api-service"
+ description = "CD pipeline for the API service"
+}
+
+# Flow with a YAML template defining trails and attestations
+# The template can also be loaded from a file: template = file("template.yml")
+resource "kosli_flow" "with_template" {
+ name = "backend-service"
+ description = "Backend service CD pipeline with full attestation template"
+
+ template = <<-YAML
+version: 1
+trail:
+ attestations:
+ - name: pull-request
+ type: pull_request
+ - name: unit-tests
+ type: generic
+ artifacts:
+ - name: docker-image
+ attestations:
+ - name: sbom
+ type: generic
+ - name: security-scan
+ type: snyk
+YAML
+}
+```
+
+## Import
+
+Flows can be imported using their name:
+
+```shell
+terraform import kosli_flow.example my-flow-name
+```
+
+## Schema
+
+### Required
+
+- `name` (String) Name of the flow. Must be unique within the organization. Changing this will force recreation of the resource.
+
+### Optional
+
+- `description` (String) Description of the flow. Explains the purpose and context of this pipeline.
+- `template` (String) YAML template defining the flow structure (trails, artifacts, attestations). Can be provided as an inline heredoc or loaded from a file using `file()`. If omitted, the flow is created without a template.
diff --git a/terraform-reference/resources/logical_environment.mdx b/terraform-reference/resources/logical_environment.mdx
index 8d0987c5..86a455e1 100644
--- a/terraform-reference/resources/logical_environment.mdx
+++ b/terraform-reference/resources/logical_environment.mdx
@@ -94,6 +94,23 @@ resource "kosli_logical_environment" "simple" {
kosli_environment.production_k8s.name,
]
}
+
+# Logical environment with tags
+resource "kosli_logical_environment" "tagged" {
+ name = "production-tagged"
+ description = "Tagged production logical environment"
+
+ included_environments = [
+ kosli_environment.production_k8s.name,
+ kosli_environment.production_ecs.name,
+ ]
+
+ tags = {
+ managed-by = "terraform"
+ environment = "production"
+ team = "platform"
+ }
+}
```
## Complete example
@@ -195,6 +212,7 @@ This resource manages logical environment configuration only. For querying envir
### Optional
- `description` (String) Description of the logical environment. Explains the purpose and aggregation strategy.
+- `tags` (Map of String) Key-value pairs to tag the logical environment.
### Read-only
From 583176b4f583efa34629983030c76e9c7a741d43 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Dan=20Gr=C3=B8ndahl?=
Date: Tue, 7 Apr 2026 09:11:11 +0200
Subject: [PATCH 2/3] fix: remove unreleased content and align with tagged
releases
- Remove tags attribute from environment/logical_environment docs (unreleased, after v0.5.0)
- Add CLI v2.15.1 version to changelog entry (all features verified in tag)
- Terraform Provider v0.5.0 changelog limited to kosli_flow only
- New flow resource and data source pages added to terraform-reference
---
changelog/index.mdx | 5 ++--
.../data-sources/environment.mdx | 28 ++++++-------------
.../data-sources/logical_environment.mdx | 6 ----
terraform-reference/resources/environment.mdx | 23 +++++----------
.../resources/logical_environment.mdx | 18 ------------
5 files changed, 18 insertions(+), 62 deletions(-)
diff --git a/changelog/index.mdx b/changelog/index.mdx
index 8f29e958..a12089e6 100644
--- a/changelog/index.mdx
+++ b/changelog/index.mdx
@@ -9,13 +9,12 @@ rss: true
## New features
- **`kosli_flow` resource and data source** — manage Kosli [flows](/getting_started/flows) as Terraform resources. Define name, description, and YAML template inline or via `file()`. The data source lets you query existing flows and reuse their templates. See the [resource](/terraform-reference/resources/flow) and [data source](/terraform-reference/data-sources/flow) reference.
-- **Tags support for environments** — the [`kosli_environment`](/terraform-reference/resources/environment) and [`kosli_logical_environment`](/terraform-reference/resources/logical_environment) resources and data sources now support a `tags` attribute for applying key-value metadata to your environments.
