lmnr-ai/lmnr, manages Signals and LLM profiles with Terraform or OpenTofu. Keep Signal prompts and output schemas in your repo, review every change in terraform plan, and roll the same definitions out to staging and production projects. It works with Laminar Cloud and self-hosted deployments.
Quick start
Create a project API key in your project’s settings and export it:main.tf
On a self-hosted deployment, a Signal also needs an LLM profile and model to run on. See Run a Signal on a profile.
Configure the provider
Arguments in the
provider block take precedence over environment variables.
Self-hosted deployments
Point the provider at your app-server’s HTTP origin:Several projects
A project API key scopes the provider to one project. Declare one provider alias per project key to manage several projects from one configuration:Shape when a Signal runs
Thetrigger, filters, sample_rate, and mode arguments map to the same settings as the Signal form in the UI:
triggersets when the Signal is evaluated: when the root span finishes (the default,rootSpanFinished) or when a span named inspan_namesfinishes (spanName).filterssets which traces are evaluated. All conditions must hold. Omittingfiltersapplies the defaulttotal_token_count > 1000; setfilters = []to evaluate every trace.modeisrealtime(the default) orbatch.
Manage LLM profiles
Anlmnr_llm_profile holds a provider, its credentials, and the models it exposes. Profiles belong to the project’s workspace, so every project in that workspace can use them.
llm_provider rather than provider because provider is a reserved Terraform argument. The provider reference lists the fields for each provider, including AWS Bedrock, Azure AI Foundry, and OpenAI-compatible gateways.
Run a Signal on a profile (self-hosted)
On self-hosted deployments every Signal runs on an LLM profile. Setllm_profile_id and one of the profile’s models:
llm_profile_id and model, or the apply fails.
Import existing Signals and profiles
Bring a Signal or profile you created in the UI under Terraform by its UUID, which you can copy from the Laminar UI:import block and let terraform plan -generate-config-out=generated.tf write the configuration for you.
After importing an LLM profile, set its credentials in the configuration. Terraform can’t read them back, so the next apply writes them.
Look up existing resources
Data sources read a Signal or profile that Terraform doesn’t manage, byid or exact name:
Use OpenTofu
The same configuration works with OpenTofu, which installs the provider from the OpenTofu registry. Runtofu init and tofu apply instead of the terraform commands.
Next steps
- Signals - how a Signal reads a trace and what its events contain.
- LLM profiles - supported providers and how credentials are stored.
- Signals CLI - create and inspect Signals from your terminal.
- Provider reference - every argument and attribute, on the Terraform Registry.