Skip to main content

Atlas Configuration

atlas​

The atlas is an optional block for configuring Atlas login credentials and local behavior.

atlas {
cloud {
org = "org-name"
}
}

atlas blocks​

atlas.cache​

The cache block configures where Atlas stores its computed-state caches. Each cache type is stored under its own path inside the directory.

atlas {
cache {
dir = "s3://my-bucket/atlas-cache?region=us-east-1"
}
}
atlas.cache attributes​
Name and descriptionRequiredValue

dir

The dir attribute specifies the cache directory URL: a local directory or a blob storage bucket shared between machines. Defaults to file://~/.atlas/cache.

falsestring

atlas.cloud​

atlas.cloud attributes​
Name and descriptionRequiredValue

org

The org attribute specifies the organization to log in to. If Atlas executes using atlas.hcl without logging in to the specified organization, the command will be aborted.

falsestring

timeout

The timeout attribute bounds the total time of each Atlas Cloud request, including retries (minimum 1m). With backup storage configured, it controls how quickly Atlas fails over to the backups when Atlas Cloud is unreachable.

falsestring
tokenfalsestring
atlas.cloud constraints​
ConstraintValue
Requiredfalse
Require Namefalse
One of required sets[org, token]

atlas constraints​

ConstraintValue
Requiredfalse
Require Namefalse
One of required sets[cloud, cache]

check migrate_apply​

check.migrate_apply blocks​

check.allow​

check.allow attributes​
NameRequiredValue
conditiontruebool
check.allow constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., check.allow "name" )true

check.deny​

check.deny attributes​
NameRequiredValue
conditiontruebool
messagefalsestring
check.deny constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., check.deny "name" )true

check.drift​

The drift block enables pre-apply drift detection. When set, Atlas compares the actual database state against the expected state from the schema registry at the current revision version before applying migrations.

check.drift attributes​
Name and descriptionRequiredValue

exclude

List of glob patterns to exclude from drift inspection. Defaults to env.exclude if not set.

false

List of strings

on_error

The behavior when drift is detected. By default, drift causes the migration to abort. Set to CONTINUE to emit a warning and proceed.

false

enum (CONTINUE, FAIL)

check.migrate_apply constraints​

ConstraintValue
Requiredfalse
Repeatabletrue

check schema_apply​

check.schema_apply blocks​

check.allow​

check.allow attributes​
NameRequiredValue
conditiontruebool
check.allow constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., check.allow "name" )true

check.deny​

check.deny attributes​
NameRequiredValue
conditiontruebool
messagefalsestring
check.deny constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., check.deny "name" )true

check.schema_apply constraints​

ConstraintValue
Requiredfalse
Repeatabletrue

data aws_dsql_token​

The aws_dsql_token data source generates a short-lived token for an AWS Aurora DSQL database using IAM Authentication.

data "aws_dsql_token" "db" {
region = "us-east-1"
endpoint = local.endpoint
}

data.aws_dsql_token attributes​

Name and descriptionRequiredValue

admin

If true, generates an admin auth token. If false (default), generates a regular user auth token.

falsebool
endpointtruestring

profile

The AWS profile name to use from the shared credentials file. If not set, the default profile will be used.

falsestring
regionfalsestring

role_arn

ARN of the role to assume for generating the token.

falsestring

data aws_rds_token​

The aws_rds_token data source generates a short-lived token for an AWS RDS database using IAM Authentication.

data "aws_rds_token" "db" {
region = "us-east-1"
endpoint = local.endpoint
username = local.user
}

data.aws_rds_token attributes​

Name and descriptionRequiredValue
endpointtruestring

profile

The AWS profile name to use from the shared credentials file. If not set, the default profile will be used.

falsestring
regionfalsestring

role_arn

ARN of the role to assume for generating the token.

falsestring
usernametruestring

data azure_db_token​

The azure_db_token data source generates a short-lived Microsoft Entra access token for an Azure Database for PostgreSQL or MySQL server. Credentials are resolved by the Azure SDK default chain: environment variables, workload identity, managed identity, or the Azure CLI login.

data "azure_db_token" "db" {}

env "azure" {
# The Entra user contains "@", so it must be URL-escaped
# with urluserinfo (or urlescape) rather than interpolated.
url = urluserinfo(
"postgres://myserver.postgres.database.azure.com:5432/postgres?sslmode=require",
"app@contoso.onmicrosoft.com",
data.azure_db_token.db,
)
}

data.azure_db_token attributes​

Name and descriptionRequiredValue

scope

The token scope. Defaults to https://ossrdbms-aad.database.windows.net/.default, the resource of Azure Database for PostgreSQL and MySQL. Use https://token.postgres.cosmos.azure.com/.default for Azure Cosmos DB for PostgreSQL.

falsestring

tenant_id

The Microsoft Entra tenant to authenticate to. Defaults to the tenant of the signed-in identity.

falsestring

data blob_dir​

The blob_dir data source reads the state of a migration directory from the blob storage. Currently, it supports S3 (s3://).

data "blob_dir" "migrations" {
url = "s3://my-bucket/migrations?region=us-east-1&profile=aws-atlas"
}

data.blob_dir attributes​

NameRequiredValue
urltruestring

data.blob_dir exposed references​

NameValue
urlstring

data cloud_databases​

The cloud_databases reads the status of migration targets from Atlas Cloud.

data "cloud_databases" "dev" {
repo = "my-app"
env = "dev"
}

data.cloud_databases attributes​

Name and descriptionRequiredValue
envfalsestring

repo

The repo attribute specifies the migrate-directory name to filter the databases by.

truestring

data.cloud_databases exposed references​

NameValue
targetsany

data composite_schema​

The composite_schema data source allows the composition of multiple Atlas schemas into a unified schema graph.

data "composite_schema" "app" {
schema "inventory" {
url = data.external_schema.sqlalchemy.url
}
schema "graph" {
url = "ent://ent/schema"
}
...
}

data.composite_schema exposed references​

NameValue
urlstring

data.composite_schema blocks​

data.schema​

data.schema attributes​
NameRequiredValue
urltrue

Composite_schema url can be one of:

  1. Object reference
  2. string
data.schema constraints​
ConstraintValue
Requiredtrue
Require Namefalse
Repeatabletrue

data external​

The external allows the execution of an external program and uses its output in the project.

data "external" "dot_env" {
program = [
"npm",
"run",
"load-env.js"
]
}

data.external attributes​

NameRequiredValue
programtrue

List of strings

working_dirfalsestring

data external_schema​

The external_schema data source allows the import of an SQL schema from an external program into Atlas' desired state.

data "external_schema" "graph" {
program = [
"npm",
"run",
"generate-schema"
]
}

data.external_schema attributes​

NameRequiredValue
programtrue

List of strings

working_dirfalsestring

data.external_schema exposed references​

NameValue
urlstring

data gcp_cloudsql_token​

The gcp_cloudsql_token data source generates a short-lived token for an GCP CloudSQL database using IAM Authentication.

data "gcp_cloudsql_token" "db" {}

data.gcp_cloudsql_token attributes​

NameRequiredValue
regionfalsestring

data hcl_schema​

The hcl_schema data source allows the loading of an Atlas HCL schema from a file or directory, with optional variables.

data "hcl_schema" "app" {
path = "schema.hcl"
vars = {
tenant = var.tenant
}
}

data.hcl_schema attributes​

NameRequiredValue
pathfalsestring
pathsfalse

List of strings

varsfalsemap

data.hcl_schema exposed references​

NameValue
urlstring

data.hcl_schema blocks​

data.annotation​

data.annotation blocks​

data.annotation.attr​

data.annotation.attr attributes​
NameRequiredValue
requiredfalsebool
typetrue

HCL type (string, number, bool, list(string), etc)

data.annotation.attr constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., data.annotation.attr "name" )true
Repeatabletrue

data.annotation.block​

data.annotation.block attributes​
NameRequiredValue
repeatablefalsebool
requiredfalsebool
data.annotation.block blocks​

data.annotation.block.attr​

data.annotation.block.attr attributes​
NameRequiredValue
requiredfalsebool
typetrue

HCL type (string, number, bool, list(string), etc)

data.annotation.block.attr constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., data.annotation.block.attr "name" )true
Repeatabletrue

data.annotation.block.block​

data.annotation.block.block attributes​
NameRequiredValue
repeatablefalsebool
requiredfalsebool
data.annotation.block.block constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., data.annotation.block.block "name" )true
Repeatabletrue
data.annotation.block constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., data.annotation.block "name" )true
Repeatabletrue
data.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue

data http​

The http data source makes an HTTP GET/HEAD/POST request to the given URL and exports information about the response. The given URL may be either an http or https URL.

data.http attributes​

Name and descriptionRequiredValue

body

The request body as a string.

falsestring

ca_cert_pem

Certificate Authority (CA) in PEM (RFC 1421) format.

falsestring

client_cert_pem

Client certificate in PEM (RFC 1421) format.

falsestring

client_key_pem

Client key in PEM (RFC 1421) format.

falsestring

headers

A map of request header field names and values.

falsemap

insecure

Disables verification of the server's certificate chain and hostname. Defaults to false.

falsebool

method

The HTTP Method for the request. Allowed methods are a subset of methods defined in RFC7231 namely, GET, HEAD, and POST. POST support is only intended for read-only URLs, such as submitting a search. If omitted, the default method is GET.

false

enum (GET, HEAD, POST)

request_body

Deprecated: use body instead.

falsestring

request_headers

Deprecated: use headers instead.

falsemap

request_timeout_ms

The request timeout in milliseconds.

falseint

url

The URL for the request. Supported schemes are http and https.

truestring

data.http exposed references​

Name and descriptionValue

response_body

The response body returned as a string.

string

response_body_base64

The response body encoded as base64 (standard) as defined in RFC 4648.

string

response_headers

A map of response header field names and values. Duplicate headers are concatenated according to RFC2616.

map

status_code

The HTTP response status code.

int

url

The URL used for the request.

string

data.http blocks​

data.retry​

Retry request configuration. By default there are no retries. Configuring this block will result in retries if an error is returned by the client (e.g., connection errors) or if a 5xx-range (except 501) status code is received.

data.retry attributes​
Name and descriptionRequiredValue

attempts

The number of times the request is to be retried. For example, if 2 is specified, the request will be tried a maximum of 3 times.

falseint

max_delay_ms

The maximum delay between retry requests in milliseconds.

falseint

min_delay_ms

The minimum delay between retry requests in milliseconds.

falseint

data remote_dir​

The remote_dir data source reads the state of a migration directory from Atlas Cloud.

data "remote_dir" "migrations" {
name = "myapp"
}

data.remote_dir attributes​

NameRequiredValue
nametruestring
tagfalsestring

data.remote_dir exposed references​

NameValue
urlstring

data remote_schema​

data.remote_schema attributes​

NameRequiredValue
nametruestring
tagfalsestring
versionfalsestring

data.remote_schema exposed references​

NameValue
urlstring

data runtimevar​

The runtimevar data source allows fetching runtime variables from a remote source.

data.runtimevar attributes​

NameRequiredValue
urltruestring

data sql​

The sql data source allows executing SQL queries and using their result in the project.

