2018-12-11 20:21:49 +01:00
# Collection of git hooks for Terraform to be used with [pre-commit framework](http://pre-commit.com/)
2016-09-27 19:47:26 +02:00
2021-09-09 12:38:43 +03:00
[](https://github.com/antonbabenko/pre-commit-terraform/releases)  [](https://www.codetriage.com/antonbabenko/pre-commit-terraform)
2021-10-26 14:39:23 +02:00
Want to contribute? Check [open issues ](https://github.com/antonbabenko/pre-commit-terraform/issues?q=label%3A%22good+first+issue%22+is%3Aopen+sort%3Aupdated-desc ) and [contributing notes ](/.github/CONTRIBUTING.md ).
2021-10-01 19:31:14 +03:00
2021-10-26 17:40:24 +02:00
## Sponsors
2021-12-08 21:03:04 +02:00
<!-- markdownlint-disable no-inline-html -->
2021-10-26 17:40:24 +02:00
<br />
<a href="https://www.env0.com/?utm_campaign=pre-commit-terraform&utm_source=sponsorship&utm_medium=social"><img src="https://raw.githubusercontent.com/antonbabenko/pre-commit-terraform/master/assets/env0.png" alt="env0" width="180" height="44" />
Automated provisioning of Terraform workflows and Infrastructure as Code.</a>
<br />
<a href="https://www.infracost.io/?utm_campaign=pre-commit-terraform&utm_source=sponsorship&utm_medium=social"><img src="https://raw.githubusercontent.com/antonbabenko/pre-commit-terraform/master/assets/infracost.png" alt="infracost" width="200" height="38" />
2021-12-08 21:03:04 +02:00
<!-- markdownlint-enable no-inline-html -->
2021-10-26 17:40:24 +02:00
Cloud cost estimates for Terraform.</a>
If you are using `pre-commit-terraform` already or want to support its development and [many other open-source projects ](https://github.com/antonbabenko/terraform-aws-devops ), please become a [GitHub Sponsor ](https://github.com/sponsors/antonbabenko )!
2021-12-08 21:03:04 +02:00
2021-10-26 17:40:24 +02:00
## Table of content
2021-11-08 22:28:02 +02:00
* [Sponsors ](#sponsors )
* [Table of content ](#table-of-content )
2021-09-09 12:38:43 +03:00
* [How to install ](#how-to-install )
* [1. Install dependencies ](#1-install-dependencies )
* [2. Install the pre-commit hook globally ](#2-install-the-pre-commit-hook-globally )
* [3. Add configs and hooks ](#3-add-configs-and-hooks )
* [4. Run ](#4-run )
* [Available Hooks ](#available-hooks )
2021-09-29 14:36:55 +03:00
* [Hooks usage notes and examples ](#hooks-usage-notes-and-examples )
* [checkov ](#checkov )
2021-10-26 14:12:01 +03:00
* [infracost_breakdown ](#infracost_breakdown )
2021-09-09 12:38:43 +03:00
* [terraform_docs ](#terraform_docs )
2021-11-08 22:28:02 +02:00
* [terraform_docs_replace (deprecated) ](#terraform_docs_replace-deprecated )
2021-10-14 16:25:45 +03:00
* [terraform_fmt ](#terraform_fmt )
2021-10-04 12:16:15 +01:00
* [terraform_providers_lock ](#terraform_providers_lock )
2021-09-09 12:38:43 +03:00
* [terraform_tflint ](#terraform_tflint )
* [terraform_tfsec ](#terraform_tfsec )
* [terraform_validate ](#terraform_validate )
* [Authors ](#authors )
* [License ](#license )
2018-01-03 22:26:39 -06:00
2018-12-11 20:21:49 +01:00
## How to install
2018-01-24 15:46:37 +01:00
2019-10-17 14:50:16 +03:00
### 1. Install dependencies
2016-09-27 19:47:26 +02:00
2021-09-09 22:29:33 +03:00
<!-- markdownlint-disable no-inline-html -->
2021-10-26 14:39:23 +02:00
* [`pre-commit` ](https://pre-commit.com/#install )
2020-09-08 15:10:56 +02:00
* [`checkov` ](https://github.com/bridgecrewio/checkov ) required for `checkov` hook.
2021-10-26 14:39:23 +02:00
* [`terraform-docs` ](https://github.com/terraform-docs/terraform-docs ) required for `terraform_docs` hook.
2021-09-11 10:47:56 +03:00
* [`terragrunt` ](https://terragrunt.gruntwork.io/docs/getting-started/install/ ) required for `terragrunt_validate` hook.
2021-04-22 16:15:00 -04:00
* [`terrascan` ](https://github.com/accurics/terrascan ) required for `terrascan` hook.
