From 9507bef8c3dcc9663750436c08d940a947e0a271 Mon Sep 17 00:00:00 2001 From: caiohasouza Date: Wed, 5 Aug 2026 23:05:54 -0300 Subject: [PATCH 1/3] chore(terraform): standardize module repository --- .github/workflows/pr-title.yml | 45 +++++------------- .github/workflows/pre-commit.yml | 80 -------------------------------- .github/workflows/release.yml | 34 +++++++------- .github/workflows/validate.yml | 38 +++++++++++++++ .gitignore | 1 + .pre-commit-config.yaml | 69 ++++++++++++++------------- .releaserc.json | 56 +++++++--------------- .terraform-version | 1 + CONTRIBUTING.md | 50 ++++++++++++++++++++ README.md | 8 +++- 10 files changed, 173 insertions(+), 209 deletions(-) delete mode 100644 .github/workflows/pre-commit.yml create mode 100644 .github/workflows/validate.yml create mode 100644 .terraform-version create mode 100644 CONTRIBUTING.md diff --git a/.github/workflows/pr-title.yml b/.github/workflows/pr-title.yml index 168011c..eb1d555 100644 --- a/.github/workflows/pr-title.yml +++ b/.github/workflows/pr-title.yml @@ -1,52 +1,29 @@ -name: 'Validate PR title' +name: Validate PR title on: pull_request_target: - types: - - opened - - edited - - synchronize + types: [opened, edited, synchronize] + +permissions: + pull-requests: read jobs: - main: - name: Validate PR title + validate: runs-on: ubuntu-latest steps: - # Please look up the latest version from - # https://github.com/amannn/action-semantic-pull-request/releases - - uses: amannn/action-semantic-pull-request@v3.4.6 + - uses: amannn/action-semantic-pull-request@v6 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} with: - # Configure which types are allowed. - # Default: https://github.com/commitizen/conventional-commit-types types: | fix feat docs ci chore - # Configure that a scope must always be provided. + style + revert requireScope: false - # Configure additional validation for the subject based on a regex. - # This example ensures the subject starts with an uppercase character. - subjectPattern: ^[A-Z].+$ - # If `subjectPattern` is configured, you can use this property to override - # the default error message that is shown when the pattern doesn't match. - # The variables `subject` and `title` can be used within the message. - subjectPatternError: | - The subject "{subject}" found in the pull request title "{title}" - didn't match the configured pattern. Please ensure that the subject - starts with an uppercase character. - # For work-in-progress PRs you can typically use draft pull requests - # from Github. However, private repositories on the free plan don't have - # this option and therefore this action allows you to opt-in to using the - # special "[WIP]" prefix to indicate this state. This will avoid the - # validation of the PR title and the pull request checks remain pending. - # Note that a second check will be reported if this is enabled. - wip: true - # When using "Squash and merge" on a PR with only one commit, GitHub - # will suggest using that commit message instead of the PR title for the - # merge commit, and it's easy to commit this by mistake. Enable this option - # to also validate the commit message for one commit PRs. + subjectPattern: ^[a-z].+$ + subjectPatternError: "The subject must start with a lowercase character." validateSingleCommit: false diff --git a/.github/workflows/pre-commit.yml b/.github/workflows/pre-commit.yml deleted file mode 100644 index 956986a..0000000 --- a/.github/workflows/pre-commit.yml +++ /dev/null @@ -1,80 +0,0 @@ -name: Pre-Commit - -on: - pull_request: - branches: - - main - - master - -env: - TERRAFORM_DOCS_VERSION: v0.16.0 - -jobs: - collectInputs: - name: Collect workflow inputs - runs-on: ubuntu-latest - outputs: - directories: ${{ steps.dirs.outputs.directories }} - steps: - - name: Checkout - uses: actions/checkout@v3 - - - name: Get root directories - id: dirs - uses: clowdhaus/terraform-composite-actions/directories@v1.3.0 - - preCommitMinVersions: - name: Min TF pre-commit - needs: collectInputs - runs-on: ubuntu-latest - strategy: - matrix: - directory: ${{ fromJson(needs.collectInputs.outputs.directories) }} - steps: - - run: git config --global url."https://".insteadOf git:// - - name: