Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 3 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -49,3 +49,6 @@ modules/**/.terraform.lock.hcl

# ignore infracost resources
.infracost/

# test fixtures
conftest-policies/testdata/
3 changes: 2 additions & 1 deletion .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,12 +6,13 @@ repos:
- id: terraform_fmt
- id: terraform_docs
- id: terraform_validate
exclude: '^[^/]+$|^modules/certificate/'
exclude: '^[^/]+$|^modules/certificate/|^conftest-policies/testdata/'
- id: terraform_tflint
args:
- "--args=--config=__GIT_WORKING_DIR__/.tflint.hcl"
- "--args=--disable-rule=terraform_standard_module_structure"
- "--args=--disable-rule=terraform_unused_required_providers"
exclude: '^conftest-policies/testdata/'
- id: terraform_checkov
args:
- --args=--quiet
Expand Down
18 changes: 18 additions & 0 deletions conftest-policies/provider_version_pinning.rego
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
package main

import rego.v1

deny_unpinned_provider_version contains msg if {
some path
some block in input.resource.terraform[path]
some name, provider in block.required_providers
version_constraint := object.get(provider, "version", "")
version_constraint != ""
startswith(version_constraint, ">=")
not contains(version_constraint, "~>")
not contains(version_constraint, "<")
msg := sprintf(
"%s/versions.tf: provider '%s' has loose version constraint '%s' - pin to specific version or use '~>' for minor version pinning",
[path, name, version_constraint],
)
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = ">= 4.66.0"
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "= 4.66.0"
}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 4.66.0"
}
}
}