2021-09-09 22:29:33 +03:00
* [`TFLint` ](https://github.com/terraform-linters/tflint ) required for `terraform_tflint` hook.
* [`TFSec` ](https://github.com/liamg/tfsec ) required for `terraform_tfsec` hook.
2021-10-26 14:12:01 +03:00
* [`infracost` ](https://github.com/infracost/infracost ) required for `infracost_breakdown` hook.
* [`jq` ](https://github.com/stedolan/jq ) required for `infracost_breakdown` hook.
2021-09-09 22:29:33 +03:00
<details><summary><b>Docker</b></summary><br>
2021-12-08 21:03:04 +02:00
**Pull docker image with all hooks**:
```bash
TAG=latest
docker pull ghcr.io/antonbabenko/pre-commit-terraform:$TAG
```
All available tags [here ](https://github.com/antonbabenko/pre-commit-terraform/pkgs/container/pre-commit-terraform/versions ).
**Build from scratch**:
When `--build-arg` is not specified, the latest version of `pre-commit` and `terraform` will be only installed.
2021-09-09 22:29:33 +03:00
```bash
git clone git@github .com:antonbabenko/pre-commit-terraform.git
cd pre-commit-terraform
2021-10-26 14:39:23 +02:00
# Install the latest versions of all the tools
2021-12-08 21:03:04 +02:00
docker build -t pre-commit-terraform --build-arg INSTALL_ALL=true .
2021-09-09 22:29:33 +03:00
```
2021-10-26 14:39:23 +02:00
To install a specific version of individual tools, define it using `--build-arg` arguments or set it to `latest` :
2021-09-09 22:29:33 +03:00
```bash
2021-12-08 21:03:04 +02:00
docker build -t pre-commit-terraform \
2021-09-09 22:29:33 +03:00
--build-arg PRE_COMMIT_VERSION=latest \
--build-arg TERRAFORM_VERSION=latest \
--build-arg CHECKOV_VERSION=2.0.405 \
2021-10-26 14:12:01 +03:00
--build-arg INFRACOST_VERSION=latest \
2021-09-09 22:29:33 +03:00
--build-arg TERRAFORM_DOCS_VERSION=0.15.0 \
--build-arg TERRAGRUNT_VERSION=latest \
--build-arg TERRASCAN_VERSION=1.10.0 \
--build-arg TFLINT_VERSION=0.31.0 \
--build-arg TFSEC_VERSION=latest \
.
```
2019-10-17 14:50:16 +03:00
2021-10-26 14:39:23 +02:00
Set `-e PRE_COMMIT_COLOR=never` to disable the color output in `pre-commit` .
2021-03-12 15:35:21 +01:00
2021-09-09 22:29:33 +03:00
</details>
<details><summary><b>MacOS</b></summary><br>
2021-10-26 14:39:23 +02:00
[`coreutils` ](https://formulae.brew.sh/formula/coreutils ) is required for `terraform_validate` hook on MacOS (due to use of `realpath` ).
2019-10-17 14:50:16 +03:00
```bash
2021-10-26 14:12:01 +03:00
brew install pre-commit terraform-docs tflint tfsec coreutils checkov terrascan infracost jq
2019-10-17 14:50:16 +03:00
```
2021-09-09 22:29:33 +03:00
</details>
<details><summary><b>Ubuntu 18.04</b></summary><br>
2018-12-11 20:21:49 +01:00
```bash
2021-03-12 10:32:41 +01:00
sudo apt update
2021-09-10 22:33:03 +03:00
sudo apt install -y unzip software-properties-common
2021-03-12 10:32:41 +01:00
sudo add-apt-repository ppa:deadsnakes/ppa
sudo apt install -y python3.7 python3-pip
2021-09-09 12:38:43 +03:00
python3 -m pip install --upgrade pip
2021-09-09 22:29:33 +03:00
pip3 install --no-cache-dir pre-commit
python3.7 -m pip install -U checkov
2021-09-10 22:33:03 +03:00
curl -L "$(curl -s https://api.github.com/repos/terraform-docs/terraform-docs/releases/latest | grep -o -E -m 1 "https://.+?-linux-amd64.tar.gz")" > terraform-docs.tgz && tar -xzf terraform-docs.tgz && rm terraform-docs.tgz && chmod +x terraform-docs && sudo mv terraform-docs /usr/bin/
curl -L "$(curl -s https://api.github.com/repos/terraform-linters/tflint/releases/latest | grep -o -E -m 1 "https://.+?_linux_amd64.zip")" > tflint.zip && unzip tflint.zip && rm tflint.zip && sudo mv tflint /usr/bin/
curl -L "$(curl -s https://api.github.com/repos/aquasecurity/tfsec/releases/latest | grep -o -E -m 1 "https://.+?tfsec-linux-amd64")" > tfsec && chmod +x tfsec && sudo mv tfsec /usr/bin/
2021-10-19 03:29:27 -07:00
curl -L "$(curl -s https://api.github.com/repos/accurics/terrascan/releases/latest | grep -o -E -m 1 "https://.+?_Linux_x86_64.tar.gz")" > terrascan.tar.gz && tar -xzf terrascan.tar.gz terrascan && rm terrascan.tar.gz && sudo mv terrascan /usr/bin/ && terrascan init