Checkout - uses: actions/checkout@v3 - - - name: Terraform min/max versions - id: minMax - uses: clowdhaus/terraform-min-max@v1.0.3 - with: - directory: ${{ matrix.directory }} - - - name: Pre-commit Terraform ${{ steps.minMax.outputs.minVersion }} - # Run only validate pre-commit check on min version supported - if: ${{ matrix.directory != '.' }} - uses: clowdhaus/terraform-composite-actions/pre-commit@v1.3.0 - with: - terraform-version: ${{ steps.minMax.outputs.minVersion }} - args: 'terraform_validate --color=always --show-diff-on-failure --files ${{ matrix.directory }}/*' - - - name: Pre-commit Terraform ${{ steps.minMax.outputs.minVersion }} - # Run only validate pre-commit check on min version supported - if: ${{ matrix.directory == '.' }} - uses: clowdhaus/terraform-composite-actions/pre-commit@v1.3.0 - with: - terraform-version: ${{ steps.minMax.outputs.minVersion }} - args: 'terraform_validate --color=always --show-diff-on-failure --files $(ls *.tf)' - - #preCommitMaxVersion: - # name: Max TF pre-commit - # runs-on: ubuntu-latest - # needs: collectInputs - # steps: - # - run: git config --global url."https://".insteadOf git:// - # - name: Checkout - # uses: actions/checkout@v3 - # with: - # ref: ${{ github.event.pull_request.head.ref }} - # repository: ${{github.event.pull_request.head.repo.full_name}} -# - # - name: Terraform min/max versions - # id: minMax - # uses: clowdhaus/terraform-min-max@v1.0.3 -# - # - name: Pre-commit Terraform ${{ steps.minMax.outputs.maxVersion }} - # uses: clowdhaus/terraform-composite-actions/pre-commit@v1.3.0 - # with: - # terraform-version: ${{ steps.minMax.outputs.maxVersion }} - # terraform-docs-version: ${{ env.TERRAFORM_DOCS_VERSION }} diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 045f4e8..b6c2306 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -1,35 +1,33 @@ name: Release on: - workflow_dispatch: push: - branches: - - main - - master + branches: [master] paths: - - '**/*.tpl' - - '**/*.py' - - '**/*.tf' - - '.github/workflows/release.yml' + - "**/*.tf" + - ".releaserc.json" + - ".github/workflows/release.yml" + +permissions: + contents: write + issues: write + pull-requests: write jobs: release: - name: Release runs-on: ubuntu-latest steps: - - name: Checkout - uses: actions/checkout@v3 + - uses: actions/checkout@v4 with: - persist-credentials: false fetch-depth: 0 + persist-credentials: false - - name: Release - uses: cycjimmy/semantic-release-action@v2 + - uses: cycjimmy/semantic-release-action@v5.0.2 with: - semantic_version: 18.0.0 + semantic_version: 25.0.8 extra_plugins: | - @semantic-release/changelog@6.0.0 - @semantic-release/git@10.0.0 - conventional-changelog-conventionalcommits@4.6.3 + @semantic-release/changelog@6.0.3 + @semantic-release/git@10.0.1 + conventional-changelog-conventionalcommits@8.0.0 env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml new file mode 100644 index 0000000..5396875 --- /dev/null +++ b/.github/workflows/validate.yml @@ -0,0 +1,38 @@ +name: Validate Terraform module + +on: + pull_request: + push: + branches: [master] + +permissions: + contents: read + +jobs: + validate: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v4 + + - uses: hashicorp/setup-terraform@v3 + with: + terraform_version: "0.13.1" + terraform_wrapper: false + + - uses: terraform-linters/setup-tflint@v6 + with: + tflint_version: v0.58.0 + + - uses: actions/setup-python@v5 + with: + python-version: "3.12" + + - name: Install pre-commit + run: pipx install pre-commit + + - name: Validate root module + run: | + terraform fmt -check -recursive + terraform init -backend=false + terraform validate + pre-commit run --all-files diff --git a/.gitignore b/.gitignore index 397af32..2bf9373 100644 --- a/.gitignore +++ b/.gitignore @@ -16,6 +16,7 @@ crash.log # control as they are data points which are potentially sensitive and subject # to change depending on the environment. *.tfvars +*.tfvars.json # Ignore override files as they are usually used to override resources locally and so # are not checked in diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index 10db981..da73cc1 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -1,37 +1,36 @@ repos: -- repo: git://github.com/antonbabenko/pre-commit-terraform - rev: v1.68.1 - hooks: - - id: terraform_fmt - - id: terraform_validate - - id: terraform_tflint - args: - - '--args=--only=terraform_deprecated_interpolation' - - '--args=--only=terraform_deprecated_index' - - '--args=--only=terraform_unused_declarations' - - '--args=--only=terraform_comment_syntax' - - '--args=--only=terraform_documented_outputs' - - '--args=--only=terraform_documented_variables' - - '--args=--only=terraform_typed_variables' - - '--args=--only=terraform_module_pinned_source' - - '--args=--only=terraform_naming_convention' - - '--args=--only=terraform_required_version' - - '--args=--only=terraform_required_providers' - - '--args=--only=terraform_standard_module_structure' - - '--args=--only=terraform_workspace_remote' -- repo: local - hooks: - - id: terraform-docs - name: terraform-docs - language: docker_image - entry: quay.io/terraform-docs/terraform-docs:latest - args: ["markdown", "--output-file", "README.md", "--output-mode", "replace", "./"] - pass_filenames: false -- repo: https://github.com/pre-commit/pre-commit-hooks - rev: v3.2.0 + - repo: https://github.com/antonbabenko/pre-commit-terraform + rev: v1.108.0 hooks: - - id: trailing-whitespace - - id: end-of-file-fixer - exclude: README.md - - id: check-added-large-files - - id: detect-aws-credentials + - id: terraform_fmt + - id: terraform_validate + files: ^(main|variables|outputs|versions)\.tf$ + - id: terraform_tflint + files: ^(main|variables|outputs|versions)\.tf$ + args: + - --args=--only=terraform_deprecated_interpolation + - --args=--only=terraform_deprecated_index + - --args=--only=terraform_unused_declarations + - --args=--only=terraform_documented_outputs + - --args=--only=terraform_documented_variables + - --args=--only=terraform_typed_variables + - --args=--only=terraform_required_version + - --args=--only=terraform_required_providers + - --args=--only=terraform_standard_module_structure + - repo: https://github.com/pre-commit/pre-commit-hooks + rev: v6.0.0 + hooks: + - id: trailing-whitespace + - id: end-of-file-fixer + exclude: README.md + - id: check-added-large-files + - id: detect-aws-credentials + args: [--allow-missing-credentials] + - repo: local + hooks: + - id: terraform-docs + name: Terraform docs + language: docker_image + entry: quay.io/terraform-docs/terraform-docs:latest + args: ["markdown", "table", "--output-file", "README.md", "--output-mode", "inject", "."] + pass_filenames: false diff --git a/.releaserc.json b/.releaserc.json index 66b3eef..dad592f 100644 --- a/.releaserc.json +++ b/.releaserc.json @@ -1,45 +1,21 @@ { - "branches": [ - "main", - "master" - ], + "branches": ["master"], "ci": false, "plugins": [ - [ - "@semantic-release/commit-analyzer", - { - "preset": "conventionalcommits" - } - ], - [ - "@semantic-release/release-notes-generator", - { - "preset": "conventionalcommits" - } - ], - [ - "@semantic-release/github", - { - "successComment": "This ${issue.pull_request ? 'PR is included' : 'issue has been resolved'} in version ${nextRelease.version} :tada:", - "labels": false, - "releasedLabels": false - } - ], - [ - "@semantic-release/changelog", - { - "changelogFile": "CHANGELOG.md", - "changelogTitle": "# Changelog\n\nAll notable changes to this project will be documented in this file." - } - ], - [ - "@semantic-release/git", - { - "assets": [ - "CHANGELOG.md" - ], - "message": "chore(release): version ${nextRelease.version} [skip ci]\n\n${nextRelease.notes}" - } - ] + ["@semantic-release/commit-analyzer", { "preset": "conventionalcommits" }], + ["@semantic-release/release-notes-generator", { "preset": "conventionalcommits" }], + ["@semantic-release/changelog", { + "changelogFile": "CHANGELOG.md", + "changelogTitle": "# Changelog\n\nAll notable changes to this project will be documented in this file." + }], + ["@semantic-release/github", { + "successComment": "This ${issue.pull_request ? 