Bump configure-aws-credentials to v6 and dflook/terraform-* to v3 in the Terraform workflows
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Anfängerfreundlichkeit
- 76/100
- Issue-Typ
- Refactoring
- Klarheit
- Klar beschrieben
- Aktivitätsstatus
- Aktiv
- Tech-Stack
- github-actions, terraform
- Bereich
- ci-cd, cloud, devops, infrastructure
Rechercherichtung
Beginne mit dem Lesen von .github/workflows/terraform-plan.yaml und .github/workflows/terraform-apply.yaml und ermittle die relevanten uses:-Zeilen, statt dich auf Zeilennummern zu verlassen. Prüfe den Pfadfilter und stimme dich vor den Änderungen mit der zugehörigen OIDC- und checkout-Arbeit ab. Erledigt ist die Aufgabe, wenn sich nur die angegebenen Action-Pins ändern, eine No-op-Änderung an einer .tf-Datei einen leeren Plan erzeugt und der Apply nach dem Merge ohne eine Veraltungshinweis-Annotation für Node.js 20 erfolgreich ist.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
Overview
We need to bump aws-actions/configure-aws-credentials from @v4 to @v6 and dflook/terraform-plan/dflook/terraform-apply from @v1 to @v3 in both Terraform workflows, because configure-aws-credentials@v4 runs on the deprecated Node 20 and the dflook pins are four releases behind, including a fix for terraform-apply wrongly aborting on a plan that contains both imports and warnings.
Action Items
aws-actions/configure-aws-credentials — @v4 to @v6, 2 lines:
-
.github/workflows/terraform-plan.yaml:25and.github/workflows/terraform-apply.yaml:25. - Go to v6, not v4-for-parity and not v5. Reading
action.ymlat each tag: v3 = node16, v4 = node20, v5 = node20, v6 = node24. Only v6 clears the Node 20 deprecation. This repo was previously described as the "good" state that incubator's@v3should be brought up to — that was wrong,@v4here is deprecated too. - Note this is the opposite call from
actions/checkoutin hackforla/devops#183, which deliberately stops at v5 rather than going current. The two look inconsistent and are not: forcheckoutan intermediate version already reaches Node 24, and for this action nothing below v6 does.
dflook/terraform-plan and dflook/terraform-apply — @v1 to @v3, 2 lines:
-
terraform-plan.yaml:32(dflook/terraform-plan@v1) andterraform-apply.yaml:32(dflook/terraform-apply@v1). -
@v1is a floating tag, so this is less stale than it looks — it resolves to v1.49.0 (2025-05-29), not the 2021 release. Latest is v3.0.0 (2026-07-18). The honest framing is four missed releases, not "two majors behind". - The Node 20 deprecation does not apply to these two. Both are Docker actions (
runs: using: docker), so no JS runtime is involved. That is why going straight to current is fine here. - Checked before this ticket was written, so you do not have to: the only input removed across both majors is the deprecated
var:input (v2.0.0), and neither workflow uses it — they pass onlypath,backend_config_fileandauto_approve, all still present at v3.0.0. The real risk is the debian 11 → 12 → 13 base-image bump.
Out of scope — do not change these here:
-
actions/checkout@v4at line 23 of both files belongs to hackforla/devops#183. Leave it alone. If hackforla/devops#183's devops-security PR has already merged, rebase; if it has not, whoever merges second rebases. Same two files, adjacent lines.
Verification — read this before opening the PR, it is the awkward part:
- Both workflows filter on
paths: ['**/*.tf']only, so a PR that changes only.github/workflows/*.yamltriggers neither plan nor apply and shows no checks at all. That is expected, not a failure — and it means this change is not self-testing the way the equivalent incubator work (hackforla/incubator#158, hackforla/incubator#159) was. - To exercise the plan job in the same PR, include a no-op change to a
.tffile (a comment line). Treat an empty plan as a hard gate: if the plan shows any resource change, stop and raise it rather than merging. - After the PR merges,
terraform-apply.yamlruns a realterraform applyagainst AWS on push tomain. Confirm that run succeeds and carries no "Node.js 20 is deprecated" annotation. This cannot be checked from the branch.
Resources/Instructions
- Files (default branch is
main):.github/workflows/terraform-plan.yaml,.github/workflows/terraform-apply.yaml - Line numbers accurate 2026-08-27 and will drift — locate each pin by its
uses:line rather than by position. - Coordination with the OIDC work. There is an unticketed plan to move both workflows off static AWS credentials onto OIDC role assumption, which rewrites
configure-aws-credentials— the very line this ticket bumps. If that work starts before this is picked up, fold this in and close this issue as covered rather than editing the same lines twice. - Related: hackforla/devops#183 (
actions/checkoutin the same files), hackforla/incubator#158 (sameconfigure-aws-credentialsbump, already ticketed), hackforla/incubator#159 (samedflookbump, already ticketed).
- Vorherrschende Sprache
- HCL
- Sterne
- 1
- Forks
- 14
- Ø Merge
- 15 Min.
- Gemergte PRs (30 T.)
- 17
Entwicklungsumgebung
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus hackforla/devops-security
-
complexity: small feature: security role: DevOps Engineer size: 2pt
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
hackforla/devops-security#203 ·
Maintainer antworten meist innerhalb von 1 Tag
-
complexity: small feature: security good first issue role: DevOps Engineer size: 0.5pt
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 75/100
hackforla/devops-security#202 ·
Maintainer antworten meist innerhalb von 1 Tag
-
complexity: prework Feature: Onboarding/Contributing.md role: missing size: 1pt
Schwierigkeit 3/5 3-5 Tage Anfängerfreundlichkeit 40/100
hackforla/devops-security#200 ·
Maintainer antworten meist innerhalb von 1 Tag
-
Create new AWS User AccountEvtl. vergeben @Sbairamian hat das vor 10 Tagen übernommen. Offencomplexity: small feature: AWS user request role: DevOps Engineer size: 1pt
hackforla/devops-security#198 · 1 zugewiesene Person ·
Maintainer antworten meist innerhalb von 1 Tag
-
Pre-work Checklist: DevOps-Security-Member: [Sevag Bairamian]Evtl. vergeben @Sbairamian hat das vor 10 Tagen übernommen. Offencomplexity: prework Feature: Onboarding/Contributing.md role: DevOps Engineer role: missing size: 1pt
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 45/100
hackforla/devops-security#195 · 1 zugewiesene Person ·
Maintainer antworten meist innerhalb von 1 Tag
Alle Issues in hackforla/devops-security
Ähnliche Issues
-
Schwierigkeit 1/5 Unter einer Stunde Anfängerfreundlichkeit 92/100
yegor256/copyrights-action#216 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 70/100
droidconKE/droidconKE2022Web#164 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
[Bug]: avm-ptn-alz-connectivity-hub-and-spoke-vnet not setting location within security_policyOffenNeeds: Triage :mag: Product: Terraform (AVM) Topic: Networking (HS) :globe_with_meridians:
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
Azure/Azure-Landing-Zones#4291 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 4 Tagen
-
bot-found bug priority: P3
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
madenvel/KalinkaPlayer#179 ·
-
Schwierigkeit 1/5 1-3 Stunden Anfängerfreundlichkeit 94/100
makeplane/helm-charts#332 ·
Maintainer antworten meist innerhalb von 1 Tag