data "sql" "tenants" {
url = var.url
query = "..."
args = [var.pattern]
}

data.sql attributes​

NameRequiredValue
argsfalse

Any value

querytruestring
urltruestring

data.sql exposed references​

NameValue
countint
valuestring
valuesstrings

data template_dir​

The template_dir data source renders a migration directory from a template directory.

data "template_dir" "app" {
path = var.path
vars = {
Key1 = "value1"
Key2 = "value2"
}
}

data.template_dir attributes​

NameRequiredValue
pathtruestring
varsfalsemap

data.template_dir exposed references​

NameValue
urlstring

deployment​

The deployment block defines a multi-tenant or deployment strategy with groups.

deployment "staged" {
variable "tier" {
type = string
}
group "canary" {
match = var.tier == "canary"
on_error = FAIL
}
group "rest" {
depends_on = [group.canary]
parallel = 32
on_error = CONTINUE
}
}

deployment blocks​

deployment.group​

The group block defines a deployment group with its execution settings.

deployment.group attributes​
Name and descriptionRequiredValue

depends_on

List of groups that must complete before this group starts.

false

List of object reference to group

match

Expression to filter which tenants belong to this group. Uses var.* to reference deployment variables.

false

Any value

on_error

Error handling mode: FAIL stops the entire deployment, CONTINUE logs and proceeds.

false

enum (FAIL, CONTINUE)

order_by

Expression or list of expressions to sort tenants within this group.

false

Any value

parallel

Maximum number of tenants to process in parallel within this group. Defaults to 1.

falseint
deployment.group constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., deployment.group "name" )true
Repeatabletrue

deployment.variable​

deployment.variable attributes​
NameRequiredValue
defaultfalse

Any value

descriptionfalsestring
typetrue

HCL type (string, number, bool, list(string), etc)

deployment.variable blocks​

deployment.variable.validation​

deployment.variable.validation attributes​
NameRequiredValue
conditiontruebool
error_messagefalsestring
deployment.variable.validation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue
deployment.variable constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., deployment.variable "name" )true

deployment constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., deployment "name" )true

dev clickhouse​

dev.clickhouse attributes​

NameRequiredValue
baselinefalsestring
urltruestring

dev.clickhouse exposed references​

NameValue
urlstring

dev.clickhouse blocks​

dev.connection​

The connection block defines the connection configuration for the dev-database.

dev "postgres" "postgis" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
dev.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

dev mariadb​

dev.mariadb attributes​

NameRequiredValue
baselinefalsestring
urltruestring

dev.mariadb exposed references​

NameValue
urlstring

dev.mariadb blocks​

dev.connection​

The connection block defines the connection configuration for the dev-database.

dev "postgres" "postgis" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
dev.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

dev mysql​

dev.mysql attributes​

NameRequiredValue
baselinefalsestring
urltruestring

dev.mysql exposed references​

NameValue
urlstring

dev.mysql blocks​

dev.connection​

The connection block defines the connection configuration for the dev-database.

dev "postgres" "postgis" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
dev.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

dev postgres​

dev.postgres attributes​

Name and descriptionRequiredValue
baselinefalsestring

template

If set, commands running multiple test cycles (e.g., schema test) run every cycle on a fresh copy of the database, which is significantly faster than replaying and restoring its state. The database is converted to a template for the duration of the run and restored at its end, and must be dedicated to Atlas.

falsebool
urltruestring

dev.postgres exposed references​

NameValue
urlstring

dev.postgres blocks​

dev.connection​

The connection block defines the connection configuration for the dev-database.

dev "postgres" "postgis" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
dev.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

dev redshift​

dev.redshift attributes​

NameRequiredValue
baselinefalsestring
urltruestring

dev.redshift exposed references​

NameValue
urlstring

dev.redshift blocks​

dev.connection​

The connection block defines the connection configuration for the dev-database.

dev "postgres" "postgis" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
dev.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

dev snowflake​

dev.snowflake attributes​

NameRequiredValue
baselinefalsestring
urltruestring

dev.snowflake exposed references​

NameValue
urlstring

dev.snowflake blocks​

dev.connection​

The connection block defines the connection configuration for the dev-database.

dev "postgres" "postgis" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
dev.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

dev sqlserver​

dev.sqlserver attributes​

NameRequiredValue
baselinefalsestring
urltruestring

dev.sqlserver exposed references​

NameValue
urlstring

dev.sqlserver blocks​

dev.connection​

The connection block defines the connection configuration for the dev-database.

dev "postgres" "postgis" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
dev.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

dev ysql​

dev.ysql attributes​

NameRequiredValue
baselinefalsestring
urltruestring

dev.ysql exposed references​

NameValue
urlstring

dev.ysql blocks​

dev.connection​

The connection block defines the connection configuration for the dev-database.

dev "postgres" "postgis" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
dev.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

diff clickhouse​

diff.clickhouse blocks​

diff.add_column​

diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_index​

diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_table​

diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

diff.cluster​

diff.cluster attributes​
NameRequiredValue
namefalsestring

diff.concurrent_index​

diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

diff.drop_table​

diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

diff.materialized​

diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

diff.session_settings​

diff.session_settings attributes​
NameRequiredValue
matchtruestring
valuesfalsemap
diff.session_settings constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue

diff.skip​

diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

diff mysql​

diff.mysql attributes​

NameRequiredValue
auto_incrementfalsebool

diff.mysql blocks​

diff.add_column​

diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_index​

diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_table​

diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

diff.concurrent_index​

diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

diff.drop_table​

diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

diff.materialized​

diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

diff.not_null​

diff.not_null attributes​
NameRequiredValue
checkfalsebool

diff.skip​

diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

diff postgres​

diff.postgres blocks​

diff.add_column​

diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_index​

diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_table​

diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

diff.concurrent_index​

diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

diff.drop_table​

diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

diff.materialized​

diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

diff.not_null​

diff.not_null attributes​
NameRequiredValue
checkfalsebool
lock_safefalsebool

diff.skip​

diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

diff redshift​

diff.redshift blocks​

diff.add_column​

diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_index​

diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_table​

diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

diff.concurrent_index​

diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

diff.drop_table​

diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

diff.materialized​

diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

diff.modify_column​

diff.modify_column attributes​
NameRequiredValue
allow_recreatefalsebool

diff.skip​

diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

diff sqlserver​

diff.sqlserver blocks​

diff.add_column​

diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_index​

diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

diff.add_table​

diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

diff.concurrent_index​

diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

diff.drop_table​

diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

diff.materialized​

diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

diff.not_null​

diff.not_null attributes​
NameRequiredValue
checkfalsebool

diff.skip​

diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

docker clickhouse​

docker.clickhouse attributes​

Name and descriptionRequiredValue

args

Additional arguments to pass to the docker run command when starting the container.

false

List of strings

baselinefalsestring

command

The command attribute specifies the command and its argument to run in the container overriding the default one.

false

List of strings

envfalse

List of strings

extra_hosts

The extra_hosts attribute adds host:ip entries to the container's /etc/hosts, similar to Docker Compose's extra_hosts. Use the special host-gateway value to reach the docker host. Maps to docker run --add-host.

docker "postgres" "dev" {
image = "postgres:18"
extra_hosts = [
"main_db:10.0.0.5",
"api.local:host-gateway",
]
}
false

List of strings

imagetruestring

init

The init attribute specifies the initialization script for the Docker-based database created in Atlas.

docker "mysql" "dev" {
image = "mysql:8.4"
init = <<-SQL
SET GLOBAL log_bin_trust_function_creators=true;
SET GLOBAL restrict_fk_on_non_standard_key=false;
SET GLOBAL sql_mode := REPLACE(@@sql_mode, 'NO_ZERO_DATE', '');
SQL
}
falsestring

platform

The platform attribute specifies the platform for the container. It defaults to the host platform if not specified. Examples: linux/amd64, linux/arm64, linux/arm/v7, etc.

falsestring
schemafalsestring

timeout

The timeout attribute specifies the timeout for waiting the container being ready to use. Defaults to 1m if not specified.

falsestring

volumes

The volumes attribute specifies volume mounts for the container.

docker "clickhouse" "dev" {
image = "clickhouse/clickhouse-server:24.10"
volumes = ["/path/to/users.xml:/etc/clickhouse-server/users.d/users.xml:ro"]
}
false

List of strings

docker.clickhouse exposed references​

NameValue
urlstring

docker.clickhouse blocks​

docker.build​

The build block defines the build configuration for the Docker image. The given image is built using the provided Dockerfile and context.

docker "postgres" "pg-vn" {
image = "postgres:15-vn"
build {
context = "."
dockerfile = "locale.Dockerfile"
args = {
LOCALE = "vi-VN"
}
}
}

Alternatively, you can define the Dockerfile inline:

docker "postgres" "dev" {
image = "postgres:15-custom"
build {
context = "."
dockerfile_inline = <<-EOF
FROM postgres:15
RUN apt-get update && apt-get install -y curl
EOF
}
}
docker.build attributes​
Name and descriptionRequiredValue
argsfalsemap
contexttruestring
dockerfilefalsestring

dockerfile_inline

The dockerfile_inline attribute allows defining the Dockerfile content inline. This is useful for simple Dockerfiles that don't require a separate file. Cannot be used together with the dockerfile attribute.

falsestring
platformfalse

List of strings

targetfalsestring
docker.build constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[dockerfile, dockerfile_inline]

docker.connection​

The connection block defines the connection configuration for the Docker-based database created in Atlas.

docker "postgres" "dev" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
docker.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

docker dsql​

docker.dsql attributes​

Name and descriptionRequiredValue

args

Additional arguments to pass to the docker run command when starting the container.

false

List of strings

baselinefalsestring

command

The command attribute specifies the command and its argument to run in the container overriding the default one.

false

List of strings

envfalse

List of strings

extra_hosts

The extra_hosts attribute adds host:ip entries to the container's /etc/hosts, similar to Docker Compose's extra_hosts. Use the special host-gateway value to reach the docker host. Maps to docker run --add-host.

docker "postgres" "dev" {
image = "postgres:18"
extra_hosts = [
"main_db:10.0.0.5",
"api.local:host-gateway",
]
}
false

List of strings

imagetruestring

init

The init attribute specifies the initialization script for the Docker-based database created in Atlas.

docker "mysql" "dev" {
image = "mysql:8.4"
init = <<-SQL
SET GLOBAL log_bin_trust_function_creators=true;
SET GLOBAL restrict_fk_on_non_standard_key=false;
SET GLOBAL sql_mode := REPLACE(@@sql_mode, 'NO_ZERO_DATE', '');
SQL
}
falsestring

platform

The platform attribute specifies the platform for the container. It defaults to the host platform if not specified. Examples: linux/amd64, linux/arm64, linux/arm/v7, etc.

falsestring
schemafalsestring

timeout

The timeout attribute specifies the timeout for waiting the container being ready to use. Defaults to 1m if not specified.

falsestring

volumes

The volumes attribute specifies volume mounts for the container.

docker "clickhouse" "dev" {
image = "clickhouse/clickhouse-server:24.10"
volumes = ["/path/to/users.xml:/etc/clickhouse-server/users.d/users.xml:ro"]
}
false

