2018-12-11 20:21:49 +01:00
# Collection of git hooks for Terraform to be used with [pre-commit framework](http://pre-commit.com/)
2016-09-27 19:47:26 +02:00
2021-09-09 12:38:43 +03:00
[](https://github.com/antonbabenko/pre-commit-terraform/releases)  [](https://www.codetriage.com/antonbabenko/pre-commit-terraform)
* [How to install ](#how-to-install )
* [1. Install dependencies ](#1-install-dependencies )
* [2. Install the pre-commit hook globally ](#2-install-the-pre-commit-hook-globally )
* [3. Add configs and hooks ](#3-add-configs-and-hooks )
* [4. Run ](#4-run )
* [Available Hooks ](#available-hooks )
* [Hooks notes ](#hooks-notes )
* [terraform_docs ](#terraform_docs )
* [terraform_tflint ](#terraform_tflint )
* [terraform_tfsec ](#terraform_tfsec )
* [terraform_validate ](#terraform_validate )
* [Notes for contributors ](#notes-for-contributors )
* [Run and debug hooks locally ](#run-and-debug-hooks-locally )
* [Authors ](#authors )
* [License ](#license )
2018-01-03 22:26:39 -06:00
2018-12-11 20:21:49 +01:00
## How to install
2018-01-24 15:46:37 +01:00
2019-10-17 14:50:16 +03:00
### 1. Install dependencies
2016-09-27 19:47:26 +02:00
2021-09-09 22:29:33 +03:00
<!-- markdownlint-disable no-inline-html -->
* [`pre-commit` ](https://pre-commit.com/#install ),
<sub><sup>[`terraform` ](https://www.terraform.io/downloads.html ),
<sub><sup>[`git` ](https://git-scm.com/downloads ),
<sub><sup>POSIX compatible shell,
<sub><sup>Internet connection (on first run),
<sub><sup>x86_64 compatible operation system,
<sub><sup>Some hardware where this OS will run,
<sub><sup>Electricity for hardware and internet connection,
<sub><sup>Some basic physical laws,
<sub><sup>Hope that it all will works.
</sup></sub></sup></sub></sup></sub></sup></sub></sup></sub></sup></sub></sup></sub></sup></sub></sup></sub><br><br>
2020-09-08 15:10:56 +02:00
* [`checkov` ](https://github.com/bridgecrewio/checkov ) required for `checkov` hook.
2021-09-09 22:29:33 +03:00
* [`terraform-docs` ](https://github.com/terraform-docs/terraform-docs ) required for `terraform_docs` hooks.
2021-09-11 10:47:56 +03:00
* [`terragrunt` ](https://terragrunt.gruntwork.io/docs/getting-started/install/ ) required for `terragrunt_validate` hook.
2021-04-22 16:15:00 -04:00
* [`terrascan` ](https://github.com/accurics/terrascan ) required for `terrascan` hook.
2021-09-09 22:29:33 +03:00
* [`TFLint` ](https://github.com/terraform-linters/tflint ) required for `terraform_tflint` hook.
* [`TFSec` ](https://github.com/liamg/tfsec ) required for `terraform_tfsec` hook.
<details><summary><b>Docker</b></summary><br>
If no `--build-arg` is specified, then the latest versions of `pre-commit` and `terraform` will be installed.
```bash
git clone git@github .com:antonbabenko/pre-commit-terraform.git
cd pre-commit-terraform
# Install all tools with latest versions:
docker build -t pre-commit --build-arg INSTALL_ALL=true .
```
You can specify needed tool versions by providing `--build-arg` 's.
If you'd like you can use the `latest` versions:
```bash
docker build -t pre-commit \
--build-arg PRE_COMMIT_VERSION=latest \
--build-arg TERRAFORM_VERSION=latest \
--build-arg CHECKOV_VERSION=2.0.405 \
--build-arg TERRAFORM_DOCS_VERSION=0.15.0 \
--build-arg TERRAGRUNT_VERSION=latest \
--build-arg TERRASCAN_VERSION=1.10.0 \
--build-arg TFLINT_VERSION=0.31.0 \
--build-arg TFSEC_VERSION=latest \
.