'PR is included' : 'issue has been resolved'} in version ${nextRelease.version} :tada:", + "labels": false, + "releasedLabels": false + }], + ["@semantic-release/git", { + "assets": ["CHANGELOG.md"], + "message": "chore(release): version ${nextRelease.version} [skip ci]\n\n${nextRelease.notes}" + }] ] } diff --git a/.terraform-version b/.terraform-version new file mode 100644 index 0000000..c317a91 --- /dev/null +++ b/.terraform-version @@ -0,0 +1 @@ +0.13.1 diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md new file mode 100644 index 0000000..2255844 --- /dev/null +++ b/CONTRIBUTING.md @@ -0,0 +1,50 @@ +# Contributing + +Contributions that improve this Terraform module are welcome. Please keep each +change focused, documented, and validated before opening a pull request. + +## Prerequisites + +- The Terraform version declared in `.terraform-version`. +- Docker, used by the `terraform-docs` pre-commit hook. +- Python with `pre-commit` installed. For example: `pipx install pre-commit`. + +## Local validation + +Before opening a pull request, run: + +```shell +tfswitch +pre-commit run --all-files +``` + +The command formats Terraform, validates the root module, runs TFLint, checks +for credentials, and refreshes generated Terraform documentation in +`README.md`. Do not manually edit content between Terraform Docs markers. + +## Pull requests + +- Create a branch from the repository default branch and keep the pull request + focused on one change. +- Describe the behavior being changed and include an example when the module + interface changes. +- Ensure the GitHub Actions validation workflow passes before requesting review. +- Use a Conventional Commit-compatible pull request title. Allowed types are + `feat`, `fix`, `docs`, `ci`, `chore`, `style`, and `revert`. The + subject must start with a lowercase character. + +## Releases + +Releases are automated by Semantic Release after changes are merged into the +repository default branch. It determines the next semantic version from +Conventional Commits, creates the Git tag and GitHub Release, and updates +`CHANGELOG.md`. + +- `fix:` produces a patch release. +- `feat:` produces a minor release. +- A commit with `!` in its type or scope, or a `BREAKING CHANGE:` footer, + produces a major release. + +The Terraform Registry is connected to this repository once by the module +owner. After initial registration, Registry versions are indexed from Semantic +Release Git tags. diff --git a/README.md b/README.md index 54ba074..486e5e2 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,7 @@ +## Compatibility + +This module requires Terraform 0.13.1 or later. Older Terraform versions are not supported. + Create an Api Gateway to trigger lambda function. @@ -13,7 +17,7 @@ Create an Api Gateway to trigger lambda function. | Name | Version | |------|---------| -| [aws](#provider\_aws) | >= 3.63 | +| [aws](#provider\_aws) | 6.58.0 | ## Modules @@ -47,4 +51,4 @@ No modules. | [execution\_arn](#output\_execution\_arn) | The execution ARN part to be used in lambda\_permission's source\_arn when allowing API Gateway to invoke a Lambda function | | [id](#output\_id) | The ID of the REST API. | | [root\_resource\_id](#output\_root\_resource\_id) | The resource ID of the REST API's root | - \ No newline at end of file + From 93168b108c6cf4aff4f03b288351477ee5a3d517 Mon Sep 17 00:00:00 2001 From: caiohasouza Date: Wed, 5 Aug 2026 23:15:34 -0300 Subject: [PATCH 2/3] fix(ci): pin terraform-docs image --- .pre-commit-config.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index da73cc1..95acafc 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -31,6 +31,6 @@ repos: - id: terraform-docs name: Terraform docs language: docker_image - entry: quay.io/terraform-docs/terraform-docs:latest + entry: quay.io/terraform-docs/terraform-docs:0.20.0 args: ["markdown", "table", "--output-file", "README.md", "--output-mode", "inject", "."] pass_filenames: false From b2bbf11936a1d2704a5069db5369afd2429cf92f Mon Sep 17 00:00:00 2001 From: caiohasouza Date: Wed, 5 Aug 2026 23:26:55 -0300 Subject: [PATCH 3/3] fix(docs): align provider version --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index 486e5e2..dfc0d8d 100644 --- a/README.md +++ b/README.md @@ -17,7 +17,7 @@ Create an Api Gateway to trigger lambda function. | Name | Version | |------|---------| -| [aws](#provider\_aws) | 6.58.0 | +| [aws](#provider\_aws) | >= 3.63 | ## Modules