List of strings

docker.dsql exposed references​

NameValue
urlstring

docker.dsql blocks​

docker.build​

The build block defines the build configuration for the Docker image. The given image is built using the provided Dockerfile and context.

docker "postgres" "pg-vn" {
image = "postgres:15-vn"
build {
context = "."
dockerfile = "locale.Dockerfile"
args = {
LOCALE = "vi-VN"
}
}
}

Alternatively, you can define the Dockerfile inline:

docker "postgres" "dev" {
image = "postgres:15-custom"
build {
context = "."
dockerfile_inline = <<-EOF
FROM postgres:15
RUN apt-get update && apt-get install -y curl
EOF
}
}
docker.build attributes​
Name and descriptionRequiredValue
argsfalsemap
contexttruestring
dockerfilefalsestring

dockerfile_inline

The dockerfile_inline attribute allows defining the Dockerfile content inline. This is useful for simple Dockerfiles that don't require a separate file. Cannot be used together with the dockerfile attribute.

falsestring
platformfalse

List of strings

targetfalsestring
docker.build constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[dockerfile, dockerfile_inline]

docker.connection​

The connection block defines the connection configuration for the Docker-based database created in Atlas.

docker "postgres" "dev" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
docker.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

docker mariadb​

docker.mariadb attributes​

Name and descriptionRequiredValue

args

Additional arguments to pass to the docker run command when starting the container.

false

List of strings

baselinefalsestring

command

The command attribute specifies the command and its argument to run in the container overriding the default one.

false

List of strings

envfalse

List of strings

extra_hosts

The extra_hosts attribute adds host:ip entries to the container's /etc/hosts, similar to Docker Compose's extra_hosts. Use the special host-gateway value to reach the docker host. Maps to docker run --add-host.

docker "postgres" "dev" {
image = "postgres:18"
extra_hosts = [
"main_db:10.0.0.5",
"api.local:host-gateway",
]
}
false

List of strings

imagetruestring

init

The init attribute specifies the initialization script for the Docker-based database created in Atlas.

docker "mysql" "dev" {
image = "mysql:8.4"
init = <<-SQL
SET GLOBAL log_bin_trust_function_creators=true;
SET GLOBAL restrict_fk_on_non_standard_key=false;
SET GLOBAL sql_mode := REPLACE(@@sql_mode, 'NO_ZERO_DATE', '');
SQL
}
falsestring

platform

The platform attribute specifies the platform for the container. It defaults to the host platform if not specified. Examples: linux/amd64, linux/arm64, linux/arm/v7, etc.

falsestring
schemafalsestring

timeout

The timeout attribute specifies the timeout for waiting the container being ready to use. Defaults to 1m if not specified.

falsestring

volumes

The volumes attribute specifies volume mounts for the container.

docker "clickhouse" "dev" {
image = "clickhouse/clickhouse-server:24.10"
volumes = ["/path/to/users.xml:/etc/clickhouse-server/users.d/users.xml:ro"]
}
false

List of strings

docker.mariadb exposed references​

NameValue
urlstring

docker.mariadb blocks​

docker.build​

The build block defines the build configuration for the Docker image. The given image is built using the provided Dockerfile and context.

docker "postgres" "pg-vn" {
image = "postgres:15-vn"
build {
context = "."
dockerfile = "locale.Dockerfile"
args = {
LOCALE = "vi-VN"
}
}
}

Alternatively, you can define the Dockerfile inline:

docker "postgres" "dev" {
image = "postgres:15-custom"
build {
context = "."
dockerfile_inline = <<-EOF
FROM postgres:15
RUN apt-get update && apt-get install -y curl
EOF
}
}
docker.build attributes​
Name and descriptionRequiredValue
argsfalsemap
contexttruestring
dockerfilefalsestring

dockerfile_inline

The dockerfile_inline attribute allows defining the Dockerfile content inline. This is useful for simple Dockerfiles that don't require a separate file. Cannot be used together with the dockerfile attribute.

falsestring
platformfalse

List of strings

targetfalsestring
docker.build constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[dockerfile, dockerfile_inline]

docker.connection​

The connection block defines the connection configuration for the Docker-based database created in Atlas.

docker "postgres" "dev" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
docker.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

docker mysql​

docker.mysql attributes​

Name and descriptionRequiredValue

args

Additional arguments to pass to the docker run command when starting the container.

false

List of strings

baselinefalsestring

command

The command attribute specifies the command and its argument to run in the container overriding the default one.

false

List of strings

envfalse

List of strings

extra_hosts

The extra_hosts attribute adds host:ip entries to the container's /etc/hosts, similar to Docker Compose's extra_hosts. Use the special host-gateway value to reach the docker host. Maps to docker run --add-host.

docker "postgres" "dev" {
image = "postgres:18"
extra_hosts = [
"main_db:10.0.0.5",
"api.local:host-gateway",
]
}
false

List of strings

imagetruestring

init

The init attribute specifies the initialization script for the Docker-based database created in Atlas.

docker "mysql" "dev" {
image = "mysql:8.4"
init = <<-SQL
SET GLOBAL log_bin_trust_function_creators=true;
SET GLOBAL restrict_fk_on_non_standard_key=false;
SET GLOBAL sql_mode := REPLACE(@@sql_mode, 'NO_ZERO_DATE', '');
SQL
}
falsestring

platform

The platform attribute specifies the platform for the container. It defaults to the host platform if not specified. Examples: linux/amd64, linux/arm64, linux/arm/v7, etc.

falsestring
schemafalsestring

timeout

The timeout attribute specifies the timeout for waiting the container being ready to use. Defaults to 1m if not specified.

falsestring

volumes

The volumes attribute specifies volume mounts for the container.

docker "clickhouse" "dev" {
image = "clickhouse/clickhouse-server:24.10"
volumes = ["/path/to/users.xml:/etc/clickhouse-server/users.d/users.xml:ro"]
}
false

List of strings

docker.mysql exposed references​

NameValue
urlstring

docker.mysql blocks​

docker.build​

The build block defines the build configuration for the Docker image. The given image is built using the provided Dockerfile and context.

docker "postgres" "pg-vn" {
image = "postgres:15-vn"
build {
context = "."
dockerfile = "locale.Dockerfile"
args = {
LOCALE = "vi-VN"
}
}
}

Alternatively, you can define the Dockerfile inline:

docker "postgres" "dev" {
image = "postgres:15-custom"
build {
context = "."
dockerfile_inline = <<-EOF
FROM postgres:15
RUN apt-get update && apt-get install -y curl
EOF
}
}
docker.build attributes​
Name and descriptionRequiredValue
argsfalsemap
contexttruestring
dockerfilefalsestring

dockerfile_inline

The dockerfile_inline attribute allows defining the Dockerfile content inline. This is useful for simple Dockerfiles that don't require a separate file. Cannot be used together with the dockerfile attribute.

falsestring
platformfalse

List of strings

targetfalsestring
docker.build constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[dockerfile, dockerfile_inline]

docker.connection​

The connection block defines the connection configuration for the Docker-based database created in Atlas.

docker "postgres" "dev" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
docker.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

docker oracle​

docker.oracle attributes​

Name and descriptionRequiredValue

args

Additional arguments to pass to the docker run command when starting the container.

false

List of strings

baselinefalsestring

command

The command attribute specifies the command and its argument to run in the container overriding the default one.

false

List of strings

database

The database attribute specifies the Oracle Pluggable Database (PDB) name to connect to. If not specified, the default database is used. This option is only available for the Oracle Enterprise Image.

falsestring
envfalse

List of strings

extra_hosts

The extra_hosts attribute adds host:ip entries to the container's /etc/hosts, similar to Docker Compose's extra_hosts. Use the special host-gateway value to reach the docker host. Maps to docker run --add-host.

docker "postgres" "dev" {
image = "postgres:18"
extra_hosts = [
"main_db:10.0.0.5",
"api.local:host-gateway",
]
}
false

List of strings

imagetruestring

init

The init attribute specifies the initialization script for the Docker-based database created in Atlas.

docker "mysql" "dev" {
image = "mysql:8.4"
init = <<-SQL
SET GLOBAL log_bin_trust_function_creators=true;
SET GLOBAL restrict_fk_on_non_standard_key=false;
SET GLOBAL sql_mode := REPLACE(@@sql_mode, 'NO_ZERO_DATE', '');
SQL
}
falsestring
modefalse

enum (database, schema)

platform

The platform attribute specifies the platform for the container. It defaults to the host platform if not specified. Examples: linux/amd64, linux/arm64, linux/arm/v7, etc.

falsestring
schemafalsestring

timeout

The timeout attribute specifies the timeout for waiting the container being ready to use. Defaults to 1m if not specified.

falsestring

volumes

The volumes attribute specifies volume mounts for the container.

docker "clickhouse" "dev" {
image = "clickhouse/clickhouse-server:24.10"
volumes = ["/path/to/users.xml:/etc/clickhouse-server/users.d/users.xml:ro"]
}
false

List of strings

docker.oracle exposed references​

NameValue
urlstring

docker.oracle blocks​

docker.build​

The build block defines the build configuration for the Docker image. The given image is built using the provided Dockerfile and context.

docker "postgres" "pg-vn" {
image = "postgres:15-vn"
build {
context = "."
dockerfile = "locale.Dockerfile"
args = {
LOCALE = "vi-VN"
}
}
}

Alternatively, you can define the Dockerfile inline:

docker "postgres" "dev" {
image = "postgres:15-custom"
build {
context = "."
dockerfile_inline = <<-EOF
FROM postgres:15
RUN apt-get update && apt-get install -y curl
EOF
}
}
docker.build attributes​
Name and descriptionRequiredValue
argsfalsemap
contexttruestring
dockerfilefalsestring

dockerfile_inline

The dockerfile_inline attribute allows defining the Dockerfile content inline. This is useful for simple Dockerfiles that don't require a separate file. Cannot be used together with the dockerfile attribute.

falsestring
platformfalse

List of strings

targetfalsestring
docker.build constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[dockerfile, dockerfile_inline]

docker.connection​

The connection block defines the connection configuration for the Docker-based database created in Atlas.

docker "postgres" "dev" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
docker.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

docker postgres​

docker.postgres attributes​

Name and descriptionRequiredValue

args

Additional arguments to pass to the docker run command when starting the container.

false

List of strings

baselinefalsestring

command

The command attribute specifies the command and its argument to run in the container overriding the default one.

false

List of strings

databasefalsestring
envfalse

List of strings

extra_hosts

The extra_hosts attribute adds host:ip entries to the container's /etc/hosts, similar to Docker Compose's extra_hosts. Use the special host-gateway value to reach the docker host. Maps to docker run --add-host.

docker "postgres" "dev" {
image = "postgres:18"
extra_hosts = [
"main_db:10.0.0.5",
"api.local:host-gateway",
]
}
false

List of strings

imagetruestring

init

The init attribute specifies the initialization script for the Docker-based database created in Atlas.

