One repo · a folder per vendor · a plan before every change
The services you rent, declared.
Your servers are code. The services around them are not: mail, the network's access rules, the backup bucket, the spending limits, each set by hand in a vendor's console. providerthing declares them the same way, in one repo.
Act I
Five consoles, all clicked.
A mail provider, a mesh network, a storage bucket, a monitoring service. Each one set up once, by hand, in a dashboard that was redesigned since.
01 · Setting up mail
A domain, verified by hand.
Pick the region, create the identity, copy five DNS records into another tab, set the MAIL FROM, check the suppression list. Once per domain.
02 · Six months later
Nobody knows what was set.
Which domains are verified? Is suppression on? Who can the network reach? The answer is in a console, and the console doesn't say why.
03 · The bill
And nothing stops the spending.
The biggest vendor has no hard cap. A leaked key sends or computes until the invoice arrives, and an alert only says so afterwards.
That was one vendor.
- settings clicked
- 2
- nowhere written down
- 2
- uncapped vendors
- 1
- changes reviewed first
- 0
Here's the same account, declared.
Act II
The providerthing way.
A folder per vendor, in OpenTofu. What the account should look like is a file; changing it is a commit.
01 · Declared
A domain is a line.
Every sending domain verified with DKIM, from one list. Adding the next domain is one more entry, and its DNS records come out as an output.
02 · Planned
See the change before it happens.
Every apply starts as a plan: what will be created, changed or destroyed, read before anything at the vendor moves.
03 · A cap, built
The off switch the vendor won't sell.
Past $50 a month, the mail credential is denied everything, automatically. A leaked key stops costing money instead of running until the invoice.
04 · Kept safe
Secrets stay sealed.
The state holds passwords, so it is encrypted before it is written and committed sealed. The vendor's credential comes from the vault for one run and is never stored.
Act III
Where the line is.
providerthing owns the settings that live at a vendor. Everything else has its own home.
-
1
What lives here
Account settings: mail domains, access policies, buckets, budgets, the users a service sends as.
-
2
What doesn't
The machines (iacthing) and the DNS records (dnsthing), which are fields of their own.
-
3
How it's applied
From one workstation, plan first, with a state per vendor so one vendor's mistake never touches another's.
| Measure | Clicked | providerthing |
|---|---|---|
| What is set | in the console | in the repo |
| A change | a click, unrecorded | a plan, then a commit |
| Spending cap | none | built from a budget |
| The next domain | the whole routine again | one line |
Settings you can't find again?
Tell me which consoles you click through. providerthing is how every service here gets set up.