Note
- Dify v1.0.0 (and later) is supported now! Try it and give us feedbacks!!
- If you fail to install any plugin, try several times and succeed in many cases.
This repository allows you to automatically set up Google Cloud resources using Terraform and deploy Dify in a highly available configuration.
- Serverless hosting
- Auto-scaling
- Data persistence
- Google Cloud account
- Terraform installed
- gcloud CLI installed
- Set environment-specific values in the
terraform/environments/dev/terraform.tfvarsfile.
Important
Secret Management using Google Secret Manager This project uses Google Secret Manager to handle all sensitive data securely. All secrets are fetched dynamically at runtime and are not stored in the repository.
Before running terraform apply, you must create the following secrets in Google Secret Manager:
| Secret Name | Description | How to Generate |
|---|---|---|
dify-secret-key |
Dify application SECRET_KEY. |
openssl rand -base64 42 |
dify-db-password |
Password for the Cloud SQL PostgreSQL database. | Generate a strong password. |
dify-plugin-daemon-key |
Secret key for the Dify plugin daemon. | openssl rand -base64 42 |
dify-plugin-dify-inner-api-key |
Inner API key for Dify plugins. | openssl rand -base64 42 |
dify-slack-webhook-url |
The full Slack Incoming Webhook URL for alerts. | From your Slack App configuration. |
dify-aws-access-key-id |
AWS Access Key ID (if using AWS services). | From your AWS IAM user. |
dify-aws-secret-access-key |
AWS Secret Access Key (if using AWS services). | From your AWS IAM user. |
Permissions: The user or service account running terraform apply must have the Secret Manager Secret Accessor (roles/secretmanager.secretAccessor) IAM role to access these secrets.
- Create a GCS bucket to manage Terraform state in advance, and replace "your-tfstate-bucket" in the
terraform/environments/dev/provider.tffile with the name of the created bucket.
-
Clone the repository:
git clone https://github.com/DeNA/dify-google-cloud-terraform.git
-
Initialize Terraform:
cd terraform/environments/dev terraform init -
Make Artifact Registry repository:
terraform apply -target=module.registry
-
Build & push container images:
cd ../../.. sh ./docker/cloudbuild.sh <your-project-id> <your-region>
You can also specify a version of the dify-api image.
sh ./docker/cloudbuild.sh <your-project-id> <your-region> <dify-api-version>
If no version is specified, the latest version is used by default.
-
Terraform plan:
cd terraform/environments/dev terraform plan -
Terraform apply:
terraform apply
terraform destroyNote: Cloud Storage, Cloud SQL, VPC, and VPC Peering cannot be deleted with the terraform destroy command. These are critical resources for data persistence. Access the console and carefully delete them. After that, use the terraform destroy command to ensure all resources have been deleted.
When running terraform apply, you may encounter an invalid_auth error while creating the google_monitoring_notification_channel for Slack, even if your webhook URL is correct.
│ Error: Error creating NotificationChannel: googleapi: Error 400: invalid_auth
This can be caused by a rare inconsistency in the GCP API when the channel is created via Terraform. If you have verified your webhook URL is correct (e.g., by testing it with curl), the workaround is to create the channel manually in the GCP console and then import it into your Terraform state.
Resolution Steps:
-
Create the Channel Manually in GCP:
- Go to the GCP Console: Monitoring > Alerting.
- Click EDIT NOTIFICATION CHANNELS.
- Under Slack, click ADD NEW and create the channel using your webhook URL.
-
Ensure the Resource Exists in Your Terraform Code: Make sure the notification channel resource is defined in your Terraform configuration (e.g.,
modules/cloudrun/main.tf). Theterraform importcommand requires a corresponding resource block in the code.resource "google_monitoring_notification_channel" "slack" { display_name = "Slack" type = "slack" labels = { channel_name = var.slack_channel_name } sensitive_labels { auth_token = var.slack_webhook_url } }
-
Find the Notification Channel's Full ID: Use the
gcloudCLI to find the full name/ID of the channel you just created. Replace[YOUR_CHANNEL_DISPLAY_NAME]with the name you gave it in the console.gcloud beta monitoring channels list --filter="displayName='[YOUR_CHANNEL_DISPLAY_NAME]'" --format="value(name)"
The output will look something like
projects/[your-project-id]/notificationChannels/[channel-id]. -
Run
terraform import: From theterraform/environments/devdirectory, run the import command. Replace[FULL_CHANNEL_ID_FROM_PREVIOUS_STEP]with the value you just copied.terraform import module.cloudrun.google_monitoring_notification_channel.slack [FULL_CHANNEL_ID_FROM_PREVIOUS_STEP]
You should see an "Import successful!" message.
-
Verify the State: Run
terraform plan. The output should beNo changes. Your infrastructure matches the configuration.. This confirms the manually created channel is now fully managed by Terraform.
This software is licensed under the MIT License. See the LICENSE file for more details.