2021-10-26 14:12:01 +03:00
sudo apt install -y jq && \
curl -L "$(curl -s https://api.github.com/repos/infracost/infracost/releases/latest | grep -o -E -m 1 "https://.+?-linux-amd64.tar.gz")" > infracost.tgz && tar -xzf infracost.tgz && rm infracost.tgz && sudo mv infracost-linux-amd64 /usr/bin/infracost && infracost register
2018-12-11 20:21:49 +01:00
```
2018-05-16 20:04:48 +02:00
2021-09-09 22:29:33 +03:00
</details>
<details><summary><b>Ubuntu 20.04</b></summary><br>
2021-09-09 12:38:43 +03:00
```bash
sudo apt update
2021-09-10 22:33:03 +03:00
sudo apt install -y unzip software-properties-common python3 python3-pip
2021-09-09 12:38:43 +03:00
python3 -m pip install --upgrade pip
2021-09-09 22:29:33 +03:00
pip3 install --no-cache-dir pre-commit
pip3 install --no-cache-dir checkov
2021-09-10 22:33:03 +03:00
curl -L "$(curl -s https://api.github.com/repos/terraform-docs/terraform-docs/releases/latest | grep -o -E -m 1 "https://.+?-linux-amd64.tar.gz")" > terraform-docs.tgz && tar -xzf terraform-docs.tgz terraform-docs && rm terraform-docs.tgz && chmod +x terraform-docs && sudo mv terraform-docs /usr/bin/
2021-10-19 03:29:27 -07:00
curl -L "$(curl -s https://api.github.com/repos/accurics/terrascan/releases/latest | grep -o -E -m 1 "https://.+?_Linux_x86_64.tar.gz")" > terrascan.tar.gz && tar -xzf terrascan.tar.gz terrascan && rm terrascan.tar.gz && sudo mv terrascan /usr/bin/ && terrascan init
2021-09-10 22:33:03 +03:00
curl -L "$(curl -s https://api.github.com/repos/terraform-linters/tflint/releases/latest | grep -o -E -m 1 "https://.+?_linux_amd64.zip")" > tflint.zip && unzip tflint.zip && rm tflint.zip && sudo mv tflint /usr/bin/
curl -L "$(curl -s https://api.github.com/repos/aquasecurity/tfsec/releases/latest | grep -o -E -m 1 "https://.+?tfsec-linux-amd64")" > tfsec && chmod +x tfsec && sudo mv tfsec /usr/bin/
2021-10-26 14:12:01 +03:00
sudo apt install -y jq && \
curl -L "$(curl -s https://api.github.com/repos/infracost/infracost/releases/latest | grep -o -E -m 1 "https://.+?-linux-amd64.tar.gz")" > infracost.tgz && tar -xzf infracost.tgz && rm infracost.tgz && sudo mv infracost-linux-amd64 /usr/bin/infracost && infracost register
2021-09-09 12:38:43 +03:00
```
2021-09-09 22:29:33 +03:00
</details>
<!-- markdownlint-enable no-inline-html -->
2021-09-09 12:38:43 +03:00
2019-10-17 14:50:16 +03:00
### 2. Install the pre-commit hook globally
2021-09-09 12:38:43 +03:00
2021-09-09 22:29:33 +03:00
> Note: not needed if you use the Docker image
2019-10-17 14:50:16 +03:00
```bash
DIR=~/.git-template
git config --global init.templateDir ${DIR}
pre-commit init-templatedir -t pre-commit ${DIR}
```
2018-05-16 20:04:48 +02:00
2019-10-17 14:50:16 +03:00
### 3. Add configs and hooks
2018-05-16 20:04:48 +02:00
2018-12-11 20:21:49 +01:00
Step into the repository you want to have the pre-commit hooks installed and run:
2016-09-27 19:47:26 +02:00
2018-12-11 20:21:49 +01:00
```bash
2019-10-17 14:50:16 +03:00
git init
2018-12-11 20:21:49 +01:00
cat <<EOF > .pre-commit-config.yaml
2020-04-29 15:06:02 -05:00
repos:
2021-10-25 21:10:36 +03:00
- repo: https://github.com/antonbabenko/pre-commit-terraform
2020-01-21 05:19:46 -05:00
rev: <VERSION> # Get the latest from: https://github.com/antonbabenko/pre-commit-terraform/releases
2018-01-15 16:12:51 +01:00
hooks:
- id: terraform_fmt
2019-06-17 12:47:06 +02:00
- id: terraform_docs
2018-12-11 20:21:49 +01:00
EOF
```
2019-10-17 14:50:16 +03:00
### 4. Run
2018-12-11 20:21:49 +01:00
2021-10-26 14:39:23 +02:00
Execute this command to run `pre-commit` on all files in the repository (not only changed files):
2018-12-11 20:21:49 +01:00
```bash
pre-commit run -a
2016-09-27 19:47:26 +02:00
```
2021-12-08 21:03:04 +02:00
Or, using Docker ([available tags ](https://github.com/antonbabenko/pre-commit-terraform/pkgs/container/pre-commit-terraform/versions )):
