Skip to content

6 files changed

+258
-0
lines changed

docs/rules/README.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -552,6 +552,9 @@ These rules enforce best practices and naming conventions:
552552
|aws_ecr_repository_invalid_name||
553553
|aws_ecr_repository_policy_invalid_policy||
554554
|aws_ecr_repository_policy_invalid_repository||
555+
|aws_ecrpublic_repository_invalid_repository_name||
556+
|aws_ecrpublic_repository_policy_invalid_policy||
557+
|aws_ecrpublic_repository_policy_invalid_repository_name||
555558
|aws_ecs_account_setting_default_invalid_name||
556559
|aws_ecs_service_invalid_launch_type||
557560
|aws_ecs_service_invalid_propagate_tags||
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
// This file generated by `generator/`. DO NOT EDIT
2+
3+
package models
4+
5+
import (
6+
"fmt"
7+
"log"
8+
"regexp"
9+
10+
hcl "github.com/hashicorp/hcl/v2"
11+
"github.com/terraform-linters/tflint-plugin-sdk/tflint"
12+
)
13+
14+
// AwsEcrpublicRepositoryInvalidRepositoryNameRule checks the pattern is valid
15+
type AwsEcrpublicRepositoryInvalidRepositoryNameRule struct {
16+
resourceType string
17+
attributeName string
18+
max int
19+
min int
20+
pattern *regexp.Regexp
21+
}
22+
23+
// NewAwsEcrpublicRepositoryInvalidRepositoryNameRule returns new rule with default attributes
24+
func NewAwsEcrpublicRepositoryInvalidRepositoryNameRule() *AwsEcrpublicRepositoryInvalidRepositoryNameRule {
25+
return &AwsEcrpublicRepositoryInvalidRepositoryNameRule{
26+
resourceType: "aws_ecrpublic_repository",
27+
attributeName: "repository_name",
28+
max: 205,
29+
min: 2,
30+
pattern: regexp.MustCompile(`^(?:[a-z0-9]+(?:[._-][a-z0-9]+)*/)*[a-z0-9]+(?:[._-][a-z0-9]+)*$`),
31+
}
32+
}
33+
34+
// Name returns the rule name
35+
func (r *AwsEcrpublicRepositoryInvalidRepositoryNameRule) Name() string {
36+
return "aws_ecrpublic_repository_invalid_repository_name"
37+
}
38+
39+
// Enabled returns whether the rule is enabled by default
40+
func (r *AwsEcrpublicRepositoryInvalidRepositoryNameRule) Enabled() bool {
41+
return true
42+
}
43+
44+
// Severity returns the rule severity
45+
func (r *AwsEcrpublicRepositoryInvalidRepositoryNameRule) Severity() string {
46+
return tflint.ERROR
47+
}
48+
49+
// Link returns the rule reference link
50+
func (r *AwsEcrpublicRepositoryInvalidRepositoryNameRule) Link() string {
51+
return ""
52+
}
53+
54+
// Check checks the pattern is valid
55+
func (r *AwsEcrpublicRepositoryInvalidRepositoryNameRule) Check(runner tflint.Runner) error {
56+
log.Printf("[TRACE] Check `%s` rule", r.Name())
57+
58+
return runner.WalkResourceAttributes(r.resourceType, r.attributeName, func(attribute *hcl.Attribute) error {
59+
var val string
60+
err := runner.EvaluateExpr(attribute.Expr, &val, nil)
61+
62+
return runner.EnsureNoError(err, func() error {
63+
if len(val) > r.max {
64+
runner.EmitIssueOnExpr(
65+
r,
66+
"repository_name must be 205 characters or less",
67+
attribute.Expr,
68+
)
69+
}
70+
if len(val) < r.min {
71+
runner.EmitIssueOnExpr(
72+
r,
73+
"repository_name must be 2 characters or higher",
74+
attribute.Expr,
75+
)
76+
}
77+
if !r.pattern.MatchString(val) {
78+
runner.EmitIssueOnExpr(
79+
r,
80+
fmt.Sprintf(`"%s" does not match valid pattern %s`, truncateLongMessage(val), `^(?:[a-z0-9]+(?:[._-][a-z0-9]+)*/)*[a-z0-9]+(?:[._-][a-z0-9]+)*$`),
81+
attribute.Expr,
82+
)
83+
}
84+
return nil
85+
})
86+
})
87+
}
Lines changed: 67 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,67 @@
1+
// This file generated by `generator/`. DO NOT EDIT
2+
3+
package models
4+
5+
import (
6+
"log"
7+
8+
hcl "github.com/hashicorp/hcl/v2"
9+
"github.com/terraform-linters/tflint-plugin-sdk/tflint"
10+
)
11+
12+
// AwsEcrpublicRepositoryPolicyInvalidPolicyRule checks the pattern is valid
13+
type AwsEcrpublicRepositoryPolicyInvalidPolicyRule struct {
14+
resourceType string
15+
attributeName string
16+
max int
17+
}
18+
19+
// NewAwsEcrpublicRepositoryPolicyInvalidPolicyRule returns new rule with default attributes
20+
func NewAwsEcrpublicRepositoryPolicyInvalidPolicyRule() *AwsEcrpublicRepositoryPolicyInvalidPolicyRule {
21+
return &AwsEcrpublicRepositoryPolicyInvalidPolicyRule{
22+
resourceType: "aws_ecrpublic_repository_policy",
23+
attributeName: "policy",
24+
max: 10240,
25+
}
26+
}
27+
28+
// Name returns the rule name
29+
func (r *AwsEcrpublicRepositoryPolicyInvalidPolicyRule) Name() string {
30+
return "aws_ecrpublic_repository_policy_invalid_policy"
31+
}
32+
33+
// Enabled returns whether the rule is enabled by default
34+
func (r *AwsEcrpublicRepositoryPolicyInvalidPolicyRule) Enabled() bool {
35+
return true
36+
}
37+
38+
// Severity returns the rule severity
39+
func (r *AwsEcrpublicRepositoryPolicyInvalidPolicyRule) Severity() string {
40+
return tflint.ERROR
41+
}
42+
43+
// Link returns the rule reference link
44+
func (r *AwsEcrpublicRepositoryPolicyInvalidPolicyRule) Link() string {
45+
return ""
46+
}
47+
48+
// Check checks the pattern is valid
49+
func (r *AwsEcrpublicRepositoryPolicyInvalidPolicyRule) Check(runner tflint.Runner) error {
50+
log.Printf("[TRACE] Check `%s` rule", r.Name())
51+
52+
return runner.WalkResourceAttributes(r.resourceType, r.attributeName, func(attribute *hcl.Attribute) error {
53+
var val string
54+
err := runner.EvaluateExpr(attribute.Expr, &val, nil)
55+
56+
return runner.EnsureNoError(err, func() error {
57+
if len(val) > r.max {
58+
runner.EmitIssueOnExpr(
59+
r,
60+
"policy must be 10240 characters or less",
61+
attribute.Expr,
62+
)
63+
}
64+
return nil
65+
})
66+
})
67+
}
Lines changed: 87 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,87 @@
1+
// This file generated by `generator/`. DO NOT EDIT
2+
3+
package models
4+
5+
import (
6+
"fmt"
7+
"log"
8+
"regexp"
9+
10+
hcl "github.com/hashicorp/hcl/v2"
11+
"github.com/terraform-linters/tflint-plugin-sdk/tflint"
12+
)
13+
14+
// AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule checks the pattern is valid
15+
type AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule struct {
16+
resourceType string
17+
attributeName string
18+
max int
19+
min int
20+
pattern *regexp.Regexp
21+
}
22+
23+
// NewAwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule returns new rule with default attributes
24+
func NewAwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule() *AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule {
25+
return &AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule{
26+
resourceType: "aws_ecrpublic_repository_policy",
27+
attributeName: "repository_name",
28+
max: 205,
29+
min: 2,
30+
pattern: regexp.MustCompile(`^(?:[a-z0-9]+(?:[._-][a-z0-9]+)*/)*[a-z0-9]+(?:[._-][a-z0-9]+)*$`),
31+
}
32+
}
33+
34+
// Name returns the rule name
35+
func (r *AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule) Name() string {
36+
return "aws_ecrpublic_repository_policy_invalid_repository_name"
37+
}
38+
39+
// Enabled returns whether the rule is enabled by default
40+
func (r *AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule) Enabled() bool {
41+
return true
42+
}
43+
44+
// Severity returns the rule severity
45+
func (r *AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule) Severity() string {
46+
return tflint.ERROR
47+
}
48+
49+
// Link returns the rule reference link
50+
func (r *AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule) Link() string {
51+
return ""
52+
}
53+
54+
// Check checks the pattern is valid
55+
func (r *AwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule) Check(runner tflint.Runner) error {
56+
log.Printf("[TRACE] Check `%s` rule", r.Name())
57+
58+
return runner.WalkResourceAttributes(r.resourceType, r.attributeName, func(attribute *hcl.Attribute) error {
59+
var val string
60+
err := runner.EvaluateExpr(attribute.Expr, &val, nil)
61+
62+
return runner.EnsureNoError(err, func() error {
63+
if len(val) > r.max {
64+
runner.EmitIssueOnExpr(
65+
r,
66+
"repository_name must be 205 characters or less",
67+
attribute.Expr,
68+
)
69+
}
70+
if len(val) < r.min {
71+
runner.EmitIssueOnExpr(
72+
r,
73+
"repository_name must be 2 characters or higher",
74+
attribute.Expr,
75+
)
76+
}
77+
if !r.pattern.MatchString(val) {
78+
runner.EmitIssueOnExpr(
79+
r,
80+
fmt.Sprintf(`"%s" does not match valid pattern %s`, truncateLongMessage(val), `^(?:[a-z0-9]+(?:[._-][a-z0-9]+)*/)*[a-z0-9]+(?:[._-][a-z0-9]+)*$`),
81+
attribute.Expr,
82+
)
83+
}
84+
return nil
85+
})
86+
})
87+
}

