Snowflake Cortex - Terraform

This sample creates the overview stack with the Snowflake Terraform provider.

File What it creates

main.tf

The provider, the database and the schema.

iam.tf

The USER role and its grants on the database, schema and warehouse.

neo4j_access.tf

The secret, the network rule and the external access integration.

functions.tf

The model stage and upload, the Python UDFs, the SQL tool functions and their grants.

accounts.tf

The CUSTOMER_ACCOUNTS view, its semantic view and the grant on it.

agent.tf

The Cortex agent and its usage grant.

setup-terraform.sql

The TERRAFORM_SVC role and service user that Terraform runs as.

Prerequisites

  • A Snowflake account. You need ACCOUNTADMIN once, to run setup-terraform.sql.

  • Terraform 1.4 or later.

  • The Snowflake CLI (snow) on your PATH. Terraform uses it to upload the model. To use another binary, set SNOW=/path/to/snow.

  • Python 3 with sentence-transformers. The first apply needs it to download the model.

Setup

  1. Create the service user. Add your public key to setup-terraform.sql and run the script as ACCOUNTADMIN.

  2. Set the Terraform variables (template: terraform.tfvars.example):

   cd samples/1-terraform
   cp terraform.tfvars.example terraform.tfvars
   # Fill in organization, account, user, private key path and Neo4j password.
  1. Apply:

   terraform init
   terraform plan
   terraform apply
The first apply downloads `all-MiniLM-L6-v2` into `shared/model/minilm/` and uploads it to the `MODEL_STAGE` stage. Later applies upload it again only if the files change.

Implementation notes

  • The sample needs provider 2.21. main.tf turns on the preview features it uses.

  • The provider cannot upload files, so upload_model.sh.tftpl uploads the model with snow stage copy.

  • The SQL functions and the semantic view come from shared/sql/. The Snowsight guide uses the same SQL.

  • Names are uppercase. The provider quotes them, and Cortex rejects quoted lowercase names.

  • Some changes show as in-place updates but are not applied, for example renamed UDF arguments or a changed semantic view. Run terraform apply -replace=<resource> for them.

  • The query_neo4j tool lets the agent write its own Cypher. Read the warning first.