Terragrunt
Description
The Terragrunt crawler looks recursively for all Terragrunt files (*.hcl) containing a module definition from a specific root directory. Then for each of them, it tries to automate its update.
It currently support two types of sources:
- terraform/registry
- gittag
It will parsed the module source and infer the source type.
It will update the file using the hcl target.
It supports the following module source definition and will update with prefixing accordingly
terraform {
source = "tfr://someModule?version=1.2.3
}
terraform {
source = local.base_url
}
terraform {
source = "tfr://${local.module}?version=${local.module_version}"
}
terraform {
source = "tfr://someModule?version=${local.module_version}"
}
terraform {
source = "tfr://${local.module}?version=1.2.3"
}This crawler is enabled by default, so it can be used either automatically by running updatecli diff from a directory containing the files to update, or by providing a manifest.
The automatic discovery behavior can be tuned by providing a YAML manifest with a terragrunt crawler in top-level directive autodiscovery as explained in the "Autodiscovery" page.
Generated manifests
The source kind is inferred from the module source:
a
tfr://source resolves throughterraform/registry,a
git::source resolves throughgittag, reading tags from the remote repository.
In both cases the version is written back with the hcl target.
Authentication
Git-hosted modules are queried over the network, so private repositories need credentials. Set username and token to authenticate against the git provider.
Manifest
Parameters
| Name | Type | Description | Required |
|---|---|---|---|
| ignore | array | “ignore” defines rules to exclude matching Terraform modules from the autodiscovery. remark:
| |
| modules | object | “modules” defines the Terraform modules to match, keyed by module source as written in the Terragrunt files. remark:
example: | |
| path | string | “path” defines a Terragrunt file path pattern. remark:
| |
| only | array | “only” defines rules to restrict the autodiscovery to matching Terraform modules. remark:
| |
| modules | object | “modules” defines the Terraform modules to match, keyed by module source as written in the Terragrunt files. remark:
example: | |
| path | string | “path” defines a Terragrunt file path pattern. remark:
| |
| rootdir | string | “rootdir” defines the directory where the crawler starts searching for Terragrunt “.hcl” files. default: the scm directory when “scmid” is set, otherwise the directory relative paths resolve from, by default the working directory. remark:
| |
| token | string | “token” defines the token used for Git authentication when accessing private module repositories. default: empty, no authentication, which suits public repositories. remark:
example:
| |
| username | string | “username” defines the username used for Git authentication when accessing private module repositories. default: “oauth2”, which matches the GitHub scm plugin and is required for go-git HTTP basic authentication. remark:
example:
| |
| versionfilter | object | “versionfilter” defines the version filter used by the generated manifests. default: kind “semver” with pattern “*”, any version greater than or equal to the current one. remark:
example: | |
| kind | string | “kind” defines the versioning scheme used to select a version. default: latest remark:
example:
| |
| pattern | string | “pattern” defines the version pattern, according to “kind”. default:
remark:
example:
| |
| regex | string | “regex” defines the regular expression extracting the version from each entry. remark:
example:
| |
| replaceall | object | “replaceall” applies a regular expression replacement to each version before filtering. remark:
example: turns “curl-8_15_0” into “curl-8.15.0”. | |
| pattern | string | “pattern” defines the regular expression matching the text to replace. example:
| |
| replacement | string | “replacement” defines the text replacing each match of “pattern”. remark:
example:
| |
| strict | boolean | “strict” enforces strict semantic versioning rules when parsing versions. default: false remark:
|
Example
# updatecli.d/default.yaml
name: "Terraform autodiscovery using git scm"
scms:
default:
kind: git
spec:
url: https://github.com/updatecli-test/jenkins-infra-aws.git
branch: main
autodiscovery:
# scmid is applied to all crawlers
scmid: default
crawlers:
terraform:
# platforms to request package checksums for, defaults to:
platforms:
- linux_amd64
- linux_arm64
- darwin_amd64
- darwin_arm64
# To ignore specific path
#ignore:
# - path: <filepath relative to scm repository>
# - providers:
# # Ignoring provider updates for this provider
# registry.terraform.io/hashicorp/aws:
# # Ignore provider updates for this version
# registry.terraform.io/hashicorp/kubernetes: "1.x"
ignore:
# - path: <filepath relative to scm repository>
# - providers:
# # Ignoring provider updates for this provider
# registry.terraform.io/hashicorp/aws:
# # Ignore provider updates for this version
# registry.terraform.io/hashicorp/kubernetes: "1.x"