docker "mysql" "dev" {
image = "mysql:8.4"
init = <<-SQL
SET GLOBAL log_bin_trust_function_creators=true;
SET GLOBAL restrict_fk_on_non_standard_key=false;
SET GLOBAL sql_mode := REPLACE(@@sql_mode, 'NO_ZERO_DATE', '');
SQL
}
falsestring

platform

The platform attribute specifies the platform for the container. It defaults to the host platform if not specified. Examples: linux/amd64, linux/arm64, linux/arm/v7, etc.

falsestring
schemafalsestring

template

If set, commands running multiple test cycles (e.g., schema test) run every cycle on a fresh copy of the database, which is significantly faster than replaying and restoring its state. Cannot be used together with the schema attribute.

falsebool

timeout

The timeout attribute specifies the timeout for waiting the container being ready to use. Defaults to 1m if not specified.

falsestring

volumes

The volumes attribute specifies volume mounts for the container.

docker "clickhouse" "dev" {
image = "clickhouse/clickhouse-server:24.10"
volumes = ["/path/to/users.xml:/etc/clickhouse-server/users.d/users.xml:ro"]
}
false

List of strings

docker.postgres exposed references​

NameValue
urlstring

docker.postgres blocks​

docker.build​

The build block defines the build configuration for the Docker image. The given image is built using the provided Dockerfile and context.

docker "postgres" "pg-vn" {
image = "postgres:15-vn"
build {
context = "."
dockerfile = "locale.Dockerfile"
args = {
LOCALE = "vi-VN"
}
}
}

Alternatively, you can define the Dockerfile inline:

docker "postgres" "dev" {
image = "postgres:15-custom"
build {
context = "."
dockerfile_inline = <<-EOF
FROM postgres:15
RUN apt-get update && apt-get install -y curl
EOF
}
}
docker.build attributes​
Name and descriptionRequiredValue
argsfalsemap
contexttruestring
dockerfilefalsestring

dockerfile_inline

The dockerfile_inline attribute allows defining the Dockerfile content inline. This is useful for simple Dockerfiles that don't require a separate file. Cannot be used together with the dockerfile attribute.

falsestring
platformfalse

List of strings

targetfalsestring
docker.build constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[dockerfile, dockerfile_inline]

docker.connection​

The connection block defines the connection configuration for the Docker-based database created in Atlas.

docker "postgres" "dev" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
docker.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

docker sqlserver​

docker.sqlserver attributes​

Name and descriptionRequiredValue

args

Additional arguments to pass to the docker run command when starting the container.

false

List of strings

baselinefalsestring
collatefalsestring

command

The command attribute specifies the command and its argument to run in the container overriding the default one.

false

List of strings

databasefalsestring
envfalse

List of strings

extra_hosts

The extra_hosts attribute adds host:ip entries to the container's /etc/hosts, similar to Docker Compose's extra_hosts. Use the special host-gateway value to reach the docker host. Maps to docker run --add-host.

docker "postgres" "dev" {
image = "postgres:18"
extra_hosts = [
"main_db:10.0.0.5",
"api.local:host-gateway",
]
}
false

List of strings

imagetruestring

init

The init attribute specifies the initialization script for the Docker-based database created in Atlas.

docker "mysql" "dev" {
image = "mysql:8.4"
init = <<-SQL
SET GLOBAL log_bin_trust_function_creators=true;
SET GLOBAL restrict_fk_on_non_standard_key=false;
SET GLOBAL sql_mode := REPLACE(@@sql_mode, 'NO_ZERO_DATE', '');
SQL
}
falsestring
modefalse

enum (database, schema)

platform

The platform attribute specifies the platform for the container. It defaults to the host platform if not specified. Examples: linux/amd64, linux/arm64, linux/arm/v7, etc.

falsestring
schemafalsestring

timeout

The timeout attribute specifies the timeout for waiting the container being ready to use. Defaults to 1m if not specified.

falsestring

volumes

The volumes attribute specifies volume mounts for the container.

docker "clickhouse" "dev" {
image = "clickhouse/clickhouse-server:24.10"
volumes = ["/path/to/users.xml:/etc/clickhouse-server/users.d/users.xml:ro"]
}
false

List of strings

docker.sqlserver exposed references​

NameValue
urlstring

docker.sqlserver blocks​

docker.build​

The build block defines the build configuration for the Docker image. The given image is built using the provided Dockerfile and context.

docker "postgres" "pg-vn" {
image = "postgres:15-vn"
build {
context = "."
dockerfile = "locale.Dockerfile"
args = {
LOCALE = "vi-VN"
}
}
}

Alternatively, you can define the Dockerfile inline:

docker "postgres" "dev" {
image = "postgres:15-custom"
build {
context = "."
dockerfile_inline = <<-EOF
FROM postgres:15
RUN apt-get update && apt-get install -y curl
EOF
}
}
docker.build attributes​
Name and descriptionRequiredValue
argsfalsemap
contexttruestring
dockerfilefalsestring

dockerfile_inline

The dockerfile_inline attribute allows defining the Dockerfile content inline. This is useful for simple Dockerfiles that don't require a separate file. Cannot be used together with the dockerfile attribute.

falsestring
platformfalse

List of strings

targetfalsestring
docker.build constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[dockerfile, dockerfile_inline]

docker.connection​

The connection block defines the connection configuration for the Docker-based database created in Atlas.

docker "postgres" "dev" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
docker.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

docker ysql​

docker.ysql attributes​

Name and descriptionRequiredValue

args

Additional arguments to pass to the docker run command when starting the container.

false

List of strings

baselinefalsestring

colocation

If set, the database is created with colocation enabled. Colocation is fixed when the database is created, hence a schema that uses it needs a dev-database created the same way.

docker "ysql" "dev" {
image = "yugabytedb/yugabyte:latest"
database = "dev"
colocation = true
}
falsebool

command

The command attribute specifies the command and its argument to run in the container overriding the default one.

false

List of strings

databasefalsestring
envfalse

List of strings

extra_hosts

The extra_hosts attribute adds host:ip entries to the container's /etc/hosts, similar to Docker Compose's extra_hosts. Use the special host-gateway value to reach the docker host. Maps to docker run --add-host.

docker "postgres" "dev" {
image = "postgres:18"
extra_hosts = [
"main_db:10.0.0.5",
"api.local:host-gateway",
]
}
false

List of strings

imagetruestring

init

The init attribute specifies the initialization script for the Docker-based database created in Atlas.

docker "mysql" "dev" {
image = "mysql:8.4"
init = <<-SQL
SET GLOBAL log_bin_trust_function_creators=true;
SET GLOBAL restrict_fk_on_non_standard_key=false;
SET GLOBAL sql_mode := REPLACE(@@sql_mode, 'NO_ZERO_DATE', '');
SQL
}
falsestring

platform

The platform attribute specifies the platform for the container. It defaults to the host platform if not specified. Examples: linux/amd64, linux/arm64, linux/arm/v7, etc.

falsestring
schemafalsestring

timeout

The timeout attribute specifies the timeout for waiting the container being ready to use. Defaults to 1m if not specified.

falsestring

volumes

The volumes attribute specifies volume mounts for the container.

docker "clickhouse" "dev" {
image = "clickhouse/clickhouse-server:24.10"
volumes = ["/path/to/users.xml:/etc/clickhouse-server/users.d/users.xml:ro"]
}
false

List of strings

docker.ysql exposed references​

NameValue
urlstring

docker.ysql blocks​

docker.build​

The build block defines the build configuration for the Docker image. The given image is built using the provided Dockerfile and context.

docker "postgres" "pg-vn" {
image = "postgres:15-vn"
build {
context = "."
dockerfile = "locale.Dockerfile"
args = {
LOCALE = "vi-VN"
}
}
}

Alternatively, you can define the Dockerfile inline:

docker "postgres" "dev" {
image = "postgres:15-custom"
build {
context = "."
dockerfile_inline = <<-EOF
FROM postgres:15
RUN apt-get update && apt-get install -y curl
EOF
}
}
docker.build attributes​
Name and descriptionRequiredValue
argsfalsemap
contexttruestring
dockerfilefalsestring

dockerfile_inline

The dockerfile_inline attribute allows defining the Dockerfile content inline. This is useful for simple Dockerfiles that don't require a separate file. Cannot be used together with the dockerfile attribute.

falsestring
platformfalse

List of strings

targetfalsestring
docker.build constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[dockerfile, dockerfile_inline]

docker.connection​

The connection block defines the connection configuration for the Docker-based database created in Atlas.

docker "postgres" "dev" {
...
connection {
max_open = 1
max_idle = 1
max_lifetime = "30s"
max_idle_time = "30s"
}
}
docker.connection attributes​
NameRequiredValue
max_idlefalseint
max_idle_timefalsestring
max_lifetimefalsestring
max_openfalseint

env​

The env block describes an environment block that can be selected by using the --env flag.

env attributes​

NameRequiredValue
devfalsestring
excludefalse

List of strings

includefalse

List of strings

namefalsestring
schemasfalse

List of strings

srcfalse

Schema source can be one of:

  1. Object reference
  2. string
  3. List of strings
urlfalsestring

env blocks​

env.check.migrate_apply​

env.check.migrate_apply blocks​

env.check.allow​

env.check.allow attributes​
NameRequiredValue
conditiontruebool
env.check.allow constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.check.allow "name" )true

env.check.deny​

env.check.deny attributes​
NameRequiredValue
conditiontruebool
messagefalsestring
env.check.deny constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.check.deny "name" )true

env.check.drift​

The drift block enables pre-apply drift detection. When set, Atlas compares the actual database state against the expected state from the schema registry at the current revision version before applying migrations.

env.check.drift attributes​
Name and descriptionRequiredValue

exclude

List of glob patterns to exclude from drift inspection. Defaults to env.exclude if not set.

false

List of strings

on_error

The behavior when drift is detected. By default, drift causes the migration to abort. Set to CONTINUE to emit a warning and proceed.

false

enum (CONTINUE, FAIL)

env.check.migrate_apply constraints​
ConstraintValue
Requiredfalse
Repeatabletrue

env.check.schema_apply​

env.check.schema_apply blocks​

env.check.allow​

env.check.allow attributes​
NameRequiredValue
conditiontruebool
env.check.allow constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.check.allow "name" )true

env.check.deny​

env.check.deny attributes​
NameRequiredValue
conditiontruebool
messagefalsestring
env.check.deny constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.check.deny "name" )true
env.check.schema_apply constraints​
ConstraintValue
Requiredfalse
Repeatabletrue

env.data​

The data block configures static/lookup data management.

data {
mode = UPSERT
include = ["countries", "currencies"]
exclude = ["temp_*"]
}
env.data attributes​
Name and descriptionRequiredValue

exclude

Exclude tables matching patterns. Supports glob patterns.

false

List of strings

include

Include only tables matching patterns. Supports glob patterns.

false

List of strings

max_rows

Maximum number of rows to manage per table. Value is required when querying a database in SYNC mode

falseint

mode

The sync mode: INSERT (new rows only), UPSERT (insert/update), or SYNC (insert/update/delete).

true

enum (INSERT, UPSERT, SYNC)

preserve_ids

Emit auto-increment/identity primary-key columns with their explicit values, instead of letting the database assign them.

falsebool

skip_diff

Skip objects from diff comparison. Supports glob patterns (e.g., *.updated_at).

