Infrastructure
Terraform Cloud Webhooks
Infrastructure as code platform by HashiCorp. Receive events for runs, plan/apply status, and workspace changes.
Connecting Terraform Cloud to Hookbase
Create a source in Hookbase first — it gives you an ingest URL to paste into Terraform Cloud. Then:
- 1Go to Terraform Cloud → Workspace → Settings → Notifications
- 2Click "Create a Notification" and select "Webhook"
- 3Paste your Hookbase ingest URL
- 4Set a token for HMAC verification and add it to your Hookbase source
- 5Select the triggers (run created, needs attention, completed, errored)
Signature verification
Terraform Cloud signs its webhooks with HMAC-SHA512 in X-TFE-Notification-Signature, and Hookbase has no verifier for that combination today. We would rather say so here than let a source report every event as verified while nothing was checked.
What you can do:
- Receive them on a
customsource with no signing secret. Hookbase still dedupes, retries, transforms, routes and replays them; it just does not vouch for the sender. - Set a signing secret anyway if Terraform Cloud can be configured to send a hex HMAC-SHA256 of the raw body in
X-Signature,X-Webhook-SignatureorX-Hub-Signature-256— that is the one scheme the custom verifier implements. - Verify downstream: the original headers travel with the event, so your own service or a transform can check the signature itself. The key is at Terraform Cloud → Workspace → Settings → Notifications → Token.
- Narrow the blast radius with an IP allowlist and a hard-to-guess source slug.
Terraform Cloud event types
6 of the events people route most often. Hookbase accepts every event Terraform Cloud sends, whether or not it is listed here.
run:created
A run was created
run:planning
A run started planning
run:needs_attention
A run needs confirmation to apply
run:applying
A run is applying changes
run:completed
A run completed successfully
run:errored
A run encountered an error
What a Terraform Cloud webhook looks like
A run:completed payload. Hookbase stores the raw body exactly as it arrived, so this is also what you get back on a replay.
{
"payload_version": 1,
"notification_configuration_id": "nc-abc123",
"run_url": "https://app.terraform.io/app/org/workspaces/infra/runs/run-def456",
"run_id": "run-def456",
"run_message": "Queued via API",
"run_created_at": "2024-01-15T10:20:00.000Z",
"run_created_by": "dev@example.com",
"workspace_id": "ws-ghi789",
"workspace_name": "production-infra",
"organization_name": "my-org",
"notifications": [
{
"message": "Run completed successfully",
"trigger": "run:completed",
"run_status": "applied",
"run_updated_at": "2024-01-15T10:30:00.000Z"
}
]
}Start receiving Terraform Cloud webhooks
Create a source, paste the URL into Terraform Cloud, and watch the first event arrive. The free tier includes 1,000 events a month.
Get Started Free