[View on GitHub](https://github.com/kosli-dev/terraform-provider-kosli/releases/tag/v0.5.0)
-
+
## New features
@@ -29,6 +28,8 @@ rss: true
- Fixed AWS API rate limiting — snapshot commands for ECS, S3, and Lambda environments now use adaptive retry with up to 10 attempts, preventing failures under heavy API load.
- Fixed git HEAD resolution in linked worktrees.
+[View on GitHub](https://github.com/kosli-dev/cli/releases/tag/v2.15.1)
+
diff --git a/terraform-reference/data-sources/environment.mdx b/terraform-reference/data-sources/environment.mdx
index 0e0e0c40..8b0eb410 100644
--- a/terraform-reference/data-sources/environment.mdx
+++ b/terraform-reference/data-sources/environment.mdx
@@ -24,21 +24,16 @@ terraform {
}
}
-# Create an environment with tags
-resource "kosli_environment" "production" {
- name = "production-k8s"
- type = "K8S"
- description = "Production Kubernetes cluster"
- tags = {
- managed-by = "terraform"
- environment = "production"
- team = "platform"
- }
+# Query an existing environment
+data "kosli_environment" "production" {
+ name = "production-k8s"
}
-# Query the environment via data source to read back its attributes and tags
-data "kosli_environment" "production" {
- name = kosli_environment.production.name
+# Use the data source to create a similar environment
+resource "kosli_environment" "staging" {
+ name = "staging-k8s"
+ type = data.kosli_environment.production.type
+ description = "Staging environment similar to ${data.kosli_environment.production.name}"
}
# Reference environment metadata for monitoring
@@ -62,12 +57,6 @@ output "production_includes_scaling" {
value = data.kosli_environment.production.include_scaling
}
-# Access tags applied to the environment
-output "production_tags" {
- description = "Tags applied to the production environment"
- value = data.kosli_environment.production.tags
-}
-
# Conditional logic based on environment metadata
locals {
# Check if environment has never reported a snapshot
@@ -110,5 +99,4 @@ Data sources provide read-only access to environment metadata. To modify environ
- `include_scaling` (Boolean) Whether the environment includes scaling events in snapshots.
- `last_modified_at` (Number) Unix timestamp (with fractional seconds) of when the environment was last modified.
- `last_reported_at` (Number) Unix timestamp (with fractional seconds) of when the environment was last reported. May be null if never reported.
-- `tags` (Map of String) Key-value pairs tagging the environment.
- `type` (String) The environment type (e.g., K8S, ECS, S3, docker, server, lambda).
diff --git a/terraform-reference/data-sources/logical_environment.mdx b/terraform-reference/data-sources/logical_environment.mdx
index 68bf7d18..6eb01bab 100644
--- a/terraform-reference/data-sources/logical_environment.mdx
+++ b/terraform-reference/data-sources/logical_environment.mdx
@@ -90,11 +90,6 @@ output "production_includes_k8s" {
description = "Whether production aggregates a K8S environment"
value = local.includes_k8s
}
-
-output "production_tags" {
- description = "Tags on the production logical environment"
- value = data.kosli_logical_environment.production.tags
-}
```
## Type validation
@@ -188,5 +183,4 @@ locals {
- `description` (String) The description of the logical environment.
- `included_environments` (List of String) List of physical environment names aggregated by this logical environment.
- `last_modified_at` (Number) Unix timestamp (with fractional seconds) of when the logical environment was last modified.
-- `tags` (Map of String) Key-value pairs tagging the logical environment.
- `type` (String) The environment type (always `logical` for logical environments).
diff --git a/terraform-reference/resources/environment.mdx b/terraform-reference/resources/environment.mdx
index 17ff791e..74e69e34 100644
--- a/terraform-reference/resources/environment.mdx
+++ b/terraform-reference/resources/environment.mdx
@@ -6,9 +6,9 @@ icon: "cube"
Manages a Kosli environment. Environments represent deployment targets where artifacts are deployed. Supports physical environment types: K8S, ECS, S3, docker, server, and lambda.