false

List of strings

env.diff.clickhouse​

env.diff.clickhouse blocks​

env.diff.add_column​

env.diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_index​

env.diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_table​

env.diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.cluster​

env.diff.cluster attributes​
NameRequiredValue
namefalsestring

env.diff.concurrent_index​

env.diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

env.diff.drop_table​

env.diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

env.diff.materialized​

env.diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

env.diff.session_settings​

env.diff.session_settings attributes​
NameRequiredValue
matchtruestring
valuesfalsemap
env.diff.session_settings constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue

env.diff.skip​

env.diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

env.diff.mysql​

env.diff.mysql attributes​
NameRequiredValue
auto_incrementfalsebool
env.diff.mysql blocks​

env.diff.add_column​

env.diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_index​

env.diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_table​

env.diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.concurrent_index​

env.diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

env.diff.drop_table​

env.diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

env.diff.materialized​

env.diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

env.diff.not_null​

env.diff.not_null attributes​
NameRequiredValue
checkfalsebool

env.diff.skip​

env.diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

env.diff.postgres​

env.diff.postgres blocks​

env.diff.add_column​

env.diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_index​

env.diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_table​

env.diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.concurrent_index​

env.diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

env.diff.drop_table​

env.diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

env.diff.materialized​

env.diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

env.diff.not_null​

env.diff.not_null attributes​
NameRequiredValue
checkfalsebool
lock_safefalsebool

env.diff.skip​

env.diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

env.diff.redshift​

env.diff.redshift blocks​

env.diff.add_column​

env.diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_index​

env.diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_table​

env.diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.concurrent_index​

env.diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

env.diff.drop_table​

env.diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

env.diff.materialized​

env.diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

env.diff.modify_column​

env.diff.modify_column attributes​
NameRequiredValue
allow_recreatefalsebool

env.diff.skip​

env.diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

env.diff.sqlserver​

env.diff.sqlserver blocks​

env.diff.add_column​

env.diff.add_column attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_index​

env.diff.add_index attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.add_table​

env.diff.add_table attributes​
NameRequiredValue
if_not_existsfalsebool

env.diff.concurrent_index​

env.diff.concurrent_index attributes​
NameRequiredValue
addfalsebool
createfalsebool
dropfalsebool

env.diff.drop_table​

env.diff.drop_table attributes​
NameRequiredValue
cascadefalsebool
if_existsfalsebool

env.diff.materialized​

env.diff.materialized attributes​
NameRequiredValue
with_no_datafalsebool

env.diff.not_null​

env.diff.not_null attributes​
NameRequiredValue
checkfalsebool

env.diff.skip​

env.diff.skip attributes​
NameRequiredValue
add_columnfalsebool
add_extensionfalsebool
add_foreign_keyfalsebool
add_funcfalsebool
add_indexfalsebool
add_procfalsebool
add_schemafalsebool
add_tablefalsebool
add_triggerfalsebool
add_viewfalsebool
drop_columnfalsebool
drop_extensionfalsebool
drop_foreign_keyfalsebool
drop_funcfalsebool
drop_indexfalsebool
drop_procfalsebool
drop_rolefalsebool
drop_schemafalsebool
drop_tablefalsebool
drop_triggerfalsebool
drop_userfalsebool
drop_viewfalsebool
modify_columnfalsebool
modify_extensionfalsebool
modify_foreign_keyfalsebool
modify_funcfalsebool
modify_indexfalsebool
modify_procfalsebool
modify_schemafalsebool
modify_tablefalsebool
modify_triggerfalsebool
modify_viewfalsebool
rename_constraintfalsebool
rename_funcfalsebool
rename_indexfalsebool
rename_procfalsebool
rename_tablefalsebool
rename_triggerfalsebool
rename_viewfalsebool

env.export​

The export block configures schema export destinations.

export {
schema {
inspect = exporter.sql.dir
diff = exporter.http.webhook
}
}
env.export blocks​

env.export.schema​

Configure schema export.

env.export.schema attributes​
Name and descriptionRequiredValue

diff

Exporter reference for 'schema diff' command.

false

Object reference to exporter

inspect

Exporter reference for 'schema inspect' command.

false

Object reference to exporter

env.format​

The format block defines the output format of the different commands

format {
migrate {
diff = "{{ sql . \" \" }}"
}
}
env.format blocks​

env.format.migrate​

env.format.migrate attributes​
NameRequiredValue
applyfalsestring
difffalsestring
downfalsestring
driftfalsestring
lintfalsestring
statusfalsestring

env.format.schema​

env.format.schema attributes​
NameRequiredValue
applyfalsestring
difffalsestring
inspectfalsestring

env.lint​

The lint block defines the linting configuration.

lint {
destructive {
error = false
}
concurrent_index {
error = true
}
naming {
force = true
}
}
env.lint attributes​
NameRequiredValue
formatfalsestring
latestfalseint
logfalsestring
reviewfalse

enum (ALWAYS, WARNING, ERROR)

env.lint blocks​

env.lint.check​

The check block defines the configuration of a specific lint check.

check "PG301" {
error = true
}

check "NM101" {
skip = true
}
env.lint.check attributes​
Name and descriptionRequiredValue

error

The error attribute specifies whether lint should error when the check fails.

falsebool

force

The force attribute specifies whether this check should be enforced even if the atlas:nolint directive is set

falsebool

skip

The skip attribute specifies whether lint should skip the check.

falsebool
env.lint.check constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.lint.check "name" )true
Mutually exclusive sets[error, skip, force]
One of required sets[error, skip, force]

env.lint.concurrent_index​

env.lint.concurrent_index attributes​
NameRequiredValue
check_createfalsebool
check_dropfalsebool
check_txmodefalsebool
errorfalsebool
forcefalsebool

env.lint.condrop​

env.lint.condrop attributes​
NameRequiredValue
errorfalsebool
forcefalsebool

env.lint.cve​

The cve block enables reporting extensions with known vulnerabilities.

cve {
min_severity = HIGH
ignore = ["CVE-2024-10977"]
}
env.lint.cve attributes​
Name and descriptionRequiredValue
errorfalsebool
forcefalsebool

ignore

CVE identifiers that are not reported (e.g., ["CVE-2024-10977"]).

false

List of strings

min_severity

This attribute specifies the lowest CVSS rating to report. If not set, all reported vulnerabilities are included.

false

enum (LOW, MEDIUM, HIGH, CRITICAL)

timeout

Time limit for querying the Security Graph. On timeout, linting reports nothing and the scan fails (default: "5s").

falsestring

env.lint.data_depend​

env.lint.data_depend attributes​
NameRequiredValue
errorfalsebool
forcefalsebool

env.lint.destructive​

env.lint.destructive attributes​
NameRequiredValue
errorfalsebool
forcefalsebool
env.lint.destructive blocks​

env.lint.destructive.allow_column​

env.lint.destructive.allow_column attributes​
NameRequiredValue
matchfalsestring

env.lint.destructive.allow_schema​

env.lint.destructive.allow_schema attributes​
NameRequiredValue
matchfalsestring

env.lint.destructive.allow_table​

env.lint.destructive.allow_table attributes​
NameRequiredValue
matchfalsestring

env.lint.git​

env.lint.git attributes​
NameRequiredValue
basefalsestring
dirfalsestring

env.lint.grant_coverage​

The grant_coverage block enables reporting roles and users whose privileges reach a large share of the database. The reach is computed by the Atlas Security Graph in Atlas Cloud, from the inspected roles and grants, which the env must enable:

env "prod" {
schema {
mode {
roles = true
permissions = true
}
}
lint {
grant_coverage {
warn_threshold = 50
error_threshold = 75
}
}
}
env.lint.grant_coverage attributes​
Name and descriptionRequiredValue
errorfalsebool

error_threshold

The share of the securable objects a role or user must be able to write to fail the command, unless error is set (default: 75). A read reach this broad is reported as well, but does not fail.

falseint
forcefalsebool

timeout

Time limit for querying the Security Graph. Reporting is skipped if Atlas Cloud does not respond in time (default: "5s").

falsestring

warn_threshold

The share of the securable objects a role or user must be able to write to be reported (default: 50). 0 reports every role or user that holds a grant.

falseint

env.lint.incompatible​

The incompatible block enables reporting backward-incompatible changes.

incompatible {
drop_table {
message = "contact the owners of ${self.schema.name}.${self.name} first"
}
drop_column {
message = "${self.table.name} still exposes ${self.name} to clients"
}
}
env.lint.incompatible attributes​
NameRequiredValue
errorfalsebool
forcefalsebool
env.lint.incompatible blocks​

env.lint.incompatible.drop_column​

The drop_column block enables reporting drops of objects clients may still reference.

env.lint.incompatible.drop_column attributes​
Name and descriptionRequiredValue

message

The message attribute replaces the default text appended to the diagnostic. It may reference the dropped object with the self variable.

falsestring

env.lint.incompatible.drop_table​

The drop_table block enables reporting drops of objects clients may still reference.

env.lint.incompatible.drop_table attributes​
Name and descriptionRequiredValue

message

The message attribute replaces the default text appended to the diagnostic. It may reference the dropped object with the self variable.

falsestring

env.lint.naming​

env.lint.naming attributes​
NameRequiredValue
errorfalsebool
forcefalsebool
matchfalsestring
messagefalsestring
env.lint.naming blocks​

env.lint.naming.check​

env.lint.naming.check attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

env.lint.naming.column​

env.lint.naming.column attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

env.lint.naming.foreign_key​

env.lint.naming.foreign_key attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

env.lint.naming.index​

env.lint.naming.index attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

env.lint.naming.schema​

env.lint.naming.schema attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

env.lint.naming.table​

env.lint.naming.table attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

env.lint.nestedtx​

env.lint.nestedtx attributes​
NameRequiredValue
errorfalsebool
forcefalsebool

env.lint.non_linear​

env.lint.non_linear attributes​
NameRequiredValue
errorfalsebool
on_editfalse

enum (IGNORE, WARN, ERROR)

env.lint.ownership.github​

env.lint.ownership.github attributes​
Name and descriptionRequiredValue

default

This attribute specifies the access level for unmatched resources. If not set, the default access level is DENY.

false

Ownership default can be one of:

  1. string
  2. enum (ALLOW, DENY)
env.lint.ownership.github blocks​

env.lint.ownership.allow​

The allow block defines which users and teams can change matched schema resources.

env.lint.ownership.allow attributes​
Name and descriptionRequiredValue

match

Pattern to match schema resources (e.g., "public.*[type=table]").

truestring

teams

GitHub team slugs allowed to change the matched resources.

false

List of strings

users

GitHub usernames allowed to change the matched resources.

false

List of strings

env.lint.ownership.allow constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.lint.ownership.allow "name" )true
Repeatabletrue

env.lint.ownership.deny​

The deny block defines which users and teams cannot change matched schema resources.

env.lint.ownership.deny attributes​
Name and descriptionRequiredValue

match

Pattern to match schema resources (e.g., "public.*[type=table]").

truestring

teams

GitHub team slugs denied from changing the matched resources.

false

List of strings

users

GitHub usernames denied from changing the matched resources.