```
2019-10-17 14:50:16 +03:00
2021-09-09 22:29:33 +03:00
To disable pre-commit color output set `-e PRE_COMMIT_COLOR=never` .
2021-03-12 15:35:21 +01:00
2021-09-09 22:29:33 +03:00
</details>
<details><summary><b>MacOS</b></summary><br>
[`coreutils` ](https://formulae.brew.sh/formula/coreutils ) required for `terraform_validate` hook on macOS (due to use of `realpath` ).
2019-10-17 14:50:16 +03:00
```bash
2021-09-10 22:33:03 +03:00
brew install pre-commit terraform-docs tflint tfsec coreutils checkov terrascan
2021-09-09 22:29:33 +03:00
terrascan init
2019-10-17 14:50:16 +03:00
```
2021-09-09 22:29:33 +03:00
</details>
<details><summary><b>Ubuntu 18.04</b></summary><br>
2018-12-11 20:21:49 +01:00
```bash
2021-03-12 10:32:41 +01:00
sudo apt update
2021-09-10 22:33:03 +03:00
sudo apt install -y unzip software-properties-common
2021-03-12 10:32:41 +01:00
sudo add-apt-repository ppa:deadsnakes/ppa
sudo apt install -y python3.7 python3-pip
2021-09-09 12:38:43 +03:00
python3 -m pip install --upgrade pip
2021-09-09 22:29:33 +03:00
pip3 install --no-cache-dir pre-commit
python3.7 -m pip install -U checkov
2021-09-10 22:33:03 +03:00
curl -L "$(curl -s https://api.github.com/repos/terraform-docs/terraform-docs/releases/latest | grep -o -E -m 1 "https://.+?-linux-amd64.tar.gz")" > terraform-docs.tgz && tar -xzf terraform-docs.tgz && rm terraform-docs.tgz && chmod +x terraform-docs && sudo mv terraform-docs /usr/bin/
curl -L "$(curl -s https://api.github.com/repos/terraform-linters/tflint/releases/latest | grep -o -E -m 1 "https://.+?_linux_amd64.zip")" > tflint.zip && unzip tflint.zip && rm tflint.zip && sudo mv tflint /usr/bin/
curl -L "$(curl -s https://api.github.com/repos/aquasecurity/tfsec/releases/latest | grep -o -E -m 1 "https://.+?tfsec-linux-amd64")" > tfsec && chmod +x tfsec && sudo mv tfsec /usr/bin/
curl -L "$(curl -s https://api.github.com/repos/accurics/terrascan/releases/latest | grep -o -E -m 1"https://.+?_Linux_x86_64.tar.gz")" > terrascan.tar.gz && tar -xzf terrascan.tar.gz terrascan && rm terrascan.tar.gz && sudo mv terrascan /usr/bin/ && terrascan init
2018-12-11 20:21:49 +01:00
```
2018-05-16 20:04:48 +02:00
2021-09-09 22:29:33 +03:00
</details>
<details><summary><b>Ubuntu 20.04</b></summary><br>
2021-09-09 12:38:43 +03:00
```bash
sudo apt update
2021-09-10 22:33:03 +03:00
sudo apt install -y unzip software-properties-common python3 python3-pip
2021-09-09 12:38:43 +03:00
python3 -m pip install --upgrade pip
2021-09-09 22:29:33 +03:00
pip3 install --no-cache-dir pre-commit
pip3 install --no-cache-dir checkov
2021-09-10 22:33:03 +03:00
curl -L "$(curl -s https://api.github.com/repos/terraform-docs/terraform-docs/releases/latest | grep -o -E -m 1 "https://.+?-linux-amd64.tar.gz")" > terraform-docs.tgz && tar -xzf terraform-docs.tgz terraform-docs && rm terraform-docs.tgz && chmod +x terraform-docs && sudo mv terraform-docs /usr/bin/
curl -L "$(curl -s https://api.github.com/repos/accurics/terrascan/releases/latest | grep -o -E -m 1"https://.+?_Linux_x86_64.tar.gz")" > terrascan.tar.gz && tar -xzf terrascan.tar.gz terrascan && rm terrascan.tar.gz && sudo mv terrascan /usr/bin/ && terrascan init
curl -L "$(curl -s https://api.github.com/repos/terraform-linters/tflint/releases/latest | grep -o -E -m 1 "https://.+?_linux_amd64.zip")" > tflint.zip && unzip tflint.zip && rm tflint.zip && sudo mv tflint /usr/bin/
curl -L "$(curl -s https://api.github.com/repos/aquasecurity/tfsec/releases/latest | grep -o -E -m 1 "https://.+?tfsec-linux-amd64")" > tfsec && chmod +x tfsec && sudo mv tfsec /usr/bin/
2021-09-09 12:38:43 +03:00
```
2021-09-09 22:29:33 +03:00
</details>
<!-- markdownlint-enable no-inline-html -->
2021-09-09 12:38:43 +03:00
2019-10-17 14:50:16 +03:00
### 2. Install the pre-commit hook globally
2021-09-09 12:38:43 +03:00
