Terraform
Description
The Terraform crawler looks recursively for every .terraform.lock.hcl file from a root directory, and updates each provider pinned in it.
Providers are read from the lock file rather than from required_providers blocks, so a module with no lock file yields nothing. Run terraform init first if that is the case.
This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a terraform crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Generated manifests
Automation is done by using two resources: terraform/registry as the source and
terraform/lock as the target.
The version filter is narrowed per provider from the version currently locked, so a provider on 5.30.0 is filtered with >=5.30.0.
Platforms
A Terraform lock file records a checksum per target platform, and the target has to refresh all of them or terraform init will fail on the platforms left behind.
Use platforms to declare which ones to request. When unset, Updatecli falls back to linux_amd64, linux_arm64, darwin_amd64, and darwin_arm64.
Important | The checksums written back cover exactly the platforms requested. If your lock file needs a platform outside the fallback list, such as windows_amd64, list every platform you require explicitly. |
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| ignore | array | ignore specifies rule to ignore .terraform.lock.hcl update. | |
| path | string | path specifies a .terraform.lock.hcl path pattern, the pattern requires to match all of name, not just a substring. | |
| providers | object |
examples:
| |
| only | array | only specify required rule to restrict .terraform.lock.hcl update. | |
| path | string | path specifies a .terraform.lock.hcl path pattern, the pattern requires to match all of name, not just a substring. | |
| providers | object |
examples:
| |
| platforms | array |
remarks: * Fallback is linux_amd64, linux_arm64, darwin_amd64, darwin_arm64 | |
| rootdir | string | rootdir defines the root directory used to recursively search for .terraform.lock.hcl | |
| versionfilter | object |
kind - semver
versionfilter of kind kind - regex
versionfilter of kind example:
and its type like regex, semver, or just latest. | |
| kind | string | specifies the version kind such as semver, regex, or latest | |
| pattern | string | specifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format | |
| regex | string | specifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used. | |
| replaceall | object | replaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction. | |
| pattern | string | Pattern specifies the regex pattern to match for replacement | |
| replacement | string | Replacement specifies the replacement string (supports $1, $2, etc. for captured groups) | |
| strict | boolean | strict enforce strict versioning rule. Only used for semantic versioning at this time |
Example
# updatecli.d/default.yaml
name: "Terraform autodiscovery using git scm"
scms:
default:
kind: git
spec:
url: https://github.com/updatecli-test/jenkins-infra-aws.git
branch: main
autodiscovery:
# scmid is applied to all crawlers
scmid: default
crawlers:
terraform:
# platforms to request package checksums for, defaults to:
platforms:
- linux_amd64
- linux_arm64
- darwin_amd64
- darwin_arm64
# To ignore specific path
#ignore:
# - path: <filepath relative to scm repository>
# - providers:
# # Ignoring provider updates for this provider
# registry.terraform.io/hashicorp/aws:
# # Ignore provider updates for this version
# registry.terraform.io/hashicorp/kubernetes: "1.x"
ignore:
# - path: <filepath relative to scm repository>
# - providers:
# # Ignoring provider updates for this provider
# registry.terraform.io/hashicorp/aws:
# # Ignore provider updates for this version
# registry.terraform.io/hashicorp/kubernetes: "1.x"