fusion_soar_workflow
Manages a Falcon Fusion SOAR workflow. The workflow is defined by a YAML document in the format the Falcon console exports, so the easiest way to author one is to build it in the console, export it, and pass the file to definition. Only the keys set in definition are managed: keys the API adds, and changes made outside Terraform to keys the configuration does not set, are not reported as drift. The API sets the trigger’s name and each action’s default_name itself, so values given for them are ignored. The API drops keys it does not recognize, so a misspelled key fails the apply with the path of the key that was dropped. A definition exported from another CID can reference activities and plugin configurations that do not exist in this CID; the workflow is then saved with validation errors and cannot be enabled.
API Scopes
Section titled “API Scopes”The following API scopes are required:
- Workflow: READ
- Workflow: WRITE
Example Usage
Section titled “Example Usage”terraform { required_providers { crowdstrike = { source = "crowdstrike/crowdstrike" } }}
provider "crowdstrike" {}
# The definition uses the YAML format the Falcon console exports. To manage an# existing workflow, export it from the console and load the exported file.resource "crowdstrike_fusion_soar_workflow" "from_file" { enabled = true definition = file("${path.module}/workflow.yaml")}
# The definition can also be written inline.resource "crowdstrike_fusion_soar_workflow" "inline" { enabled = true
definition = <<-EOT name: tf-example-inline-workflow description: Pauses for one minute when run on demand. trigger: next: - Sleep name: On demand type: On demand actions: Sleep: id: 4f1af1ae4c13dc1e3bcd725f8dc0f63b properties: sleep_time: 1m version_constraint: ~1 EOT}
output "fusion_soar_workflow_from_file" { value = crowdstrike_fusion_soar_workflow.from_file}
output "fusion_soar_workflow_inline" { value = crowdstrike_fusion_soar_workflow.inline}Schema
Section titled “Schema”Required
Section titled “Required”definition(String) The workflow definition as a YAML document, in the format produced by exporting a workflow from the Falcon console. It must set a top-levelname, which must be unique in the CID. Renaming the workflow updates it in place. Actions should setversion_constraint; the API treats an omitted constraint as~0.
Optional
Section titled “Optional”enabled(Boolean) Whether the workflow is enabled and runs when its trigger fires. A workflow with validation errors cannot be enabled. Defaults tofalse.
Read-Only
Section titled “Read-Only”id(String) Identifier for the workflow.
Import
Section titled “Import”Import is supported using the following syntax:
# A Fusion SOAR workflow can be imported by specifying the workflow ID.# Import reads the definition from the API's YAML export, which is formatted# differently from most configurations, so the first apply after import# updates the workflow once to store the configured definition.terraform import crowdstrike_fusion_soar_workflow.example 7fb858a949034a0cbca175f660f1e769