2021-09-09 22:29:33 +03:00
> Note: not needed if you use the Docker image
2019-10-17 14:50:16 +03:00
```bash
DIR=~/.git-template
git config --global init.templateDir ${DIR}
pre-commit init-templatedir -t pre-commit ${DIR}
```
2018-05-16 20:04:48 +02:00
2019-10-17 14:50:16 +03:00
### 3. Add configs and hooks
2018-05-16 20:04:48 +02:00
2018-12-11 20:21:49 +01:00
Step into the repository you want to have the pre-commit hooks installed and run:
2016-09-27 19:47:26 +02:00
2018-12-11 20:21:49 +01:00
```bash
2019-10-17 14:50:16 +03:00
git init
2018-12-11 20:21:49 +01:00
cat <<EOF > .pre-commit-config.yaml
2020-04-29 15:06:02 -05:00
repos:
2018-01-15 16:12:51 +01:00
- repo: git://github.com/antonbabenko/pre-commit-terraform
2020-01-21 05:19:46 -05:00
rev: <VERSION> # Get the latest from: https://github.com/antonbabenko/pre-commit-terraform/releases
2018-01-15 16:12:51 +01:00
hooks:
- id: terraform_fmt
2019-06-17 12:47:06 +02:00
- id: terraform_docs
2018-12-11 20:21:49 +01:00
EOF
```
2019-10-17 14:50:16 +03:00
### 4. Run
2018-12-11 20:21:49 +01:00
2021-09-09 22:29:33 +03:00
After pre-commit hook has been installed you can run it manually on all files in the repository.
Local installation:
2018-12-11 20:21:49 +01:00
```bash
pre-commit run -a
2016-09-27 19:47:26 +02:00
```
2021-09-09 22:29:33 +03:00
Docker:
2021-09-09 12:38:43 +03:00
2021-03-12 15:35:21 +01:00
```bash
2021-04-22 16:15:00 -04:00
docker run -v $(pwd):/lint -w /lint pre-commit run -a
2021-03-12 15:35:21 +01:00
```
2021-09-11 10:47:56 +03:00
> You be able list tools versions when needed
>
> ```bash
> TAG=latest && docker run --entrypoint cat pre-commit:$TAG /usr/bin/tools_versions_info
> ```
2018-12-11 20:21:49 +01:00
## Available Hooks
2020-01-21 05:19:46 -05:00
There are several [pre-commit ](https://pre-commit.com/ ) hooks to keep Terraform configurations (both `*.tf` and `*.tfvars` ) and Terragrunt configurations (`*.hcl` ) in a good shape:
2019-10-17 14:50:16 +03:00
2021-09-09 22:29:33 +03:00
| Hook name | Description |
| ------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `terraform_fmt` | Rewrites all Terraform configuration files to a canonical format. [Hook notes ](#terraform_docs ) |
| `terraform_validate` | Validates all Terraform configuration files. [Hook notes ](#terraform_validate ) |
| `terraform_docs` | Inserts input and output documentation into `README.md` . Recommended. |
| `terraform_docs_without_aggregate_type_defaults` | Inserts input and output documentation into `README.md` without aggregate type defaults. |
| `terraform_docs_replace` | Runs `terraform-docs` and pipes the output directly to README.md |
| `terraform_tflint` | Validates all Terraform configuration files with [TFLint ](https://github.com/terraform-linters/tflint ). [Available TFLint rules ](https://github.com/terraform-linters/tflint/tree/master/docs/rules#rules ). [Hook notes ](#terraform_tflint ). |
| `terragrunt_fmt` | Rewrites all [Terragrunt ](https://github.com/gruntwork-io/terragrunt ) configuration files (`*.hcl` ) to a canonical format. |
| `terragrunt_validate` | Validates all [Terragrunt ](https://github.com/gruntwork-io/terragrunt ) configuration files (`*.hcl` ) |
| `terraform_tfsec` | [TFSec ](https://github.com/liamg/tfsec ) static analysis of terraform templates to spot potential security issues. [Hook notes ](#terraform_tfsec ) |
| `checkov` | [checkov ](https://github.com/bridgecrewio/checkov ) static analysis of terraform templates to spot potential security issues. |
| `terrascan` | [terrascan ](https://github.com/accurics/terrascan ) Detect compliance and security violations. |
2018-12-11 20:21:49 +01:00
Check the [source file ](https://github.com/antonbabenko/pre-commit-terraform/blob/master/.pre-commit-hooks.yaml ) to know arguments used for each hook.