2021-09-09 12:38:43 +03:00
2021-03-12 15:35:21 +01:00
```bash
2021-12-08 21:03:04 +02:00
TAG=latest
docker run -v $(pwd):/lint -w /lint ghcr.io/antonbabenko/pre-commit-terraform:$TAG run -a
2021-03-12 15:35:21 +01:00
```
2021-10-26 14:39:23 +02:00
Execute this command to list the versions of the tools in Docker:
2021-12-08 21:03:04 +02:00
2021-10-26 14:39:23 +02:00
```bash
2021-12-08 21:03:04 +02:00
TAG=latest
docker run --entrypoint cat ghcr.io/antonbabenko/pre-commit-terraform:$TAG /usr/bin/tools_versions_info
2021-10-26 14:39:23 +02:00
```
2021-09-11 10:47:56 +03:00
2018-12-11 20:21:49 +01:00
## Available Hooks
2020-01-21 05:19:46 -05:00
There are several [pre-commit ](https://pre-commit.com/ ) hooks to keep Terraform configurations (both `*.tf` and `*.tfvars` ) and Terragrunt configurations (`*.hcl` ) in a good shape:
2019-10-17 14:50:16 +03:00
2021-10-15 15:08:26 +03:00
<!-- markdownlint-disable no-inline-html -->
2021-11-08 22:28:02 +02:00
| Hook name | Description | Dependencies<br><sup>[Install instructions here ](#1-install-dependencies )</sup> |
| ------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
| `checkov` | [checkov ](https://github.com/bridgecrewio/checkov ) static analysis of terraform templates to spot potential security issues. [Hook notes ](#checkov ) | `checkov` <br>Ubuntu deps: `python3` , `python3-pip` |
| `infracost_breakdown` | Check how much your infra costs with [infracost ](https://github.com/infracost/infracost ). [Hook notes ](#infracost_breakdown ) | `infracost` , `jq` , [Infracost API key ](https://www.infracost.io/docs/#2-get-api-key ) |
| `terraform_docs_replace` | Runs `terraform-docs` and pipes the output directly to README.md. **DEPRECATED ** , see [#248 ](https://github.com/antonbabenko/pre-commit-terraform/issues/248 ). [Hook notes ](#terraform_docs_replace-deprecated ) | `python3` , `terraform-docs` |
| `terraform_docs_without_` <br>`aggregate_type_defaults` | Inserts input and output documentation into `README.md` without aggregate type defaults. Hook notes same as for [terraform_docs ](#terraform_docs ) | `terraform-docs` |
| `terraform_docs` | Inserts input and output documentation into `README.md` . Recommended. [Hook notes ](#terraform_docs ) | `terraform-docs` |
| `terraform_fmt` | Reformat all Terraform configuration files to a canonical format. [Hook notes ](#terraform_fmt ) | - |
| `terraform_providers_lock` | Updates provider signatures in [dependency lock files ](https://www.terraform.io/docs/cli/commands/providers/lock.html ). [Hook notes ](#terraform_providers_lock ) | - |
| `terraform_tflint` | Validates all Terraform configuration files with [TFLint ](https://github.com/terraform-linters/tflint ). [Available TFLint rules ](https://github.com/terraform-linters/tflint/tree/master/docs/rules#rules ). [Hook notes ](#terraform_tflint ). | `tflint` |
| `terraform_tfsec` | [TFSec ](https://github.com/aquasecurity/tfsec ) static analysis of terraform templates to spot potential security issues. [Hook notes ](#terraform_tfsec ) | `tfsec` |
| `terraform_validate` | Validates all Terraform configuration files. [Hook notes ](#terraform_validate ) | - |
| `terragrunt_fmt` | Reformat all [Terragrunt ](https://github.com/gruntwork-io/terragrunt ) configuration files (`*.hcl` ) to a canonical format. | `terragrunt` |
| `terragrunt_validate` | Validates all [Terragrunt ](https://github.com/gruntwork-io/terragrunt ) configuration files (`*.hcl` ) | `terragrunt` |
| `terrascan` | [terrascan ](https://github.com/accurics/terrascan ) Detect compliance and security violations. | `terrascan` |
2021-10-15 15:08:26 +03:00
<!-- markdownlint-enable no-inline-html -->
2018-12-11 20:21:49 +01:00
Check the [source file ](https://github.com/antonbabenko/pre-commit-terraform/blob/master/.pre-commit-hooks.yaml ) to know arguments used for each hook.