false

List of strings

env.lint.ownership.deny constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.lint.ownership.deny "name" )true
Repeatabletrue

env.lint.rule.hcl​

env.lint.rule.hcl attributes​
NameRequiredValue
errorfalsebool
srctrue

List of strings

varsfalsemap

env.lint.statement​

The statement block defines the configuration of the statement analyzer.

statement {
allow "only-alter-create" {
match = "(ALTER|CREATE) .+"
}
allow "delete-with-filter" {
match = "DELETE .+ WHERE .+"
}
deny "reject-delete" {
match = "DELETE .+"
}
deny "reject-truncate" {
match = "TRUNCATE .+"
}
}
env.lint.statement attributes​
NameRequiredValue
errorfalsebool
forcefalsebool
env.lint.statement blocks​

env.lint.statement.allow​

env.lint.statement.allow attributes​
NameRequiredValue
matchtruestring
env.lint.statement.allow constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.lint.statement.allow "name" )true

env.lint.statement.deny​

env.lint.statement.deny attributes​
NameRequiredValue
matchtruestring
messagefalsestring
env.lint.statement.deny constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., env.lint.statement.deny "name" )true
env.lint.statement constraints​
ConstraintValue
Requiredfalse
Require Namefalse
One of required sets[deny, allow]
env.lint constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[latest, git], [log, format]

env.log​

Use the format block instead

env.log blocks​

env.log.migrate​

env.log.migrate attributes​
NameRequiredValue
applyfalsestring
difffalsestring
downfalsestring
lintfalsestring
statusfalsestring

env.log.schema​

env.log.schema attributes​
NameRequiredValue
applyfalsestring
difffalsestring
inspectfalsestring

env.migration​

The migration block defines the migration configuration

migration {
dir = "file://migrations"
repo {
name = "app"
}
}
env.migration attributes​
Name and descriptionRequiredValue

allow_dirty

Allow start working on a non-clean database.

falsebool
baselinefalsestring
dirfalsestring
excludefalse

List of strings

exec_orderfalse

enum (LINEAR, linear, LINEAR_SKIP, linear-skip, NON_LINEAR, non-linear)

formatfalse

Migration format can be one of:

  1. enum (atlas, golang-migrate, goose, flyway, liquibase, dbmate)
  2. string
includefalse

List of strings

lock_namefalsestring
lock_timeoutfalsestring

report

Report deployments to Atlas Cloud for a local or data-source migration directory linked to a repo. atlas:// directories are reported by default, so this option only takes effect for non-atlas:// directories.

falsebool
revisions_schemafalsestring
skip_lockfalsebool

skip_report

Skip reporting migrations to Atlas Cloud. Useful for temporary environments (e.g., PR previews).

falsebool
to_versionfalsestring
tx_modefalse

Transaction mode can be one of:

  1. string
  2. enum (none, file, all)
env.migration blocks​

env.migration.repo​

The repository configuration for the migrations directory in the registry

repo {
name = "app"
}

# Repo with backup
repo {
name = "app"
backup = ["s3://my-bucket/atlas-backup?region=us-east-1"]
}
env.migration.repo attributes​
Name and descriptionRequiredValue

backup

Optional backup repository URLs for migration directories. See supported providers and URL formats: https://atlasgo.io/cloud/directories#backup-provider-urls.

false

List of strings

nametruestring
env.migration constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[allow_dirty, baseline], [report, skip_report]

env.post.migrate_apply​

env.post.migrate_apply blocks​

env.post.exec​

env.post.exec attributes​
NameRequiredValue
on_errorfalse

enum (CONTINUE, SKIP_FILE, BREAK)

sqlfalsestring
srcfalsestring
env.post.exec constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[src, sql]
One of required sets[src, sql]

env.post.skip​

env.post.skip attributes​
NameRequiredValue
conditiontruebool
messagefalsestring
env.post.migrate_apply constraints​
ConstraintValue
Requiredfalse
Repeatabletrue

env.post.schema_apply​

env.post.schema_apply blocks​

env.post.exec​

env.post.exec attributes​
NameRequiredValue
on_errorfalse

enum (CONTINUE, SKIP_FILE, BREAK)

sqlfalsestring
srcfalsestring
env.post.exec constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[src, sql]
One of required sets[src, sql]

env.post.skip​

env.post.skip attributes​
NameRequiredValue
conditiontruebool
messagefalsestring
env.post.schema_apply constraints​
ConstraintValue
Requiredfalse
Repeatabletrue

env.pre.migrate_apply​

env.pre.migrate_apply blocks​

env.pre.exec​

env.pre.exec attributes​
NameRequiredValue
on_errorfalse

enum (CONTINUE, SKIP_FILE, BREAK, FAIL)

sqlfalsestring
srcfalsestring
env.pre.exec constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[src, sql]
One of required sets[src, sql]

env.pre.skip​

env.pre.skip attributes​
NameRequiredValue
conditiontruebool
messagefalsestring
env.pre.migrate_apply constraints​
ConstraintValue
Requiredfalse
Repeatabletrue

env.pre.schema_apply​

env.pre.schema_apply blocks​

env.pre.exec​

env.pre.exec attributes​
NameRequiredValue
on_errorfalse

enum (CONTINUE, SKIP_FILE, BREAK, FAIL)

sqlfalsestring
srcfalsestring
env.pre.exec constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[src, sql]
One of required sets[src, sql]

env.pre.skip​

env.pre.skip attributes​
NameRequiredValue
conditiontruebool
messagefalsestring
env.pre.schema_apply constraints​
ConstraintValue
Requiredfalse
Repeatabletrue

env.rollout​

The rollout block configures multi-tenant or multi-environment deployment for this environment.

rollout {
deployment = deployment.staged
vars = {
tier = each.value.tier
region = each.value.region
}
}
env.rollout attributes​
Name and descriptionRequiredValue

deployment

Reference to a deployment block that defines the rollout strategy.

true

Object reference to deployment

vars

Map of variable values to pass to the deployment. Keys must match the deployment's variable declarations.

falsemap

env.schema​

The configuration for the desired schema

schema {
src = "file://schema.hcl"
repo {
name = "app"
}
}
env.schema attributes​
NameRequiredValue
srcfalse

Schema source can be one of:

  1. Object reference
  2. string
  3. List of strings
env.schema blocks​

env.schema.mode.clickhouse​

env.schema.mode.clickhouse attributes​
Name and descriptionRequiredValue

dictionaries

Enable inspection of ClickHouse dictionaries.

falsebool
funcsfalsebool

named_collections

Enable inspection of ClickHouse named collections.

falsebool
objectsfalsebool
permissionsfalsebool

policies

Enable inspection of ClickHouse row policies.

falsebool
rolesfalsebool

schemas

Inspect schemas and their objects. Disabling it skips them entirely, and is useful for managing only realm-level objects, such as roles and users.

falsebool

sensitive

Control sensitive values (e.g., passwords) in migration planning. Valid values: ALLOW or DENY (default).

false

enum (ALLOW, DENY)

settings_profiles

Enable inspection of ClickHouse settings profiles.

falsebool
tablesfalsebool
triggersfalsebool
typesfalsebool
viewsfalsebool

wasm_modules

Enable inspection of ClickHouse WASM modules.

falsebool

env.schema.mode.redshift​

env.schema.mode.redshift attributes​
Name and descriptionRequiredValue

datashares

Enable inspection of the Redshift datashares created in this database. Independent of the objects mode, but the schemas a datashare shares from must stay in scope: its objects are references to them. Datashare names are unique across a cluster, so the dev database must live on a separate cluster or serverless workgroup: loading a state into one sharing the cluster of the target database collides with the datashare it already holds.

falsebool
funcsfalsebool
objectsfalsebool
permissionsfalsebool
rolesfalsebool

schemas

Inspect schemas and their objects. Disabling it skips them entirely, and is useful for managing only realm-level objects, such as roles and users.

falsebool

sensitive

Control sensitive values (e.g., passwords) in migration planning. Valid values: ALLOW or DENY (default).

false

enum (ALLOW, DENY)

tablesfalsebool
triggersfalsebool
typesfalsebool
viewsfalsebool

env.schema.mode.snowflake​

env.schema.mode.snowflake attributes​
Name and descriptionRequiredValue
alertsfalsebool
external_access_integrationsfalsebool
external_volumesfalsebool
funcsfalsebool
network_rulesfalsebool
objectsfalsebool
permissionsfalsebool
policiesfalsebool
resource_monitorsfalsebool
rolesfalsebool

schemas

Inspect schemas and their objects. Disabling it skips them entirely, and is useful for managing only realm-level objects, such as roles and users.

falsebool
secretsfalsebool

sensitive

Control sensitive values (e.g., passwords) in migration planning. Valid values: ALLOW or DENY (default).

false

enum (ALLOW, DENY)

tablesfalsebool
tagsfalsebool
triggersfalsebool
typesfalsebool
viewsfalsebool
warehousesfalsebool

env.schema.mode.sqlserver​

env.schema.mode.sqlserver attributes​
Name and descriptionRequiredValue
funcsfalsebool

header_comment

Enable processing of header comments for SQL Server functions, procedures, and views.

falsebool
objectsfalsebool
permissionsfalsebool
rolesfalsebool

schemas

Inspect schemas and their objects. Disabling it skips them entirely, and is useful for managing only realm-level objects, such as roles and users.

falsebool

sensitive

Control sensitive values (e.g., passwords) in migration planning. Valid values: ALLOW or DENY (default).

false

enum (ALLOW, DENY)

tablesfalsebool
triggersfalsebool
typesfalsebool
viewsfalsebool

env.schema.repo​

The repository configuration for the desired schema in the registry

repo {
name = "app"
}

# Repo with backup
repo {
name = "app"
backup = ["s3://my-bucket/atlas-backup?region=us-east-1"]
}
env.schema.repo attributes​
Name and descriptionRequiredValue

backup

Optional backup repository URLs for schema plans. See supported providers and URL formats: https://atlasgo.io/cloud/directories#backup-provider-urls.

false

List of strings

nametruestring

env.script​

The script block defines the scripts configuration.

script {
src = "file://scripts"
repo {
name = "app"
}
}
env.script attributes​
Name and descriptionRequiredValue

src

URL to a script file or a directory of *.script.hcl files.

falsestring
env.script blocks​

env.script.repo​

The repository configuration for the scripts in the registry.

repo {
name = "app"
}

# Repo with backup
repo {
name = "app"
backup = ["s3://my-bucket/atlas-backup?region=us-east-1"]
}
env.script.repo attributes​
Name and descriptionRequiredValue

backup

Optional backup repository URLs for scripts. See supported providers and URL formats: https://atlasgo.io/cloud/directories#backup-provider-urls.

false

List of strings

nametruestring

env.security​

The security block defines the configuration of the atlas security scan command, which inspects running databases and reports the security issues it finds. Each check has its own block and runs when it is present, and the cve check is included by default.

security {
min_severity = ELEVATED
fail_on = HIGH
cve {
ignore = ["CVE-2024-10977"]
}
notify {
http "slack" {
url = var.slack_webhook
body = jsonencode({ text = "${scan.count} vulnerable extensions found" })
}
}
}
env.security attributes​
Name and descriptionRequiredValue

fail_on

Fail the command when an issue of this severity or higher was reported. If not set, issues are reported without failing the command.