2021-09-09 12:38:43 +03:00
## Hooks notes
### terraform_docs
2018-12-11 20:21:49 +01:00
2020-08-19 06:06:55 -04:00
1. `terraform_docs` and `terraform_docs_without_aggregate_type_defaults` will insert/update documentation generated by [terraform-docs ](https://github.com/terraform-docs/terraform-docs ) framed by markers:
2019-10-17 14:50:16 +03:00
2021-09-09 12:38:43 +03:00
```txt
<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
```
if they are present in `README.md` .
2018-12-11 20:21:49 +01:00
2021-09-09 12:38:43 +03:00
2. `terraform_docs_replace` replaces the entire README.md rather than doing string replacement between markers. Put your additional documentation at the top of your `main.tf` for it to be pulled in. The optional `--dest` argument lets you change the name of the file that gets created/modified.
Example:
2018-12-13 22:16:01 -05:00
```yaml
hooks:
- id: terraform_docs_replace
2020-11-12 05:55:53 -05:00
args: ['--sort-by-required', '--dest=TEST.md']
2018-12-13 22:16:01 -05:00
```
2021-09-09 12:38:43 +03:00
3. It is possible to pass additional arguments to shell scripts when using `terraform_docs` and `terraform_docs_without_aggregate_type_defaults` . Send pull-request with the new hook if there is something missing.
2018-12-11 20:21:49 +01:00
2021-09-09 12:38:43 +03:00
### terraform_tflint
2019-11-16 18:37:23 +00:00
1. `terraform_tflint` supports custom arguments so you can enable module inspection, deep check mode etc.
2021-09-09 12:38:43 +03:00
Example:
2019-11-16 18:37:23 +00:00
```yaml
hooks:
- id: terraform_tflint
2020-08-27 10:57:45 +01:00
args: ['--args=--deep']
2020-03-02 14:48:53 +00:00
```
In order to pass multiple args, try the following:
2021-09-09 12:38:43 +03:00
2020-03-02 14:48:53 +00:00
```yaml
- id: terraform_tflint
2020-05-27 10:35:15 +02:00
args:
2020-08-27 10:57:45 +01:00
- '--args=--deep'
- '--args=--enable-rule=terraform_documented_variables'
2019-11-16 18:37:23 +00:00
```
2021-09-09 12:38:43 +03:00
3. When you have multiple directories and want to run `tflint` in all of them and share single config file it is impractical to hard-code the path to `.tflint.hcl` file. The solution is to use `__GIT_WORKING_DIR__` placeholder which will be replaced by `terraform_tflint` hooks with Git working directory (repo root) at run time. For example:
2020-09-22 14:20:27 +02:00
2021-09-09 12:38:43 +03:00
```yaml
hooks:
- id: terraform_tflint
args:
- '--args=--config=__GIT_WORKING_DIR__/.tflint.hcl'
```
2020-09-22 14:20:27 +02:00
2021-09-09 12:38:43 +03:00
### terraform_tfsec
2020-04-23 09:56:33 -05:00
2020-09-01 01:07:08 -07:00
1. `terraform_tfsec` will consume modified files that pre-commit
passes to it, so you can perform whitelisting of directories
or files to run against via [files ](https://pre-commit.com/#config-files )
pre-commit flag
2021-09-09 12:38:43 +03:00
Example:
2020-09-01 01:07:08 -07:00
```yaml
hooks:
- id: terraform_tfsec
files: ^prd-infra/
```
The above will tell pre-commit to pass down files from the `prd-infra/` folder
only such that the underlying `tfsec` tool can run against changed files in this
directory, ignoring any other folders at the root level
2021-09-09 12:38:43 +03:00
2. To ignore specific warnings, follow the convention from the
2020-04-23 09:56:33 -05:00
[documentation ](https://github.com/liamg/tfsec#ignoring-warnings ).
