Snowflake Cortex - Terraform
This sample creates the overview stack with the Snowflake Terraform provider.
| File | What it creates |
|---|---|
The provider, the database and the schema. |
|
The |
|
The secret, the network rule and the external access integration. |
|
The model stage and upload, the Python UDFs, the SQL tool functions and their grants. |
|
The |
|
The Cortex agent and its usage grant. |
|
The |
Prerequisites
-
A Snowflake account. You need
ACCOUNTADMINonce, to runsetup-terraform.sql. -
Terraform 1.4 or later.
-
The Snowflake CLI (
snow) on yourPATH. Terraform uses it to upload the model. To use another binary, setSNOW=/path/to/snow. -
Python 3 with
sentence-transformers. The first apply needs it to download the model.
Setup
-
Create the service user. Add your public key to
setup-terraform.sqland run the script asACCOUNTADMIN. -
Set the Terraform variables (template:
terraform.tfvars.example):
cd samples/1-terraform
cp terraform.tfvars.example terraform.tfvars
# Fill in organization, account, user, private key path and Neo4j password.
-
Apply:
terraform init
terraform plan
terraform apply
The first apply downloads `all-MiniLM-L6-v2` into `shared/model/minilm/` and uploads it to the `MODEL_STAGE` stage. Later applies upload it again only if the files change.
Implementation notes
-
The sample needs provider 2.21.
main.tfturns on the preview features it uses. -
The provider cannot upload files, so
upload_model.sh.tftpluploads the model withsnow stage copy. -
The SQL functions and the semantic view come from
shared/sql/. The Snowsight guide uses the same SQL. -
Names are uppercase. The provider quotes them, and Cortex rejects quoted lowercase names.
-
Some changes show as in-place updates but are not applied, for example renamed UDF arguments or a changed semantic view. Run
terraform apply -replace=<resource>for them. -
The
query_neo4jtool lets the agent write its own Cypher. Read the warning first.