Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
28 changes: 13 additions & 15 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,18 +19,16 @@ FEATURES:

NOTES:

* Endpoint URLs with the credential removed are named `safe_http_url` and
`safe_wss_url`, and carry the literal `TOKEN` where the credential belongs
rather than having it cut out. The real URL's shape survives, including any
path suffix the chain appends after the token, so
`replace(..., "TOKEN", token)` reproduces a working address on every chain.

* `quicknode_endpoint` gains `security_options`, which decides what the endpoint
enforces, and `ip_custom_header` for endpoints behind a proxy. A toggle left
out of the configuration keeps whatever value the endpoint already has.
* Allowlist entries are imported by value rather than by the id the API
assigned, so `terraform import quicknode_endpoint_ip.office 652052/203.0.113.7`
needs nothing looked up first.
* Adding an allowlist entry while its toggle is disabled warns rather than
fails. Building an allowlist before enabling enforcement is the safe order for
an endpoint already serving traffic.
* `safe_http_url` and `safe_wss_url` carry the literal `TOKEN` where the credential
belongs, so `replace(url, "TOKEN", token)` rebuilds a working address on every chain.
* `quicknode_endpoint.security_options` decides what the endpoint enforces. A toggle
left out of the configuration keeps the value the endpoint already has.
* `quicknode_endpoint.ip_custom_header` names the header an endpoint behind a proxy
reads the caller's IP address from.
* Allowlist entries are imported by value, as `652052/203.0.113.7`.
* Adding an allowlist entry while its toggle is disabled warns and succeeds, so an
allowlist can be built before enforcement is turned on.
* `quicknode_endpoint.label` cannot be cleared once set, so removing the attribute
leaves the endpoint's label in place.
* `quicknode_endpoint_jwt` takes `kid` as an input. The Admin API requires it when
the signing key is registered.
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,8 +35,8 @@ resource "quicknode_endpoint" "payments" {
```

Authentication uses a Quicknode [API key](https://www.quicknode.com/docs/admin-api),
available on paid plans. Set `QUICKNODE_API_KEY` in the environment rather than
writing it into a configuration file.
available on paid plans. Set `QUICKNODE_API_KEY` in the environment; do not
write it into a configuration file.

The provider covers endpoints, the security mechanisms they enforce and who is
allowed past them, RPC method filtering, and rate limits both endpoint-wide and
Expand Down
12 changes: 6 additions & 6 deletions api/admin/admin.gen.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion api/admin/openapi.json

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

19 changes: 19 additions & 0 deletions api/admin/patches.json
Original file line number Diff line number Diff line change
Expand Up @@ -331,5 +331,24 @@
}
}
}
},
{
"op": "set",
"path": "/paths/~1v0~1endpoints~1{id}~1security/get/responses/200/content/application~1json/schema/properties/data/properties/domain_masks",
"value": {
"description": "An array of domain mask entries; null if none configured",
"type": "array",
"items": {
"type": "object",
"properties": {
"id": {
"type": "string"
},
"domain": {
"type": "string"
}
}
}
}
}
]
2 changes: 1 addition & 1 deletion docs/data-sources/chains.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions docs/data-sources/endpoint.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions docs/data-sources/endpoints.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion docs/index.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

12 changes: 6 additions & 6 deletions docs/resources/endpoint.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion docs/resources/endpoint_ip.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

10 changes: 4 additions & 6 deletions docs/resources/endpoint_jwt.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

6 changes: 3 additions & 3 deletions docs/resources/endpoint_rate_limits.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions docs/resources/endpoint_referrer.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

4 changes: 2 additions & 2 deletions docs/resources/endpoint_token.md

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion examples/data-sources/quicknode_chains/data-source.tf
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
data "quicknode_chains" "all" {}

# Chain slugs are abbreviations that often differ from the chain's name, so look
# one up rather than hardcoding it.
# one up instead of hardcoding it.
locals {
ethereum = one([for chain in data.quicknode_chains.all.chains : chain if chain.slug == "eth"])
}
Expand Down
2 changes: 1 addition & 1 deletion examples/resources/quicknode_endpoint_ip/resource.tf
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ resource "quicknode_endpoint_ip" "office" {

# Entries may be added before the toggle is enabled, which is the safe order for
# an endpoint already serving traffic. Adding one while security_options.ips is
# false produces a warning rather than an error.
# false produces a warning and not an error.
resource "quicknode_endpoint_ip" "vpn" {
endpoint_id = quicknode_endpoint.api.id
ip = "198.51.100.0/24"
Expand Down
8 changes: 3 additions & 5 deletions examples/resources/quicknode_endpoint_jwt/resource.tf
Original file line number Diff line number Diff line change
Expand Up @@ -11,11 +11,9 @@ resource "quicknode_endpoint" "api" {
resource "quicknode_endpoint_jwt" "signer" {
endpoint_id = quicknode_endpoint.api.id
name = "signer"
kid = "signer-2026-01"
public_key = file("${path.module}/signer.pub.pem")
}

# Put the generated kid in the header of the tokens signed with the matching
# private key.
output "jwt_kid" {
value = quicknode_endpoint_jwt.signer.kid
}
# Tokens signed with the matching private key carry the same kid in their
# header, which is how Quicknode picks the key to verify them with.
4 changes: 2 additions & 2 deletions examples/resources/quicknode_endpoint_token/import.sh
Original file line number Diff line number Diff line change
@@ -1,3 +1,3 @@
# Tokens are imported by id rather than by value, as "<endpoint id>/<token id>",
# so the credential stays out of shell history.
# Tokens are imported by id, as "<endpoint id>/<token id>", which keeps the
# credential out of shell history.
terraform import quicknode_endpoint_token.indexer 652052/d3312bd2-c1a2-4d89-865f-11c99fa3863a
Loading
Loading