rules/models/mappings/ecr-public.hcl

Lines changed: 11 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
import = "aws-sdk-go/models/apis/ecr-public/2020-10-30/api-2.json"
2+
3+
mapping "aws_ecrpublic_repository" {
4+
repository_name = RepositoryName
5+
catalog_data = RepositoryCatalogDataInput
6+
}
7+
8+
mapping "aws_ecrpublic_repository_policy" {
9+
repository_name = RepositoryName
10+
policy = RepositoryPolicyText
11+
}

rules/models/provider.go

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -480,6 +480,9 @@ var Rules = []tflint.Rule{
480480
NewAwsEcrRepositoryInvalidNameRule(),
481481
NewAwsEcrRepositoryPolicyInvalidPolicyRule(),
482482
NewAwsEcrRepositoryPolicyInvalidRepositoryRule(),
483+
NewAwsEcrpublicRepositoryInvalidRepositoryNameRule(),
484+
NewAwsEcrpublicRepositoryPolicyInvalidPolicyRule(),
485+
NewAwsEcrpublicRepositoryPolicyInvalidRepositoryNameRule(),
483486
NewAwsEcsAccountSettingDefaultInvalidNameRule(),
484487
NewAwsEcsServiceInvalidLaunchTypeRule(),
485488
NewAwsEcsServiceInvalidPropagateTagsRule(),

0 commit comments

Comments
 (0)