false

enum (NORMAL, ELEVATED, HIGH, CRITICAL)

min_severity

The lowest level every check reports, as the Security Graph grades it. A check raises it for itself by setting its own, and never lowers it.

false

enum (NORMAL, ELEVATED, HIGH, CRITICAL)

env.security blocks​

env.security.cve​

The cve check reports installed extensions with known vulnerabilities, as recorded in the Atlas Security Graph. Included by default. Note, this is not the cve block of the lint policy, which reports on schema changes rather than on a running database.

cve {
min_severity = HIGH
ignore = ["CVE-2024-10977"]
}
env.security.cve attributes​
Name and descriptionRequiredValue

ignore

CVE identifiers that are not reported (e.g., ["CVE-2024-10977"]).

false

List of strings

min_severity

This attribute specifies the lowest level this check reports, as the Security Graph grades it. It applies when higher than the one the security block sets for every check.

false

enum (NORMAL, ELEVATED, HIGH, CRITICAL)

timeout

Time limit for querying the Security Graph. On timeout, linting reports nothing and the scan fails (default: "5s").

falsestring

env.security.notify​

Send the result of the scan to HTTP endpoints. e.g., a Slack webhook.

notify {
on = [FINDINGS, FAILURE]
http "slack" {
url = var.slack_webhook
headers = { "Content-Type" = "application/json" }
body = jsonencode({ text = "${scan.count} vulnerable extensions found" })
}
}
env.security.notify attributes​
Name and descriptionRequiredValue

on

Events the result is sent on: FINDINGS (vulnerabilities were reported), FAILURE (a database could not be scanned), or ALWAYS. Defaults to [FINDINGS, FAILURE].

false

List of enum (ALWAYS, FINDINGS, FAILURE)

env.security.notify blocks​

env.security.notify.http​

Send the result of the scan in an HTTP request. The url, headers and body may interpolate the result of the scan: scan.count, scan.critical, scan.high, scan.elevated, scan.normal, scan.failures, scan.report and scan.targets.

http "slack" {
url = var.slack_webhook
headers = { "Content-Type" = "application/json" }
body = jsonencode({ text = "${scan.count} vulnerable extensions found" })
}
env.security.notify.http attributes​
Name and descriptionRequiredValue

body

The request body as a string.

falsestring

ca_cert_pem

Certificate Authority (CA) in PEM (RFC 1421) format.

falsestring

client_cert_pem

Client certificate in PEM (RFC 1421) format.

falsestring

client_key_pem

Client key in PEM (RFC 1421) format.

falsestring

headers

A map of request header field names and values.

falsemap

insecure

Disables verification of the server's certificate chain and hostname. Defaults to false.

falsebool

method

The HTTP method for the request: POST (default), PUT or PATCH.

false

enum (POST, PUT, PATCH)

request_timeout_ms

The request timeout in milliseconds.

falseint

url

The URL for the request. Supported schemes are http and https.

truestring
env.security.notify.http blocks​

env.security.notify.http.retry​

Retry request configuration. By default there are no retries. Configuring this block will result in retries if an error is returned by the client (e.g., connection errors) or if a 5xx-range (except 501) status code is received.

env.security.notify.http.retry attributes​
Name and descriptionRequiredValue

attempts

The number of times the request is to be retried. For example, if 2 is specified, the request will be tried a maximum of 3 times.

falseint

max_delay_ms

The maximum delay between retry requests in milliseconds.

falseint

min_delay_ms

The minimum delay between retry requests in milliseconds.

falseint
env.security.notify.http constraints​
ConstraintValue
Requiredtrue
Require Namefalse
Repeatabletrue
Mutually exclusive sets[ca_cert_pem, insecure]

env.test​

The test block defines the testing configuration.

test {
schema {
src = ["schema.test.hcl"]
vars = {
seed_file = "filename.sql"
variable2 = var.name
variable3 = data.external.value
}
}
}
env.test blocks​

env.test.migrate​

env.test.migrate attributes​
NameRequiredValue
srctrue

List of strings

varsfalsemap

env.test.schema​

env.test.schema attributes​
NameRequiredValue
srctrue

List of strings

varsfalsemap

env.test.script​

env.test.script attributes​
NameRequiredValue
srctrue

List of strings

varsfalsemap

env constraints​

ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue
Allow unknown attributestrue
Mutually exclusive sets[src, schema]

exporter hcl​

Export schema as HCL.

// Single file output.
exporter "hcl" "file" {
path = "schema.hcl"
}

// Split by object (directory output).
exporter "hcl" "dir" {
path = "schema/hcl"
split_by = object
naming = lower
}

exporter.hcl attributes​

Name and descriptionRequiredValue

ext

File extension for split files (defaults to '.hcl').

falsestring

main

File name (without extension) for resources not associated with a schema. Defaults to 'main'.

falsestring

naming

Naming convention for split files: same (preserve), lower (lowercase), upper (uppercase).

false

enum (same, lower, upper)

path

Output path. If split_by is set, this is the directory; otherwise, it's the file path.

truestring

split_by

Split strategy: object (per object), schema (per schema), type (per type).

false

enum (object, schema, type)

exporter http​

Export schema via HTTP request.

// Using a template for the body.
exporter "http" "webhook" {
url = "https://api.example.com/schemas"
method = "POST"
body_template = "{{ sql . }}"
headers = {
"Content-Type" = "application/json"
"Authorization" = "Bearer ${var.token}"
}
}

// Using a non-template body.
exporter "http" "simple" {
url = "https://api.example.com/schemas"
method = "POST"
body = "simple request body"
}

exporter.http attributes​

Name and descriptionRequiredValue

body

The request body as a string.

falsestring

body_template

The request body template. Supports template functions like sql, json, mermaid, etc.

falsestring

ca_cert_pem

Certificate Authority (CA) in PEM (RFC 1421) format.

falsestring

client_cert_pem

Client certificate in PEM (RFC 1421) format.

falsestring

client_key_pem

Client key in PEM (RFC 1421) format.

falsestring

headers

A map of request header field names and values.

falsemap

insecure

Disables verification of the server's certificate chain and hostname. Defaults to false.

falsebool

method

The HTTP method for the request (e.g., GET, POST, PUT, PATCH).

truestring

request_timeout_ms

The request timeout in milliseconds.

falseint

url

The URL for the request. Supported schemes are http and https.

truestring

exporter.http blocks​

exporter.retry​

Retry request configuration. By default there are no retries. Configuring this block will result in retries if an error is returned by the client (e.g., connection errors) or if a 5xx-range (except 501) status code is received.

exporter.retry attributes​
Name and descriptionRequiredValue

attempts

The number of times the request is to be retried. For example, if 2 is specified, the request will be tried a maximum of 3 times.

falseint

max_delay_ms

The maximum delay between retry requests in milliseconds.

falseint

min_delay_ms

The minimum delay between retry requests in milliseconds.

falseint

exporter multi​

Export schema to multiple exporters.

// Export to multiple HTTP endpoints with fail-fast behavior (default).
exporter "multi" "webhooks" {
exporters = [
exporter.http.webhook1,
exporter.http.webhook2,
]
}

// Export to both SQL and HCL formats, continue on errors.
exporter "multi" "all" {
exporters = [
exporter.sql.file,
exporter.hcl.file,
]
on_error = CONTINUE // Defaults to FAIL.
}

exporter.multi attributes​

Name and descriptionRequiredValue

exporters

List of exporter references to execute in sequence.

true

List of object reference to exporter

on_error

Error handling mode. Defaults to FAIL (stop on first error). Options: FAIL (default), CONTINUE (continue but collect errors), IGNORE (silently ignore errors).

false

enum (FAIL, CONTINUE, IGNORE)

exporter sql​

Export schema as SQL.

// Single file output.
exporter "sql" "file" {
path = "schema.sql"
indent = " "
}

// Split by object (directory output).
exporter "sql" "dir" {
path = "schema/sql"
split_by = object
naming = lower
}

exporter.sql attributes​

Name and descriptionRequiredValue

indent

Indentation string for SQL output (e.g., " " for 2 spaces).

falsestring

naming

Naming convention for split files: same (preserve), lower (lowercase), upper (uppercase).

false

enum (same, lower, upper)

path

Output path. If split_by is set, this is the directory; otherwise, it's the file path.

truestring

split_by

Split strategy. Only object is supported for SQL.

false

enum (object)

exporter template​

Export schema using user-defined Go templates.

exporter "template" "docs" {
template {
src = "templates/index.tmpl"
name = "output/index.yaml"
}
template {
src = "templates/object.tmpl"
on "table" {
match = ["public.*"]
name = "output/tables/{{ .Schema }}_{{ .Name }}.yaml"
}
on "function" {
match = ["public.*"]
name = "output/functions/{{ .Schema }}_{{ .Name }}.yaml"
}
}
}

exporter.template blocks​

exporter.template​

exporter.template attributes​
Name and descriptionRequiredValue

name

Output file path for static templates (executed once with the full schema).

falsestring

skip_empty

Skip writing the file if the template output is empty or blank.

falsebool

src

Path to the Go template file.

truestring
exporter.template blocks​

exporter.template.on​

Match rule for per-object template execution.

exporter.template.on attributes​
Name and descriptionRequiredValue

match

List of glob patterns to match object names (e.g., ["public.*"]).

false

List of strings

name

Output file name Go template with {{ .Schema }} and {{ .Name }}.

truestring
exporter.template.on constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue
exporter.template constraints​
ConstraintValue
Requiredtrue
Require Namefalse
Repeatabletrue

hook sql​

The hook "sql" "name" block defines an SQL hook configuration.

hook "sql" "timeout" {
transaction {
after_begin = [
"SET statement_timeout TO '50ms'",
]
}
}

hook.sql attributes​

NameRequiredValue
skip_errorsfalsebool

hook.sql blocks​

hook.transaction​

hook.transaction attributes​
NameRequiredValue
after_beginfalse

List of strings

before_commitfalse

List of strings

before_rollbackfalse

List of strings

lint​

The lint block defines the linting configuration.

lint {
destructive {
error = false
}
concurrent_index {
error = true
}
naming {
force = true
}
}

lint attributes​

NameRequiredValue
formatfalsestring
latestfalseint
logfalsestring
reviewfalse

enum (ALWAYS, WARNING, ERROR)

lint blocks​

lint.check​

The check block defines the configuration of a specific lint check.

check "PG301" {
error = true
}

check "NM101" {
skip = true
}
lint.check attributes​
Name and descriptionRequiredValue

error

The error attribute specifies whether lint should error when the check fails.

falsebool

force

The force attribute specifies whether this check should be enforced even if the atlas:nolint directive is set

falsebool

skip

The skip attribute specifies whether lint should skip the check.

falsebool
lint.check constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., lint.check "name" )true
Mutually exclusive sets[error, skip, force]
One of required sets[error, skip, force]

lint.concurrent_index​

lint.concurrent_index attributes​
NameRequiredValue
check_createfalsebool
check_dropfalsebool
check_txmodefalsebool
errorfalsebool
forcefalsebool

lint.condrop​

lint.condrop attributes​
NameRequiredValue
errorfalsebool
forcefalsebool

lint.cve​

The cve block enables reporting extensions with known vulnerabilities.

