tfprovidercheck
Install | Usage | Config
Censor Terraform Providers.
# Only google provider and azurerm provider are allowed
$ cat .tfprovidercheck.yaml
providers:
- name: registry.terraform.io/hashicorp/google
version: ">= 4.0.0"
- name: registry.terraform.io/hashicorp/azurerm
# tfprovidercheck fails because aws provider is disallowed
$ terraform version -json | tfprovidercheck
FATA[0000] tfprovidercheck failed error="this Terraform Provider is disallowed" program=tfprovidercheck provider_name=registry.terraform.io/hashicorp/aws tfprovidercheck_version=0.1.0tfprovidercheck is a command line tool to execute Terraform security. It prevents malicious Terraform Providers from being executed. You can define the allow list of Terraform Providers and their versions, and check if disallowed providers aren't used.
Usage
Please run terraform init in advance to update the list of Terraform Providers.
terraform version -json | tfprovidercheck [-c <configuration file path>]To prevent malicious codes from being executed, you should run tfprovidercheck before running other Terraform commands such as terraform validate, terraform plan, and terraform apply.
$ tfprovidercheck --help
tfprovidercheck - Censor Terraform Providers
https://github.com/suzuki-shunsuke/tfprovidercheck
Usage:
tfprovidercheck [<options>]
Options:
-help, -h Show help
-version, -v Show version
-config, -c Configuration file pathConfiguration
There are several ways to configure tfprovidercheck. In order of priority, they are as follows.
- The command line option -config [-c], which is the configuration file path
- The environment variable TFPROVIDERCHECKCONFIGBODY, which is the configuration itself (YAML)
- The environment variable TFPROVIDERCHECKCONFIG, which is the configuration file path
- The configuration file .tfprovidercheck.yaml on the current directory
The field providers lists allowed providers and their versions.
e.g.
providers:
- name: registry.terraform.io/hashicorp/aws
version: ">= 3.0.0" # Quotes are necessary because '>' is a special character for YAML
- name: registry.terraform.io/hashicorp/google
# version is optional- name (Required, string): name must be equal to the provider name. Regular expression and glob aren't supported
- version (Optional, string): The version constraint of Terraform Provider. version is evaluated as hashicorp/go-version' Version Constraints. If version is empty, any version is allowed