2021-09-09 12:38:43 +03:00
Example:
2020-04-23 09:56:33 -05:00
```hcl
resource "aws_security_group_rule" "my-rule" {
type = "ingress"
cidr_blocks = ["0.0.0.0/0"] #tfsec:ignore:AWS006
}
```
2021-09-09 12:38:43 +03:00
### terraform_validate
2020-08-27 10:57:45 +01:00
1. `terraform_validate` supports custom arguments so you can pass supported no-color or json flags.
2021-09-09 12:38:43 +03:00
Example:
2020-08-27 10:57:45 +01:00
```yaml
hooks:
- id: terraform_validate
args: ['--args=-json']
```
In order to pass multiple args, try the following:
2021-09-09 12:38:43 +03:00
2020-08-27 10:57:45 +01:00
```yaml
- id: terraform_validate
args:
- '--args=-json'
- '--args=-no-color'
```
2021-09-09 12:38:43 +03:00
2. `terraform_validate` also supports custom environment variables passed to the pre-commit runtime
Example:
2020-08-27 10:57:45 +01:00
```yaml
hooks:
- id: terraform_validate
args: ['--envs=AWS_DEFAULT_REGION="us-west-2"']
```
In order to pass multiple args, try the following:
2021-09-09 12:38:43 +03:00
2020-08-27 10:57:45 +01:00
```yaml
- id: terraform_validate
args:
- '--envs=AWS_DEFAULT_REGION="us-west-2"'
- '--envs=AWS_ACCESS_KEY_ID="anaccesskey"'
- '--envs=AWS_SECRET_ACCESS_KEY="asecretkey"'
```
2020-04-23 09:56:33 -05:00
2021-09-09 12:38:43 +03:00
3. It may happen that Terraform working directory (`.terraform` ) already exists but not in the best condition (eg, not initialized modules, wrong version of Terraform, etc). To solve this problem you can find and delete all `.terraform` directories in your repository using this command:
2020-11-02 21:44:54 +01:00
```shell
find . -type d -name ".terraform" -print0 | xargs -0 rm -r
```
`terraform_validate` hook will try to reinitialize them before running `terraform validate` command.
2021-09-09 12:38:43 +03:00
## Notes for contributors
2018-12-14 16:16:42 -05:00
1. Python hooks are supported now too. All you have to do is:
2019-06-19 06:10:21 -04:00
1. add a line to the `console_scripts` array in `entry_points` in `setup.py`
2021-09-09 12:38:43 +03:00
2. Put your python script in the `pre_commit_hooks` folder
2018-12-14 16:16:42 -05:00
2020-11-02 21:44:54 +01:00
Enjoy the clean, valid, and documented code!
2018-12-11 20:21:49 +01:00
2021-09-09 12:38:43 +03:00
### Run and debug hooks locally
```bash
pre-commit try-repo {-a} /path/to/local/pre-commit-terraform/repo {hook_name}
```
I.e.
```bash
pre-commit try-repo /mnt/c/Users/tf/pre-commit-terraform terraform_fmt # Run only `terraform_fmt` check
pre-commit try-repo -a ~/pre-commit-terraform # run all existing checks from repo
```
Running `pre-commit` with `try-repo` ignores all arguments specified in `.pre-commit-config.yaml` .
2018-12-11 20:21:49 +01:00
## Authors
This repository is managed by [Anton Babenko ](https://github.com/antonbabenko ) with help from [these awesome contributors ](https://github.com/antonbabenko/pre-commit-terraform/graphs/contributors ).
## License
MIT licensed. See LICENSE for full details.