2021-09-29 14:36:55 +03:00
## Hooks usage notes and examples
### checkov
For [checkov ](https://github.com/bridgecrewio/checkov ) you need to specify each argument separately:
```yaml
- id: checkov
args: [
"-d", ".",
"--skip-check", "CKV2_AWS_8",
]
```
2021-09-09 12:38:43 +03:00
2021-10-26 14:12:01 +03:00
### infracost_breakdown
2021-10-26 14:39:23 +02:00
`infracost_breakdown` executes `infracost breakdown` command and compare the estimated costs with those specified in the hook-config. `infracost breakdown` normally runs `terraform init` , `terraform plan` , and calls Infracost Cloud Pricing API (remote version or [self-hosted version ](https://www.infracost.io/docs/cloud_pricing_api/self_hosted )).
2021-10-26 14:12:01 +03:00
2021-10-26 14:39:23 +02:00
Unlike most other hooks, this hook triggers once if there are any changed files in the repository.
2021-10-26 14:12:01 +03:00
2021-10-26 14:39:23 +02:00
1. `infracost_breakdown` supports [all `infracost breakdown` arguments ](https://www.infracost.io/docs/#useful-options ). The following example only shows costs:
2021-10-26 14:12:01 +03:00
```yaml
- id: infracost_breakdown
args:
- --args=--path=./env/dev
verbose: true # Always show costs
```
<!-- markdownlint-disable-next-line no-inline-html -->
<details><summary>Output</summary>
```bash
Running in "env/dev"
Summary: {
"unsupportedResourceCounts": {
"aws_sns_topic_subscription": 1
}
}
Total Monthly Cost: 86.83 USD
Total Monthly Cost (diff): 86.83 USD
```
<!-- markdownlint-disable-next-line no-inline-html -->
</details>
2021-10-26 14:39:23 +02:00
2. (Optionally) Define `cost constrains` the hook should evaluate successfully in order to pass:
2021-10-26 14:12:01 +03:00
```yaml
- id: infracost_breakdown
args:
- --args=--path=./env/dev
2021-10-27 14:45:25 +03:00
- --hook-config='.totalHourlyCost|tonumber > 0.1'
- --hook-config='.totalHourlyCost|tonumber > 1'
- --hook-config='.projects[].diff.totalMonthlyCost|tonumber != 10000'
- --hook-config='.currency == "USD"'
2021-10-26 14:12:01 +03:00
```
<!-- markdownlint-disable-next-line no-inline-html -->
<details><summary>Output</summary>
```bash
Running in "env/dev"
Passed: .totalHourlyCost|tonumber > 0.1 0.11894520547945205 > 0.1
Failed: .totalHourlyCost|tonumber > 1 0.11894520547945205 > 1
Passed: .projects[].diff.totalMonthlyCost|tonumber !=10000 86.83 != 10000
Passed: .currency == "USD" "USD" == "USD"
Summary: {
"unsupportedResourceCounts": {
2021-10-26 14:39:23 +02:00
"aws_sns_topic_subscription": 1
2021-10-26 14:12:01 +03:00
}
}
Total Monthly Cost: 86.83 USD
Total Monthly Cost (diff): 86.83 USD
```
<!-- markdownlint-disable-next-line no-inline-html -->
</details>
2021-10-26 14:39:23 +02:00
* Only one path per one hook (`- id: infracost_breakdown` ) is allowed.
* Set `verbose: true` to see cost even when the checks are passed.
* Hook uses `jq` to process the cost estimation report returned by `infracost breakdown` command
* Expressions defined as `--hook-config` argument should be in a jq-compatible format (e.g. `.totalHourlyCost` , `.totalMonthlyCost` )
To study json output produced by `infracost` , run the command `infracost breakdown -p PATH_TO_TF_DIR --format json` , and explore it on [jqplay.org ](https://jqplay.org/ ).
