diff --git a/terraform-reference/data-sources/environment.mdx b/terraform-reference/data-sources/environment.mdx
index 8b0eb41..389e37e 100644
--- a/terraform-reference/data-sources/environment.mdx
+++ b/terraform-reference/data-sources/environment.mdx
@@ -57,6 +57,18 @@ output "production_includes_scaling" {
value = data.kosli_environment.production.include_scaling
}
+# Access tags applied to the environment
+output "production_tags" {
+ description = "Tags applied to the production environment"
+ value = data.kosli_environment.production.tags
+}
+
+# Check if a specific tag exists
+output "production_managed_by" {
+ description = "Who manages the production environment (from tags)"
+ value = try(data.kosli_environment.production.tags["managed-by"], "unknown")
+}
+
# Conditional logic based on environment metadata
locals {
# Check if environment has never reported a snapshot
@@ -99,4 +111,5 @@ Data sources provide read-only access to environment metadata. To modify environ
- `include_scaling` (Boolean) Whether the environment includes scaling events in snapshots.
- `last_modified_at` (Number) Unix timestamp (with fractional seconds) of when the environment was last modified.
- `last_reported_at` (Number) Unix timestamp (with fractional seconds) of when the environment was last reported. May be null if never reported.
+- `tags` (Map of String) Key-value pairs tagging the environment.
- `type` (String) The environment type (e.g., K8S, ECS, S3, docker, server, lambda).
diff --git a/terraform-reference/data-sources/flow.mdx b/terraform-reference/data-sources/flow.mdx
index 5457056..dcfcebd 100644
--- a/terraform-reference/data-sources/flow.mdx
+++ b/terraform-reference/data-sources/flow.mdx
@@ -38,6 +38,11 @@ output "flow_template" {
description = "The YAML template of the flow"
value = data.kosli_flow.example.template
}
+
+output "flow_tags" {
+ description = "The tags of the flow"
+ value = data.kosli_flow.example.tags
+}
```
## Schema
@@ -49,4 +54,5 @@ output "flow_template" {
### Read-only
- `description` (String) The description of the flow.
+- `tags` (Map of String) Key-value pairs tagging the flow.
- `template` (String) YAML template defining the flow structure (trails, artifacts, attestations).
diff --git a/terraform-reference/data-sources/logical_environment.mdx b/terraform-reference/data-sources/logical_environment.mdx
index 6eb01ba..63b4d09 100644
--- a/terraform-reference/data-sources/logical_environment.mdx
+++ b/terraform-reference/data-sources/logical_environment.mdx
@@ -63,6 +63,11 @@ output "production_last_modified" {
value = data.kosli_logical_environment.production.last_modified_at
}
+output "production_tags" {
+ description = "Tags on the production logical environment"
+ value = data.kosli_logical_environment.production.tags
+}
+
# Count how many environments are aggregated
output "production_environment_count" {
description = "Number of environments aggregated in production"
@@ -183,4 +188,5 @@ locals {
- `description` (String) The description of the logical environment.
- `included_environments` (List of String) List of physical environment names aggregated by this logical environment.
- `last_modified_at` (Number) Unix timestamp (with fractional seconds) of when the logical environment was last modified.
+- `tags` (Map of String) Key-value pairs tagging the logical environment.
- `type` (String) The environment type (always `logical` for logical environments).
diff --git a/terraform-reference/resources/environment.mdx b/terraform-reference/resources/environment.mdx
index 74e69e3..07073fc 100644
--- a/terraform-reference/resources/environment.mdx
+++ b/terraform-reference/resources/environment.mdx
@@ -7,7 +7,7 @@ icon: "cube"
Manages a Kosli environment. Environments represent deployment targets where artifacts are deployed. Supports physical environment types: K8S, ECS, S3, docker, server, and lambda.
-This resource manages the environment configuration only. Environment tags are managed through a separate Kosli API. To attach compliance policies, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment). For querying environment metadata such as `last_modified_at`, `last_reported_at`, and `archived` status, use the [`kosli_environment` data source](/terraform-reference/data-sources/environment).
+This resource manages the environment configuration and tags. To attach compliance policies, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment). For querying environment metadata such as `last_modified_at`, `last_reported_at`, and `archived` status, use the [`kosli_environment` data source](/terraform-reference/data-sources/environment).
Kosli environments track deployments and provide visibility into what's running in your infrastructure. Physical environments represent actual runtime locations such as:
@@ -23,10 +23,6 @@ Kosli environments track deployments and provide visibility into what's running
For aggregating multiple physical environments into logical groups, use the [`kosli_logical_environment` resource](/terraform-reference/resources/logical_environment).
-
-Environment tags are managed through a separate Kosli API and are not included in this Terraform resource.