-
-To attach compliance policies, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment). For querying environment metadata such as `last_modified_at`, `last_reported_at`, and `archived` status, use the [`kosli_environment` data source](/terraform-reference/data-sources/environment).
-
+
+This resource manages the environment configuration only. Environment tags are managed through a separate Kosli API. To attach compliance policies, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment). For querying environment metadata such as `last_modified_at`, `last_reported_at`, and `archived` status, use the [`kosli_environment` data source](/terraform-reference/data-sources/environment).
+
Kosli environments track deployments and provide visibility into what's running in your infrastructure. Physical environments represent actual runtime locations such as:
@@ -23,6 +23,10 @@ Kosli environments track deployments and provide visibility into what's running
For aggregating multiple physical environments into logical groups, use the [`kosli_logical_environment` resource](/terraform-reference/resources/logical_environment).
+
+Environment tags are managed through a separate Kosli API and are not included in this Terraform resource.
+
+
To attach compliance policies to environments, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment).
@@ -80,18 +84,6 @@ resource "kosli_environment" "serverless_functions" {
type = "lambda"
description = "AWS Lambda functions"
}
-
-# K8S environment with tags for IaC traceability
-resource "kosli_environment" "tagged" {
- name = "production-k8s-tagged"
- type = "K8S"
- description = "Production cluster managed by Terraform"
- tags = {
- managed-by = "terraform"
- environment = "production"
- team = "platform"
- }
-}
```
## Environment types
@@ -141,4 +133,3 @@ For querying environment metadata such as `last_modified_at` and `last_reported_
- `description` (String) Description of the environment. Explains the purpose and characteristics of this deployment target.
- `include_scaling` (Boolean) Whether to include scaling information when reporting environment snapshots. Defaults to `false`.
-- `tags` (Map of String) Key-value pairs to tag the environment.
diff --git a/terraform-reference/resources/logical_environment.mdx b/terraform-reference/resources/logical_environment.mdx
index 86a455e1..8d0987c5 100644
--- a/terraform-reference/resources/logical_environment.mdx
+++ b/terraform-reference/resources/logical_environment.mdx
@@ -94,23 +94,6 @@ resource "kosli_logical_environment" "simple" {
kosli_environment.production_k8s.name,
]
}
-
-# Logical environment with tags
-resource "kosli_logical_environment" "tagged" {
- name = "production-tagged"
- description = "Tagged production logical environment"
-
- included_environments = [
- kosli_environment.production_k8s.name,
- kosli_environment.production_ecs.name,
- ]
-
- tags = {
- managed-by = "terraform"
- environment = "production"
- team = "platform"
- }
-}
```
## Complete example
@@ -212,7 +195,6 @@ This resource manages logical environment configuration only. For querying envir
### Optional
- `description` (String) Description of the logical environment. Explains the purpose and aggregation strategy.
-- `tags` (Map of String) Key-value pairs to tag the logical environment.
### Read-only
From 0ce83bc6404c7056cbc0d740efc090b7c3a177f2 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Dan=20Gr=C3=B8ndahl?=
Date: Tue, 7 Apr 2026 09:17:49 +0200
Subject: [PATCH 3/3] fix: remove SCIM provisioning from changelog
No documentation available yet for SCIM support.
---
changelog/index.mdx | 1 -
1 file changed, 1 deletion(-)
diff --git a/changelog/index.mdx b/changelog/index.mdx
index a12089e6..ce993c6e 100644
--- a/changelog/index.mdx
+++ b/changelog/index.mdx
@@ -38,7 +38,6 @@ rss: true
- **Deployment list** — the repository releases page now includes a deployments tab showing a paginated list of deployments with artifact details, commit links, replaced artifacts, and compliance status.
- **Filter deployments by environment** — filter the deployment list and metrics by specific environments on the repository releases page.
-- **SCIM provisioning** — Kosli now supports SCIM-based user provisioning, enabling automated user lifecycle management through your identity provider.
## Updates