2021-10-26 14:12:01 +03:00
* Supported comparison operators: `<` , `<=` , `==` , `!=` , `>=` , `>` .
* Most useful paths and checks:
2021-10-26 14:39:23 +02:00
* `.totalHourlyCost` (same as `.projects[].breakdown.totalHourlyCost` ) - show total hourly infra cost
* `.totalMonthlyCost` (same as `.projects[].breakdown.totalMonthlyCost` ) - show total monthly infra cost
* `.projects[].diff.totalHourlyCost` - show the difference in hourly cost for the existing infra and tf plan
* `.projects[].diff.totalMonthlyCost` - show the difference in monthly cost for the existing infra and tf plan
* `.diffTotalHourlyCost` (for Infracost version 0.9.12 or newer) or `[.projects[].diff.totalMonthlyCost | select (.!=null) | tonumber] | add` (for Infracost older than 0.9.12)
* To disable hook color output, set `PRE_COMMIT_COLOR=never` env var.
2021-10-26 14:12:01 +03:00
3. **Docker usage ** . In `docker build` or `docker run` command:
2021-10-26 14:39:23 +02:00
* You need to provide [Infracost API key ](https://www.infracost.io/docs/integrations/environment_variables/#infracost_api_key ) via `-e INFRACOST_API_KEY=<your token>` . By default, it is saved in `~/.config/infracost/credentials.yml`
* Set `-e INFRACOST_SKIP_UPDATE_CHECK=true` to [skip the Infracost update check ](https://www.infracost.io/docs/integrations/environment_variables/#infracost_skip_update_check ) if you use this hook as part of your CI/CD pipeline.
2021-10-26 14:12:01 +03:00
2021-09-09 12:38:43 +03:00
### terraform_docs
2018-12-11 20:21:49 +01:00
2020-08-19 06:06:55 -04:00
1. `terraform_docs` and `terraform_docs_without_aggregate_type_defaults` will insert/update documentation generated by [terraform-docs ](https://github.com/terraform-docs/terraform-docs ) framed by markers:
2019-10-17 14:50:16 +03:00
2021-09-09 12:38:43 +03:00
```txt
<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
```
if they are present in `README.md` .
2018-12-11 20:21:49 +01:00
2021-10-26 14:39:23 +02:00
2. It is possible to pass additional arguments to shell scripts when using `terraform_docs` and `terraform_docs_without_aggregate_type_defaults` .
2021-09-09 12:38:43 +03:00
2021-10-15 15:26:23 +03:00
3. It is possible to automatically:
2021-12-08 21:03:04 +02:00
* create a documentation file
2021-10-26 14:39:23 +02:00
* extend existing documentation file by appending markers to the end of the file (see item 1 above)
* use different filename for the documentation (default is `README.md` )
2018-12-13 22:16:01 -05:00
2021-10-15 15:26:23 +03:00
```yaml
- id: terraform_docs
args:
- --hook-config=--path-to-file=README.md # Valid UNIX path. I.e. ../TFDOC.md or docs/README.md etc.
2021-11-17 19:16:38 +01:00
- --hook-config=--add-to-existing-file=true # Boolean. true or false
2021-10-15 15:26:23 +03:00
- --hook-config=--create-file-if-not-exist=true # Boolean. true or false
```
2021-12-08 21:03:04 +02:00
4. You can provide [any configuration available in `terraform-docs` ](https://terraform-docs.io/user-guide/configuration/ ) as an argument to `terraform_doc` hook, for example:
2021-10-15 15:26:23 +03:00
```yaml
- id: terraform_docs
args:
- --args=--config=.terraform-docs.yml
2021-10-26 14:12:01 +03:00
5. If you need some exotic settings, it can be done too. I.e. this one generates HCL files:
2021-10-15 15:26:23 +03:00
```yaml
- id: terraform_docs
2021-10-26 14:39:23 +02:00
args:
2021-10-15 15:26:23 +03:00
- tfvars hcl --output-file terraform.tfvars.model .
```
2021-09-29 14:36:55 +03:00
2021-11-08 22:28:02 +02:00
### terraform_docs_replace (deprecated)
**DEPRECATED**. Will be merged in [`terraform_docs` ](#terraform_docs ). See [#248 ](https://github.com/antonbabenko/pre-commit-terraform/issues/248 ) for details.
2018-12-13 22:16:01 -05:00
2021-10-15 15:08:26 +03:00
`terraform_docs_replace` replaces the entire README.md rather than doing string replacement between markers. Put your additional documentation at the top of your `main.tf` for it to be pulled in. The optional `--dest` argument lets you change the filename that gets created/modified.
