providerthing Get in touch

One repo · a folder per vendor · a plan before every change

The services you rent, declared.

Your servers are code. The services around them are not: mail, the network's access rules, the backup bucket, the spending limits, each set by hand in a vendor's console. providerthing declares them the same way, in one repo.

Act I

Five consoles, all clicked.

A mail provider, a mesh network, a storage bucket, a monitoring service. Each one set up once, by hand, in a dashboard that was redesigned since.

01 · Setting up mail

A domain, verified by hand.

Pick the region, create the identity, copy five DNS records into another tab, set the MAIL FROM, check the suppression list. Once per domain.

console.provider.example/ses/identities
Identities eu-central-1
Identity type Domain
Domain stubthing.com
Create identity
Identity created. Copy the 3 CNAME records.
MAIL FROM set. Copy the MX and TXT records.

02 · Six months later

Nobody knows what was set.

Which domains are verified? Is suppression on? Who can the network reach? The answer is in a console, and the console doesn't say why.

~
$ grep -ri "suppression" ~/notes
# no results
# the access policy: pasted by hand, last copy unknown

03 · The bill

And nothing stops the spending.

The biggest vendor has no hard cap. A leaked key sends or computes until the invoice arrives, and an alert only says so afterwards.

~
✗ hard spending cap · not offered
alerts: emailed, hours after the fact

That was one vendor.

settings clicked
2
nowhere written down
2
uncapped vendors
1
changes reviewed first
0

Here's the same account, declared.

Act II

The providerthing way.

A folder per vendor, in OpenTofu. What the account should look like is a file; changing it is a commit.

01 · Declared

A domain is a line.

Every sending domain verified with DKIM, from one list. Adding the next domain is one more entry, and its DNS records come out as an output.

aws/ses.tf lines 1–12
locals {
sending_domains = ["stubthing.com"]
}
resource "aws_sesv2_email_identity" "domain" {
for_each = toset(local.sending_domains)
email_identity = each.value
dkim_signing_attributes {
next_signing_key_length = "RSA_2048_BIT"
}
}

02 · Planned

See the change before it happens.

Every apply starts as a plan: what will be created, changed or destroyed, read before anything at the vendor moves.

~/providerthing
$ nix run .#tofu -- aws plan
+ aws_sesv2_email_identity.domain["llmthing.com"]
Plan: 1 to add, 0 to change, 0 to destroy.

03 · A cap, built

The off switch the vendor won't sell.

Past $50 a month, the mail credential is denied everything, automatically. A leaked key stops costing money instead of running until the invoice.

aws/budgets.tf lines 1–12
resource "aws_budgets_budget_action" "stop_smtp" {
budget_name = aws_budgets_budget.stop.name # $50 a month
action_type = "APPLY_IAM_POLICY"
approval_model = "AUTOMATIC"
definition {
iam_action_definition {
policy_arn = "arn:aws:iam::aws:policy/AWSDenyAll"
users = [aws_iam_user.smtp.name]
}
}
}

04 · Kept safe

Secrets stay sealed.

The state holds passwords, so it is encrypted before it is written and committed sealed. The vendor's credential comes from the vault for one run and is never stored.

~/providerthing
✓ aws/terraform.tfstate · encrypted, committed
✓ credential · from the vault, for this run only

Act III

Where the line is.

providerthing owns the settings that live at a vendor. Everything else has its own home.

  1. 1

    What lives here

    Account settings: mail domains, access policies, buckets, budgets, the users a service sends as.

  2. 2

    What doesn't

    The machines (iacthing) and the DNS records (dnsthing), which are fields of their own.

  3. 3

    How it's applied

    From one workstation, plan first, with a state per vendor so one vendor's mistake never touches another's.

Vendor accounts, both ways
Measure Clicked providerthing
What is set in the console in the repo
A change a click, unrecorded a plan, then a commit
Spending cap none built from a budget
The next domain the whole routine again one line

Settings you can't find again?

Tell me which consoles you click through. providerthing is how every service here gets set up.

Get in touch