sourceconditiontarget

✗

✔

✔

Description

The terraform/provider resource updates the version of one provider inside a required_providers block, so you name the provider rather than working out its attribute path:

terraform {
  required_providers {
    kubernetes = {
      source  = "hashicorp/kubernetes"
      version = "2.23.0"
    }
  }
}
condition

Tests that the block records the expected version for the provider.

target

Updates that version.

source

Not supported - a source fails with Source not supported for the plugin terraform/provider. Get the version from terraform/registry.

Parameters

NameTypeDescriptionRequired
filestring

“file” defines the path of the Terraform file to use.

compatible:

  • condition
  • target

remark:

  • “file” and “files” are mutually exclusive.
  • the schemes “https://”, “http://” and “file://” are supported in a condition.
filesarray

“files” defines the list of Terraform file paths to use.

compatible:

  • condition
  • target

remark:

  • “file” and “files” are mutually exclusive.
  • a condition only supports one file.
  • the schemes “https://”, “http://” and “file://” are supported in a condition.
providerstring

“provider” defines the name of the Terraform provider to update, as declared in the “required_providers” block.

compatible:

  • condition
  • target

remark:

  • “provider” is required.

example:

  • provider: kubernetes
valuestring

“value” defines the version of the Terraform provider.

compatible:

  • condition
  • target

default: in a condition or a target, the output of the associated source.

file or files and provider are mandatory; missing either aborts the run with wrong spec content, preceded by terraform/provider file undefined or terraform/provider provider undefined. file and files are mutually exclusive, and a condition accepts only one file.

provider

The key inside required_providers - kubernetes in the example above, not hashicorp/kubernetes. Unlike terraform/lock, this resource matches on the block key rather than the registry address.

value

Defaults to the source output.

Tip
Updating a provider usually means touching two files. Pair this resource with a terraform/lock target in the same pipeline so required_providers and .terraform.lock.hcl stay consistent.

For any attribute that is not a provider version, use terraform/file, which addresses attributes by path.

Remote files

For a condition, file accepts https://, http:// and file://. A target must write locally and refuses a URL.

Example

The example uses an additional resource plugin: terraform/registry.

# updatecli.yaml
name: Terraform Provider

sources:
  kubernetes:
    name: Get version from registry
    kind: terraform/registry
    spec:
      type: provider
      namespace: hashicorp
      name: kubernetes

conditions:
  using-value:
    name: Condition using value
    kind: terraform/provider
    disablesourceinput: true
    spec:
      file: versions.tf
      provider: kubernetes
      value: 2.22.0

targets:
  update-file-from-source:
    name: Update files content from value
    kind: terraform/provider
    sourceid: kubernetes
    spec:
      file: versions.tf
      provider: kubernetes