-
-
To attach compliance policies to environments, use the [`kosli_policy_attachment` resource](/terraform-reference/resources/policy_attachment).
@@ -49,6 +45,18 @@ resource "kosli_environment" "production_k8s" {
description = "Production Kubernetes cluster"
}
+# K8S environment with tags
+resource "kosli_environment" "tagged" {
+ name = "production-k8s-tagged"
+ type = "K8S"
+ description = "Production cluster managed by Terraform"
+ tags = {
+ managed-by = "terraform"
+ environment = "production"
+ team = "platform"
+ }
+}
+
# ECS environment with scaling
resource "kosli_environment" "staging_ecs" {
name = "staging-ecs"
@@ -133,3 +141,4 @@ For querying environment metadata such as `last_modified_at` and `last_reported_
- `description` (String) Description of the environment. Explains the purpose and characteristics of this deployment target.
- `include_scaling` (Boolean) Whether to include scaling information when reporting environment snapshots. Defaults to `false`.
+- `tags` (Map of String) Key-value pairs to tag the environment. Tags are applied via a diff — only changed tags are sent to the API. An empty map (`tags = {}`) removes all tags.
diff --git a/terraform-reference/resources/flow.mdx b/terraform-reference/resources/flow.mdx
index 4faa0c1..947322a 100644
--- a/terraform-reference/resources/flow.mdx
+++ b/terraform-reference/resources/flow.mdx
@@ -32,6 +32,17 @@ resource "kosli_flow" "with_description" {
description = "CD pipeline for the API service"
}
+# Flow with tags
+resource "kosli_flow" "tagged" {
+ name = "api-service-tagged"
+ description = "API service CD pipeline managed by Terraform"
+ tags = {
+ managed-by = "terraform"
+ team = "platform"
+ environment = "production"
+ }
+}
+
# Flow with a YAML template defining trails and attestations
# The template can also be loaded from a file: template = file("template.yml")
resource "kosli_flow" "with_template" {
@@ -74,4 +85,5 @@ terraform import kosli_flow.example my-flow-name
### Optional
- `description` (String) Description of the flow. Explains the purpose and context of this pipeline.
+- `tags` (Map of String) Key-value pairs to tag the flow. Tags are applied via a diff — only changed tags are sent to the API. An empty map (`tags = {}`) removes all tags.
- `template` (String) YAML template defining the flow structure (trails, artifacts, attestations). Can be provided as an inline heredoc or loaded from a file using `file()`. If omitted, the flow is created without a template.
diff --git a/terraform-reference/resources/logical_environment.mdx b/terraform-reference/resources/logical_environment.mdx
index 8d0987c..0ed87c9 100644
--- a/terraform-reference/resources/logical_environment.mdx
+++ b/terraform-reference/resources/logical_environment.mdx
@@ -11,7 +11,7 @@ Logical environments can ONLY contain physical environments (K8S, ECS, S3, docke
-This resource manages logical environment configuration only. For querying environment metadata such as `last_modified_at` and `archived` status, use the [`kosli_logical_environment` data source](/terraform-reference/data-sources/logical_environment).
+This resource manages logical environment configuration and tags. For querying environment metadata such as `last_modified_at` and `archived` status, use the [`kosli_logical_environment` data source](/terraform-reference/data-sources/logical_environment).
Logical environments in Kosli aggregate multiple physical environments for organizational purposes, providing:
@@ -86,6 +86,23 @@ resource "kosli_logical_environment" "future_environments" {
included_environments = []
}
+# Logical environment with tags
+resource "kosli_logical_environment" "tagged" {
+ name = "production-tagged"
+ description = "Tagged production logical environment"
+
+ included_environments = [
+ kosli_environment.production_k8s.name,
+ kosli_environment.production_ecs.name,
+ ]
+
+ tags = {
+ managed-by = "terraform"
+ environment = "production"
+ team = "platform"
+ }
+}
+
# Logical environment without description (optional)
resource "kosli_logical_environment" "simple" {
name = "simple-aggregate"
@@ -181,10 +198,6 @@ terraform import kosli_logical_environment.future_environments future-environmen
## Querying metadata
-
-This resource manages logical environment configuration only. For querying environment metadata such as `last_modified_at` and `archived` status, use the [`kosli_logical_environment` data source](/terraform-reference/data-sources/logical_environment).
-
-
## Schema
### Required
@@ -195,6 +208,7 @@ This resource manages logical environment configuration only. For querying envir
### Optional
- `description` (String) Description of the logical environment. Explains the purpose and aggregation strategy.
+- `tags` (Map of String) Key-value pairs to tag the logical environment. Tags are applied via a diff — only changed tags are sent to the API. An empty map (`tags = {}`) removes all tags.
### Read-only