Skip to main content
The Laminar Terraform provider, lmnr-ai/lmnr, manages Signals and LLM profiles with Terraform or OpenTofu. Keep Signal prompts and output schemas in your repo, review every change in terraform plan, and roll the same definitions out to staging and production projects. It works with Laminar Cloud and self-hosted deployments.

Quick start

Create a project API key in your project’s settings and export it:
Declare the provider and a Signal:
main.tf
Install the provider and create the Signal:
The Signal starts evaluating new traces as soon as the apply finishes. Open it under Signals in your project to see its events.
On a self-hosted deployment, a Signal also needs an LLM profile and model to run on. See Run a Signal on a profile.

Configure the provider

Arguments in the provider block take precedence over environment variables.

Self-hosted deployments

Point the provider at your app-server’s HTTP origin:

Several projects

A project API key scopes the provider to one project. Declare one provider alias per project key to manage several projects from one configuration:

Shape when a Signal runs

The trigger, filters, sample_rate, and mode arguments map to the same settings as the Signal form in the UI:
  • trigger sets when the Signal is evaluated: when the root span finishes (the default, rootSpanFinished) or when a span named in span_names finishes (spanName).
  • filters sets which traces are evaluated. All conditions must hold. Omitting filters applies the default total_token_count > 1000; set filters = [] to evaluate every trace.
  • mode is realtime (the default) or batch.
The provider reference lists every column and operator.

Manage LLM profiles

An lmnr_llm_profile holds a provider, its credentials, and the models it exposes. Profiles belong to the project’s workspace, so every project in that workspace can use them.
The attribute is llm_provider rather than provider because provider is a reserved Terraform argument. The provider reference lists the fields for each provider, including AWS Bedrock, Azure AI Foundry, and OpenAI-compatible gateways.
The Laminar API never returns credentials, so Terraform keeps the values you configure in its state, marked sensitive. Store state in an encrypted backend.

Run a Signal on a profile (self-hosted)

On self-hosted deployments every Signal runs on an LLM profile. Set llm_profile_id and one of the profile’s models:
On Laminar Cloud, Signals run on Laminar’s own models: leave out llm_profile_id and model, or the apply fails.

Import existing Signals and profiles

Bring a Signal or profile you created in the UI under Terraform by its UUID, which you can copy from the Laminar UI:
On Terraform 1.5 and later you can also use an import block and let terraform plan -generate-config-out=generated.tf write the configuration for you. After importing an LLM profile, set its credentials in the configuration. Terraform can’t read them back, so the next apply writes them.

Look up existing resources

Data sources read a Signal or profile that Terraform doesn’t manage, by id or exact name:

Use OpenTofu

The same configuration works with OpenTofu, which installs the provider from the OpenTofu registry. Run tofu init and tofu apply instead of the terraform commands.

Next steps

  • Signals - how a Signal reads a trace and what its events contain.
  • LLM profiles - supported providers and how credentials are stored.
  • Signals CLI - create and inspect Signals from your terminal.
  • Provider reference - every argument and attribute, on the Terraform Registry.