Manage HTML/CSS to Image resources with Terraform.
Website · Documentation · Management API · API reference · Terraform Registry
Resources include proxies, API keys, OG configs, storage destinations, HTML/CSS templates, and HTML/CSS, URL, and templated images. Templates create new versions on edits; image inputs trigger replacement. Image creation saves a definition without rendering bytes.
Add the provider to your Terraform configuration:
terraform {
required_providers {
htmlcsstoimage = {
source = "htmlcsstoimage/html-css-to-image"
version = "= 0.1.0"
}
}
}
provider "htmlcsstoimage" {}
resource "htmlcsstoimage_image_html_css" "hello" {
html = "<h1>Hello from Terraform</h1>"
}Set HCTI_API_ID and HCTI_API_KEY in your environment, then run:
terraform init
terraform plan
terraform applyThe API key needs the permissions required by the resources you manage. The default API URL is https://hcti.io. See provider configuration and the Terraform Registry.
For a complete AWS setup, see the end-to-end example: S3, IAM trust with the HCTI external ID, two API keys in Secrets Manager, a storage destination, and image creation/rendering.
- Proxy: examples, inputs, outputs, credential updates, and import
- API key: permissions, one-time secrets, import, and disable behavior
- OG config: HTML/CSS and templates, render options, headers, and import
- Storage destination: providers, credentials, connection tests, and import
- Template: versioning, rendering inputs, and import
- HTML/CSS image, URL image, and templated image
- AWS storage external ID lookup
- Existing template lookup and template version listing
See the resource reference. All settings update in place. Reads only fetch metadata and never render images or test proxy connectivity.
Passwords are sensitive but persist in Terraform state when supplied. Import reconstructs the username without inventing a password. Omit password to retain an existing password during an unrelated update; changing username requires a password, and an empty password is valid. Omit the entire authentication object to remove credentials. The provider sends API retention flags internally.
An omitted port is sent as null. effective_port exposes the server-selected value without filling the input with a default. Equivalent normalized names and bypass hosts preserve the configured representation to avoid inconsistent plans.
Only HTTP 404 removes a resource during refresh or makes a repeated delete successful. Other errors surface without interpreting the resource as missing. Writes are not retried automatically.
API failures include the HTTP status, API error code/message, and field-level validation paths and messages. Known sensitive request/state values are redacted from messages; raw response bodies and headers are not included.
Local validation checks input structure and basic invariants, such as nonnegative rendering values. The API controls rendering ranges, account limits, string lengths, collection sizes, supported timezones, and storage regions. Documented API limits are informational, not hardcoded provider restrictions.
See development, live acceptance testing, and releasing.