cve {
min_severity = HIGH
ignore = ["CVE-2024-10977"]
}
lint.cve attributes​
Name and descriptionRequiredValue
errorfalsebool
forcefalsebool

ignore

CVE identifiers that are not reported (e.g., ["CVE-2024-10977"]).

false

List of strings

min_severity

This attribute specifies the lowest CVSS rating to report. If not set, all reported vulnerabilities are included.

false

enum (LOW, MEDIUM, HIGH, CRITICAL)

timeout

Time limit for querying the Security Graph. On timeout, linting reports nothing and the scan fails (default: "5s").

falsestring

lint.data_depend​

lint.data_depend attributes​
NameRequiredValue
errorfalsebool
forcefalsebool

lint.destructive​

lint.destructive attributes​
NameRequiredValue
errorfalsebool
forcefalsebool
lint.destructive blocks​

lint.destructive.allow_column​

lint.destructive.allow_column attributes​
NameRequiredValue
matchfalsestring

lint.destructive.allow_schema​

lint.destructive.allow_schema attributes​
NameRequiredValue
matchfalsestring

lint.destructive.allow_table​

lint.destructive.allow_table attributes​
NameRequiredValue
matchfalsestring

lint.git​

lint.git attributes​
NameRequiredValue
basefalsestring
dirfalsestring

lint.grant_coverage​

The grant_coverage block enables reporting roles and users whose privileges reach a large share of the database. The reach is computed by the Atlas Security Graph in Atlas Cloud, from the inspected roles and grants, which the env must enable:

env "prod" {
schema {
mode {
roles = true
permissions = true
}
}
lint {
grant_coverage {
warn_threshold = 50
error_threshold = 75
}
}
}
lint.grant_coverage attributes​
Name and descriptionRequiredValue
errorfalsebool

error_threshold

The share of the securable objects a role or user must be able to write to fail the command, unless error is set (default: 75). A read reach this broad is reported as well, but does not fail.

falseint
forcefalsebool

timeout

Time limit for querying the Security Graph. Reporting is skipped if Atlas Cloud does not respond in time (default: "5s").

falsestring

warn_threshold

The share of the securable objects a role or user must be able to write to be reported (default: 50). 0 reports every role or user that holds a grant.

falseint

lint.incompatible​

The incompatible block enables reporting backward-incompatible changes.

incompatible {
drop_table {
message = "contact the owners of ${self.schema.name}.${self.name} first"
}
drop_column {
message = "${self.table.name} still exposes ${self.name} to clients"
}
}
lint.incompatible attributes​
NameRequiredValue
errorfalsebool
forcefalsebool
lint.incompatible blocks​

lint.incompatible.drop_column​

The drop_column block enables reporting drops of objects clients may still reference.

lint.incompatible.drop_column attributes​
Name and descriptionRequiredValue

message

The message attribute replaces the default text appended to the diagnostic. It may reference the dropped object with the self variable.

falsestring

lint.incompatible.drop_table​

The drop_table block enables reporting drops of objects clients may still reference.

lint.incompatible.drop_table attributes​
Name and descriptionRequiredValue

message

The message attribute replaces the default text appended to the diagnostic. It may reference the dropped object with the self variable.

falsestring

lint.naming​

lint.naming attributes​
NameRequiredValue
errorfalsebool
forcefalsebool
matchfalsestring
messagefalsestring
lint.naming blocks​

lint.naming.check​

lint.naming.check attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

lint.naming.column​

lint.naming.column attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

lint.naming.foreign_key​

lint.naming.foreign_key attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

lint.naming.index​

lint.naming.index attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

lint.naming.schema​

lint.naming.schema attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

lint.naming.table​

lint.naming.table attributes​
NameRequiredValue
matchfalsestring
messagefalsestring

lint.nestedtx​

lint.nestedtx attributes​
NameRequiredValue
errorfalsebool
forcefalsebool

lint.non_linear​

lint.non_linear attributes​
NameRequiredValue
errorfalsebool
on_editfalse

enum (IGNORE, WARN, ERROR)

lint.ownership.github​

lint.ownership.github attributes​
Name and descriptionRequiredValue

default

This attribute specifies the access level for unmatched resources. If not set, the default access level is DENY.

false

Ownership default can be one of:

  1. string
  2. enum (ALLOW, DENY)
lint.ownership.github blocks​

lint.ownership.allow​

The allow block defines which users and teams can change matched schema resources.

lint.ownership.allow attributes​
Name and descriptionRequiredValue

match

Pattern to match schema resources (e.g., "public.*[type=table]").

truestring

teams

GitHub team slugs allowed to change the matched resources.

false

List of strings

users

GitHub usernames allowed to change the matched resources.

false

List of strings

lint.ownership.allow constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., lint.ownership.allow "name" )true
Repeatabletrue

lint.ownership.deny​

The deny block defines which users and teams cannot change matched schema resources.

lint.ownership.deny attributes​
Name and descriptionRequiredValue

match

Pattern to match schema resources (e.g., "public.*[type=table]").

truestring

teams

GitHub team slugs denied from changing the matched resources.

false

List of strings

users

GitHub usernames denied from changing the matched resources.

false

List of strings

lint.ownership.deny constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., lint.ownership.deny "name" )true
Repeatabletrue

lint.rule.hcl​

lint.rule.hcl attributes​
NameRequiredValue
errorfalsebool
srctrue

List of strings

varsfalsemap

lint.statement​

The statement block defines the configuration of the statement analyzer.

statement {
allow "only-alter-create" {
match = "(ALTER|CREATE) .+"
}
allow "delete-with-filter" {
match = "DELETE .+ WHERE .+"
}
deny "reject-delete" {
match = "DELETE .+"
}
deny "reject-truncate" {
match = "TRUNCATE .+"
}
}
lint.statement attributes​
NameRequiredValue
errorfalsebool
forcefalsebool
lint.statement blocks​

lint.statement.allow​

lint.statement.allow attributes​
NameRequiredValue
matchtruestring
lint.statement.allow constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., lint.statement.allow "name" )true

lint.statement.deny​

lint.statement.deny attributes​
NameRequiredValue
matchtruestring
messagefalsestring
lint.statement.deny constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., lint.statement.deny "name" )true
lint.statement constraints​
ConstraintValue
Requiredfalse
Require Namefalse
One of required sets[deny, allow]

lint constraints​

ConstraintValue
Requiredfalse
Require Namefalse
Mutually exclusive sets[latest, git], [log, format]

security​

The security block defines the configuration of the atlas security scan command, which inspects running databases and reports the security issues it finds. Each check has its own block and runs when it is present, and the cve check is included by default.

security {
min_severity = ELEVATED
fail_on = HIGH
cve {
ignore = ["CVE-2024-10977"]
}
notify {
http "slack" {
url = var.slack_webhook
body = jsonencode({ text = "${scan.count} vulnerable extensions found" })
}
}
}

security attributes​

Name and descriptionRequiredValue

fail_on

Fail the command when an issue of this severity or higher was reported. If not set, issues are reported without failing the command.

false

enum (NORMAL, ELEVATED, HIGH, CRITICAL)

min_severity

The lowest level every check reports, as the Security Graph grades it. A check raises it for itself by setting its own, and never lowers it.

false

enum (NORMAL, ELEVATED, HIGH, CRITICAL)

security blocks​

security.cve​

The cve check reports installed extensions with known vulnerabilities, as recorded in the Atlas Security Graph. Included by default. Note, this is not the cve block of the lint policy, which reports on schema changes rather than on a running database.

cve {
min_severity = HIGH
ignore = ["CVE-2024-10977"]
}
security.cve attributes​
Name and descriptionRequiredValue

ignore

CVE identifiers that are not reported (e.g., ["CVE-2024-10977"]).

false

List of strings

min_severity

This attribute specifies the lowest level this check reports, as the Security Graph grades it. It applies when higher than the one the security block sets for every check.

false

enum (NORMAL, ELEVATED, HIGH, CRITICAL)

timeout

Time limit for querying the Security Graph. On timeout, linting reports nothing and the scan fails (default: "5s").

falsestring

security.notify​

Send the result of the scan to HTTP endpoints. e.g., a Slack webhook.

notify {
on = [FINDINGS, FAILURE]
http "slack" {
url = var.slack_webhook
headers = { "Content-Type" = "application/json" }
body = jsonencode({ text = "${scan.count} vulnerable extensions found" })
}
}
security.notify attributes​
Name and descriptionRequiredValue

on

Events the result is sent on: FINDINGS (vulnerabilities were reported), FAILURE (a database could not be scanned), or ALWAYS. Defaults to [FINDINGS, FAILURE].

false

List of enum (ALWAYS, FINDINGS, FAILURE)

security.notify blocks​

security.notify.http​

Send the result of the scan in an HTTP request. The url, headers and body may interpolate the result of the scan: scan.count, scan.critical, scan.high, scan.elevated, scan.normal, scan.failures, scan.report and scan.targets.

http "slack" {
url = var.slack_webhook
headers = { "Content-Type" = "application/json" }
body = jsonencode({ text = "${scan.count} vulnerable extensions found" })
}
security.notify.http attributes​
Name and descriptionRequiredValue

body

The request body as a string.

falsestring

ca_cert_pem

Certificate Authority (CA) in PEM (RFC 1421) format.

falsestring

client_cert_pem

Client certificate in PEM (RFC 1421) format.

falsestring

client_key_pem

Client key in PEM (RFC 1421) format.

falsestring

headers

A map of request header field names and values.

falsemap

insecure

Disables verification of the server's certificate chain and hostname. Defaults to false.

falsebool

method

The HTTP method for the request: POST (default), PUT or PATCH.

false

enum (POST, PUT, PATCH)

request_timeout_ms

The request timeout in milliseconds.

falseint

url

The URL for the request. Supported schemes are http and https.

truestring
security.notify.http blocks​

security.notify.http.retry​

Retry request configuration. By default there are no retries. Configuring this block will result in retries if an error is returned by the client (e.g., connection errors) or if a 5xx-range (except 501) status code is received.

security.notify.http.retry attributes​
Name and descriptionRequiredValue

attempts

The number of times the request is to be retried. For example, if 2 is specified, the request will be tried a maximum of 3 times.

falseint

max_delay_ms

The maximum delay between retry requests in milliseconds.

falseint

min_delay_ms

The minimum delay between retry requests in milliseconds.

falseint
security.notify.http constraints​
ConstraintValue
Requiredtrue
Require Namefalse
Repeatabletrue
Mutually exclusive sets[ca_cert_pem, insecure]

test​

The test block defines the testing configuration.

test {
schema {
src = ["schema.test.hcl"]
vars = {
seed_file = "filename.sql"
variable2 = var.name
variable3 = data.external.value
}
}
}

test blocks​

test.migrate​

test.migrate attributes​
NameRequiredValue
srctrue

List of strings

varsfalsemap

test.schema​

test.schema attributes​
NameRequiredValue
srctrue

List of strings

varsfalsemap

test.script​

test.script attributes​
NameRequiredValue
srctrue

List of strings

varsfalsemap