Advanced examples
The maintained Debian VM Cookbook uses a Secret-backed Custom Provider. Its separate guest mints a short-lived token. Terraform runs in the recipe guest without the stored cloud key.
The recipe owns cloud work and state. The Provider supplies bounded short-lived context for the exact job. Terraform writes local state to the private workspace. LEMC rehydrates and publishes that workspace through its internal object store. An independent cloud inventory check proves teardown.
Secret-backed GCP example
The Cookbook has Build and Teardown recipes on one workspace page. Each recipe image owns one Terraform module. A failed apply stays failed. A later explicit action reads the rehydrated private workspace state.
Provider and cleanup safety
- The Custom Provider Profile pins an exact OCI image and result schema.
- The Cookbook binds an owner-qualified Secret to the approved Profile.
- Only the Provider guest gets the stored key. The recipe gets bounded short-lived context.
- Each fixed Terraform module uses a local backend below
/lemc/private/terraform/. The GCP service account needs no state-bucket access. - A controlled stop can publish only the state that Terraform wrote before the stop. A Runner or host loss before publication can lose the most recent local update.
- A destroy result is valid only after an independent cloud inventory check is empty.
Source contract
The website build publishes only tracked source from the maintained Cookbook directory. It rejects internal fixtures, untracked files, local state, and secret-shaped artifacts.