Provider (kind: provider)
A cloud provider instance: which provider type, which region, and provider-level defaults (tags, passthrough configuration). One document per real account/subscription/region combination a workspace provisions into.
Schema
spec.properties.type— provider type (must match a providerconfig.md document’smeta.name)spec.properties.region— region/datacenter (cross-checked against thatProviderConfig’sspec.regions)spec.properties.display_name— optional human-readable label, purely cosmeticspec.authentication— optional; one of several supported methods (OAuth2, API key, certificate/mTLS, managed identity, CLI-based, …)spec.configuration— raw passthrough to the provisioner (e.g. extra Terraform provider-block arguments), never validated by strataspec.default_tags— default cloud tags applied to every resource this provider createsspec.custom— free-form data for external tooling, not consumed by any provisionerspec.lifecycle— optional IaC workflow hook phases
Example
apiVersion: strata.huybrechts.xyz/v2
kind: provider
meta:
name: azure-main
spec:
properties:
type: azure
region: westeurope
display_name: "West Europe"
default_tags:
managed-by: strata
Notes
No
spec.references(unlike v1): a provider no longer declares required variable/secret key names separately — any value that needs to vary by environment is a${var:}/${secret:}/${feature:}token directly in the relevant field, checked against a realEnvironmentin Phase 2 (see environment.md).default_tagsis distinct frommeta.tags— the former are real cloud tags, the latter is a free-form list for strata-internal categorization only.