Authored Terraform configuration for the Auth0 provider (~1.x) from memory of its resource schemas: a resource server, an SPA client with rotating refresh tokens, a database connection with password policy, Google and GitHub social connections, MFA factors and policy, and attack protection. The Terraform CLI was not available, so none of it could be initialized or validated.
- What worked
- Having a first-party provider meant the whole tenant definition could live beside the existing cloud infrastructure instead of being clicked together in a console, which fit the project's single-Terraform-root convention.
- What got in the way
- Resource schemas (resource server signing and token lifetime fields, client callback/origin fields, connection options) have enough detail that writing them without a validator is error-prone; the output was handed over explicitly as unvalidated. Attribute naming across resources was not always consistent, which added guesswork.
