// the find
Mastercard/terraform-provider-restapi
A terraform provider to manage objects in a RESTful API
A generic Terraform provider that lets you manage arbitrary REST API resources without writing a dedicated provider — essentially a Terraform-wrapped cURL client with JSON support. It's for teams stuck with internal or niche APIs that don't have first-class Terraform support and are willing to work within a narrow set of assumptions about how that API behaves.
The docs are unusually honest about exactly where this breaks — it spells out that request bodies are always JSON-encoded even if you change the Content-Type header, and explains the destroy-path assumption (uniform DELETE support across resources) with concrete workarounds (destroy_method/destroy_data, or falling back to null_resource + local-exec). It even points you to three alternative providers (hashicorp/http, salrashid123/http-full, magodo/restful) when your API doesn't fit its model, which is rare for a project to do. Ships a fakeserver CLI and matching example .tf files so you can learn the provider's request/response behavior against a mock backend before pointing it at a real API. The internal/apiclient and internal/provider packages have real test coverage (CRUD, PATCH, search-by-query, schema, delta checking), not just a smoke test.
Hard JSON-only limitation: it will not send form-urlencoded or multipart bodies no matter what you set in headers, so any API that isn't JSON-in/JSON-out is a non-starter — this is common enough to warrant its own troubleshooting entry for HTTP 415 errors. Explicitly in maintenance mode: updates are 'sporadic,' driven by security fixes and community PRs rather than a roadmap, and the maintainers state up front that per-API troubleshooting isn't guaranteed. Debugging relies on reading raw HTTP request/response dumps via TF_LOG rather than the provider surfacing meaningful errors, so you're doing a fair amount of the diagnostic work yourself. The path-substitution model for split create/read/update paths (the {id} token, read_path pinned to state rather than new config) is a subtle enough behavior that it's called out as a specific gotcha in the README rather than being self-evident from the schema.