2021-09-29 14:36:55 +03:00
Example:
```yaml
- id: terraform_docs_replace
args:
- --sort-by-required
- --dest=TEST.md
```
2018-12-11 20:21:49 +01:00
2021-10-14 16:25:45 +03:00
### terraform_fmt
1. `terraform_fmt` supports custom arguments so you can pass [supported flags ](https://www.terraform.io/docs/cli/commands/fmt.html#usage ). Eg:
```yaml
- id: terraform_fmt
args:
- --args=-no-color
- --args=-diff
- --args=-write=false
```
### terraform_providers_lock
1. The hook requires Terraform 0.14 or later.
2. The hook invokes two operations that can be really slow:
* `terraform init` (in case `.terraform` directory is not initialised)
2021-10-26 14:39:23 +02:00
* `terraform providers lock`
2021-10-14 16:25:45 +03:00
Both operations require downloading data from remote Terraform registries, and not all of that downloaded data or meta-data is currently being cached by Terraform.
3. `terraform_providers_lock` supports custom arguments:
```yaml
- id: terraform_providers_lock
args:
2021-10-27 14:45:25 +03:00
- --args=-platform=windows_amd64
- --args=-platform=darwin_amd64
2021-10-14 16:25:45 +03:00
```
2021-10-15 15:08:26 +03:00
4. It may happen that Terraform working directory (`.terraform` ) already exists but not in the best condition (eg, not initialized modules, wrong version of Terraform, etc.). To solve this problem, you can find and delete all `.terraform` directories in your repository:
2021-10-14 16:25:45 +03:00
```bash
echo "
function rm_terraform {
find . -name ".terraform*" -print0 | xargs -0 rm -r
}
" >>~/.bashrc
2021-10-15 15:08:26 +03:00
# Reload shell and use `rm_terraform` command in the repo root
2021-10-14 16:25:45 +03:00
```
2021-10-26 14:39:23 +02:00
`terraform_providers_lock` hook will try to reinitialize directories before running the `terraform providers lock` command.
2021-10-14 16:25:45 +03:00
2021-09-09 12:38:43 +03:00
### terraform_tflint
2019-11-16 18:37:23 +00:00
2021-10-15 15:08:26 +03:00
1. `terraform_tflint` supports custom arguments so you can enable module inspection, deep check mode, etc.
2019-11-16 18:37:23 +00:00
2021-09-09 12:38:43 +03:00
Example:
2019-11-16 18:37:23 +00:00
```yaml
2021-09-29 14:36:55 +03:00
- id: terraform_tflint
args:
- --args=--deep
- --args=--enable-rule=terraform_documented_variables
2019-11-16 18:37:23 +00:00
```
2021-10-26 14:12:01 +03:00
2. When you have multiple directories and want to run `tflint` in all of them and share a single config file, it is impractical to hard-code the path to the `.tflint.hcl` file. The solution is to use the `__GIT_WORKING_DIR__` placeholder which will be replaced by `terraform_tflint` hooks with Git working directory (repo root) at run time. For example:
2020-09-22 14:20:27 +02:00
2021-09-09 12:38:43 +03:00
```yaml
2021-09-29 14:36:55 +03:00
- id: terraform_tflint
args:
- --args=--config=__GIT_WORKING_DIR__/.tflint.hcl
2021-09-09 12:38:43 +03:00
```
2020-09-22 14:20:27 +02:00
2021-09-09 12:38:43 +03:00
### terraform_tfsec
2020-04-23 09:56:33 -05:00
2020-09-01 01:07:08 -07:00
1. `terraform_tfsec` will consume modified files that pre-commit
passes to it, so you can perform whitelisting of directories
or files to run against via [files ](https://pre-commit.com/#config-files )
pre-commit flag
2021-09-09 12:38:43 +03:00
Example:
2020-09-01 01:07:08 -07:00
```yaml
2021-09-29 14:36:55 +03:00
- id: terraform_tfsec
files: ^prd-infra/
2020-09-01 01:07:08 -07:00
```
The above will tell pre-commit to pass down files from the `prd-infra/` folder
only such that the underlying `tfsec` tool can run against changed files in this
directory, ignoring any other folders at the root level
2021-09-09 12:38:43 +03:00
2. To ignore specific warnings, follow the convention from the
2021-10-26 14:39:23 +02:00
[documentation ](https://github.com/aquasecurity/tfsec#ignoring-warnings ).
