sourceconditiontarget

✔

✔

✗

Description

The terraform/registry resource queries a Terraform registry for the versions of a provider or a module. It is the read half of the Terraform workflow: this resource finds the version, and terraform/provider, terraform/lock or terraform/file write it into your configuration.

source

Returns the version matching versionfilter.

condition

Checks that version exists in the registry.

target

Not supported - a registry is read-only. A target fails with Target not supported for the plugin terraform/registry.

Note
An scm attached to a condition is ignored; the lookup always goes to the registry over HTTP.

Parameters

NameTypeDescriptionRequired
hostnamestring

“hostname” defines the hostname of the registry hosting the provider or module.

compatible:

  • source
  • condition

default: registry.terraform.io

remark:

  • “hostname” and “rawstring” are mutually exclusive.
  • applies to modules and providers.

example:

  • hostname: app.terraform.io
namestring

“name” defines the name of the provider or module.

compatible:

  • source
  • condition

remark:

  • required unless “rawstring” is set.
  • “name” and “rawstring” are mutually exclusive.
  • applies to modules and providers.

example:

  • name: kubernetes
namespacestring

“namespace” defines the namespace of the provider or module.

compatible:

  • source
  • condition

remark:

  • required unless “rawstring” is set.
  • “namespace” and “rawstring” are mutually exclusive.
  • applies to modules and providers.

example:

  • namespace: hashicorp
rawstringstring

“rawstring” defines the provider or module reference in the registry as a single string.

compatible:

  • source
  • condition

remark:

  • applies to modules and providers.
  • “rawstring” is mutually exclusive with “hostname”, “namespace”, “name” and “targetsystem”.

example:

  • rawstring: hashicorp/kubernetes
  • rawstring: registry.terraform.io/hashicorp/kubernetes
  • rawstring: terraform-aws-modules/vpc/aws
  • rawstring: app.terraform.io/terraform-aws-modules/vpc/aws
targetsystemstring

“targetsystem” defines the target system of the module in the registry.

compatible:

  • source
  • condition

remark:

  • required for type “module” unless “rawstring” is set.
  • “targetsystem” and “rawstring” are mutually exclusive.
  • only applies to modules.

example:

  • targetsystem: aws
typestring

“type” defines the type of registry object to look up.

compatible:

  • source
  • condition

remark:

  • “type” is required.
  • accepted values are “module” and “provider”.

example:

  • type: provider
versionstring

“version” defines the version to check.

compatible:

  • condition

default: the output of the associated source.

versionfilterobject

“versionfilter” defines the filter used to select the version, such as a regex, semver or latest pattern.

compatible:

  • source

default: kind: semver pattern: “*”

    kindstring

“kind” defines the versioning scheme used to select a version.

default: latest

remark:

  • accepted values are “latest”, “semver”, “regex”, “regex/semver”, “time”, “regex/time”, “lex” and “pep440”.
  • “latest” returns the last version of the list.
  • “lex” sorts the versions lexicographically and returns the last one.
  • “pep440” follows https://peps.python.org/pep-0440/

example:

  • kind: semver
    patternstring

“pattern” defines the version pattern, according to “kind”.

default:

  • latest: “latest”
  • semver and pep440: “*”
  • regex: “.*”
  • time and regex/time: “2006-01-02”

remark:

  • for “latest”, “latest” returns the last version, any other value must match a version exactly.
  • for “semver” and “regex/semver”, it is a semantic versioning constraint.
  • for “pep440”, it is a pep440 version specifier.
  • for “regex”, it is a regular expression.
  • for “time” and “regex/time”, it is a Go date layout.
  • ignored by “lex”.

example:

  • pattern: ~1.2
  • pattern: “>=1.0.0 <2.0.0”
  • pattern: ^v\d+.\d+.\d+$
    regexstring

“regex” defines the regular expression extracting the version from each entry.

remark:

  • only used by the kinds “regex/semver” and “regex/time”.
  • the value of the first capture group is used as the version.

example:

  • regex: ^v(\d+.\d+.\d+)$
    replaceallobject

“replaceall” applies a regular expression replacement to each version before filtering.

remark:

  • only used by the kinds “regex”, “regex/semver” and “regex/time”.
  • the replacement runs before “pattern” or “regex” is evaluated.

example:

replaceall:
  pattern: "_"
  replacement: "."

turns “curl-8_15_0” into “curl-8.15.0”.

    strictboolean

“strict” enforces strict semantic versioning rules when parsing versions.

default: false

remark:

  • only used by the kinds “semver” and “regex/semver”.

type is mandatory and must be provider or module. The address of what to look up is then given in one of two mutually exclusive styles.

Addressing by rawstring

rawstring is the whole address in one string, in the form Terraform itself uses:

spec:
  type: provider
  rawstring: hashicorp/kubernetes                          # or registry.terraform.io/hashicorp/kubernetes
spec:
  type: module
  rawstring: terraform-aws-modules/vpc/aws                 # or app.terraform.io/terraform-aws-modules/vpc/aws

rawstring cannot be combined with hostname, namespace, name or targetsystem.

Addressing by components

FieldRequiredNotes

namespace

yes

The organisation publishing it, e.g. hashicorp.

name

yes

The provider or module name, e.g. kubernetes.

targetsystem

modules only

The target system, e.g. aws. Providers must not set it.

hostname

no

Defaults to the public registry. Set it for a private one such as app.terraform.io.

A module address must resolve to three or four slash-separated components. Getting it wrong is reported by the address parser rather than by a field-level message:

failed to create resource terraform/registry: a module registry source address must have either three or four slash-separated components

Version selection

versionfilter defaults to kind: semver with pattern * when it is not set - unlike most resources, which default to the generic filter. See the "Version Filtering" page.

version is condition-only: it names the version whose existence is being checked.

Example

# updatecli.yaml
name: Terraform Registry

sources:
  kubernetes:
    name: Get version from registry
    kind: terraform/registry
    spec:
      type: provider
      namespace: hashicorp
      name: kubernetes

  terraform-aws-modules:
    name: Get version from registry
    kind: terraform/registry
    spec:
      type: module
      namespace: terraform-aws-modules
      name: vpc
      targetsystem: aws

conditions:
  provider-using-value:
    name: Condition using value
    kind: terraform/registry
    disablesourceinput: true
    spec:
      type: provider
      namespace: hashicorp
      name: kubernetes
      version: 2.22.0

  module-using-value:
    name: Condition using value
    kind: terraform/registry
    disablesourceinput: true
    spec:
      type: module
      namespace: terraform-aws-modules
      name: vpc
      targetsystem: aws
      version: 5.1.0