Description

The Terraform crawler looks recursively for every .terraform.lock.hcl file from a root directory, and updates each provider pinned in it.

Providers are read from the lock file rather than from required_providers blocks, so a module with no lock file yields nothing. Run terraform init first if that is the case.

This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest. The automatic discovery behavior can be tuned by providing a YAML manifest with a terraform crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.

Generated manifests

Automation is done by using two resources: terraform/registry as the source and terraform/lock as the target.

The version filter is narrowed per provider from the version currently locked, so a provider on 5.30.0 is filtered with >=5.30.0.

Platforms

A Terraform lock file records a checksum per target platform, and the target has to refresh all of them or terraform init will fail on the platforms left behind.

Use platforms to declare which ones to request. When unset, Updatecli falls back to linux_amd64, linux_arm64, darwin_amd64, and darwin_arm64.

Important
The checksums written back cover exactly the platforms requested. If your lock file needs a platform outside the fallback list, such as windows_amd64, list every platform you require explicitly.

Manifest

Parameters

NameTypeDescriptionRequired
ignorearrayignore specifies rule to ignore .terraform.lock.hcl update.
    pathstringpath specifies a .terraform.lock.hcl path pattern, the pattern requires to match all of name, not just a substring.
    providersobject

providers specifies a map of providers, the key is provider url as seen in the .terraform.lock.hcl, the value is an optional semver version constraint.

examples: - providers: # Ignoring provider updates for this provider registry.terraform.io/hashicorp/aws: # Ignore provider updates for this version registry.terraform.io/hashicorp/kubernetes: "1.x"

onlyarrayonly specify required rule to restrict .terraform.lock.hcl update.
    pathstringpath specifies a .terraform.lock.hcl path pattern, the pattern requires to match all of name, not just a substring.
    providersobject

providers specifies a map of providers, the key is provider url as seen in the .terraform.lock.hcl, the value is an optional semver version constraint.

examples: - providers: # Ignoring provider updates for this provider registry.terraform.io/hashicorp/aws: # Ignore provider updates for this version registry.terraform.io/hashicorp/kubernetes: "1.x"

platformsarray

platforms is the target platforms to request package checksums for.

remarks: * Fallback is linux_amd64, linux_arm64, darwin_amd64, darwin_arm64

rootdirstringrootdir defines the root directory used to recursively search for .terraform.lock.hcl
versionfilterobject

versionfilter provides parameters to specify the version pattern to use when generating manifest.

kind - semver versionfilter of kind semver uses semantic versioning as version filtering pattern accepts one of: patch - patch only update patch version minor - minor only update minor version major - major only update major versions a version constraint such as >= 1.0.0

kind - regex versionfilter of kind regex uses regular expression as version filtering pattern accepts a valid regular expression

example: versionfilter: kind: semver pattern: minor

and its type like regex, semver, or just latest.

    kindstringspecifies the version kind such as semver, regex, or latest
    patternstringspecifies the version pattern according the version kind for semver, it is a semver constraint for regex, it is a regex pattern for time, it is a date format
    regexstringspecifies the regex pattern, used for regex/semver and regex/time. Output of the first capture group will be used.
    replaceallobjectreplaceAll applies a regex replacement to version strings before filtering. This is useful for transforming versions (e.g., curl-8_15_0 to curl-8.15.0) before regex extraction.
        patternstringPattern specifies the regex pattern to match for replacement
        replacementstringReplacement specifies the replacement string (supports $1, $2, etc. for captured groups)
    strictbooleanstrict enforce strict versioning rule. Only used for semantic versioning at this time
⚠ This table is generated from the Updatecli codebase and may contain inaccurate data. Feel free to report them on github.com/updatecli/updatecli

Example

# updatecli.d/default.yaml
name: "Terraform autodiscovery using git scm"
scms:
  default:
    kind: git
    spec:
      url: https://github.com/updatecli-test/jenkins-infra-aws.git
      branch: main

autodiscovery:
  # scmid is applied to all crawlers
  scmid: default
  crawlers:
    terraform:
      # platforms to request package checksums for, defaults to:
      platforms:
        - linux_amd64
        - linux_arm64
        - darwin_amd64
        - darwin_arm64
      # To ignore specific path
      #ignore:
      #  - path: <filepath relative to scm repository>
      #  - providers:
      #      # Ignoring provider updates for this provider
      #      registry.terraform.io/hashicorp/aws:
      #      # Ignore provider updates for this version
      #      registry.terraform.io/hashicorp/kubernetes: "1.x"

      ignore:
      #  - path: <filepath relative to scm repository>
      #  - providers:
      #      # Ignoring provider updates for this provider
      #      registry.terraform.io/hashicorp/aws:
      #      # Ignore provider updates for this version
      #      registry.terraform.io/hashicorp/kubernetes: "1.x"