2021-09-09 12:38:43 +03:00
Example:
2020-04-23 09:56:33 -05:00
```hcl
resource "aws_security_group_rule" "my-rule" {
type = "ingress"
cidr_blocks = ["0.0.0.0/0"] #tfsec:ignore:AWS006
}
```
2021-10-26 14:39:23 +02:00
3. `terraform_tfsec` supports custom arguments, so you can pass supported `--no-color` or `--format` (output), `-e` (exclude checks) flags:
2021-10-01 21:52:35 +03:00
```yaml
- id: terraform_tfsec
args:
- >
--args=--format json
--no-color
-e aws-s3-enable-bucket-logging,aws-s3-specify-public-access-block
```
2021-10-26 15:35:55 +03:00
4. When you have multiple directories and want to run `tfsec` in all of them and share a single config file - use the `__GIT_WORKING_DIR__` placeholder. It will be replaced by `terraform_tfsec` hooks with Git working directory (repo root) at run time. For example:
```yaml
- id: terraform_tfsec
args:
- --args=--config-file=__GIT_WORKING_DIR__/.tfsec.json
```
Otherwise, will be used files that located in sub-folders:
2021-10-21 15:13:34 +01:00
```yaml
- id: terraform_tfsec
2021-10-26 15:35:55 +03:00
args:
- --args=--config-file=.tfsec.json
2021-10-21 15:13:34 +01:00
```
2021-10-01 21:52:35 +03:00
2021-09-09 12:38:43 +03:00
### terraform_validate
2020-08-27 10:57:45 +01:00
2021-10-01 21:52:35 +03:00
1. `terraform_validate` supports custom arguments so you can pass supported `-no-color` or `-json` flags:
2021-09-09 12:38:43 +03:00
2020-08-27 10:57:45 +01:00
```yaml
- id: terraform_validate
args:
2021-09-29 14:36:55 +03:00
- --args=-json
- --args=-no-color
2020-08-27 10:57:45 +01:00
```
2021-09-29 14:36:55 +03:00
2. `terraform_validate` also supports custom environment variables passed to the pre-commit runtime:
2021-09-09 12:38:43 +03:00
2020-08-27 10:57:45 +01:00
```yaml
2021-09-29 14:36:55 +03:00
- id: terraform_validate
args:
- --envs=AWS_DEFAULT_REGION="us-west-2"
- --envs=AWS_ACCESS_KEY_ID="anaccesskey"
- --envs=AWS_SECRET_ACCESS_KEY="asecretkey"
2020-08-27 10:57:45 +01:00
```
2021-12-11 05:33:22 -08:00
3. `terraform_validate` also supports passing custom arguments to its `terraform init` :
```yaml
- id: terraform_validate
args:
- --init-args=-lockfile=readonly
```
4. It may happen that Terraform working directory (`.terraform` ) already exists but not in the best condition (eg, not initialized modules, wrong version of Terraform, etc.). To solve this problem, you can find and delete all `.terraform` directories in your repository:
2021-09-09 12:38:43 +03:00
2021-09-29 14:36:55 +03:00
```bash
echo "
function rm_terraform {
find . -name ".terraform*" -print0 | xargs -0 rm -r
}
" >>~/.bashrc
2020-11-02 21:44:54 +01:00
2021-10-15 15:08:26 +03:00
# Reload shell and use `rm_terraform` command in the repo root
2020-11-02 21:44:54 +01:00
```
2021-10-15 15:08:26 +03:00
`terraform_validate` hook will try to reinitialize them before running the `terraform validate` command.
2020-11-02 21:44:54 +01:00
2021-10-26 14:39:23 +02:00
**Warning: ** If you use Terraform workspaces, DO NOT use this workaround ([details ](https://github.com/antonbabenko/pre-commit-terraform/issues/203#issuecomment-918791847 )). Wait to [`force-init` ](https://github.com/antonbabenko/pre-commit-terraform/issues/224 ) option implementation.
2021-09-29 14:36:55 +03:00
2021-09-09 12:38:43 +03:00
2018-12-11 20:21:49 +01:00
## Authors
2021-10-01 19:53:53 +03:00
This repository is managed by [Anton Babenko ](https://github.com/antonbabenko ) with help from these awesome contributors:
2021-10-15 15:08:26 +03:00
<!-- markdownlint-disable no-inline-html -->
2021-10-01 19:53:53 +03:00
<a href="https://github.com/antonbabenko/pre-commit-terraform/graphs/contributors">
<img src="https://contrib.rocks/image?repo=antonbabenko/pre-commit-terraform" />
</a>
2021-10-15 15:08:26 +03:00
<!-- markdownlint-enable no-inline-html -->
2018-12-11 20:21:49 +01:00
## License
2021-10-15 15:08:26 +03:00
MIT licensed. See [LICENSE ](LICENSE ) for full details.