Some Alpine-based packages must be locked when building with terraform
Maintainers usually reply within 2 days
Nobody has claimed this yet.
Assessment
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Newbie friendliness
- 48/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- terraform
- Domain
- infrastructure
Research direction
Start by reproducing the Alpine package configuration with terraform apply and inspect .terraform/modules/latest.this/main.tf at line 72, where the Invalid index error is reported. Trace how unpinned packages are represented before that expression runs. Done means the configuration completes without the Invalid index errors while retaining package locking behavior.
Written by the indexing model from the issue text.
Description
With the following config (alpine-base):
contents:
packages:
- alpine-baselayout-data
- alpine-release
- apk-tools
- busybox
- libc-utils
on terraform apply, we get the following obscure error:
╷
│ Warning: unable to lock certain packages
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [alpine-release]
╵
╷
│ Warning: unable to lock certain packages for 386
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [libcrypto3 libssl3 musl musl-utils]
╵
╷
│ Warning: unable to lock certain packages for amd64
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [libcrypto3 libssl3 musl musl-utils]
╵
╷
│ Warning: unable to lock certain packages for arm/v6
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [libcrypto3 libssl3 musl musl-utils]
╵
╷
│ Warning: unable to lock certain packages for arm/v7
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [libcrypto3 libssl3 musl musl-utils]
╵
╷
│ Warning: unable to lock certain packages for arm64
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [libcrypto3 libssl3 musl musl-utils]
╵
╷
│ Warning: unable to lock certain packages for ppc64le
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [libcrypto3 libssl3 musl musl-utils]
╵
╷
│ Warning: unable to lock certain packages for riscv64
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [libcrypto3 libssl3 musl musl-utils]
╵
╷
│ Warning: unable to lock certain packages for s390x
│
│ with module.latest.module.this.data.apko_config.this,
│ on .terraform/modules/latest.this/main.tf line 17, in data "apko_config" "this":
│ 17: data "apko_config" "this" {
│
│ [libcrypto3 libssl3 musl musl-utils]
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
╷
│ Error: Invalid index
│
│ on .terraform/modules/latest.this/main.tf line 72, in resource "cosign_attest" "slsa-provenance":
│ 72: for k in data.apko_config.this.config.contents.packages : split("=", k)[0] => split("=", k)[1]
│
│ The given key does not identify an element in this collection value: the given index is greater than or equal to the length of the
│ collection.
╵
this is resolved by locking the package referred to in the error:
contents:
packages:
- alpine-baselayout-data
- alpine-release==3 # <--------
- apk-tools
- busybox
- libc-utils
- Dominant language
- HCL
- Stars
- 28
- Forks
- 25
- Avg merge
- 4d 31m
- Merged PRs (30d)
- 6
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from wolfi-dev/tools
-
bug needs-triage
Difficulty 3/5 1-2 days Newbie friendliness 35/100
Maintainers usually reply within 2 days
-
enhancement needs-triage
Difficulty 3/5 1-2 days Newbie friendliness 45/100
Maintainers usually reply within 2 days
-
Difficulty 3/5 1-2 days Newbie friendliness 45/100
Maintainers usually reply within 2 days
Similar issues
-
[quality] refresh-radar-reports.yml runs on ubuntu-latest while every other job pins ubuntu-24.04Openagent/quality hive/hosted-available-lke648397-260827-5n31 quality testing
Difficulty 1/5 1-3 hours Newbie friendliness 90/100
Maintainers usually reply within 1 day
-
CI enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
OpenZeppelin/compact-contracts#1048 ·
Maintainers usually reply within 1 day
-
cvss-severity:high devguard l3montree-cybersecurity/.../devguard-documentation pkg:oci/devguard-documen...ch=amd64&tag=main-amd64 risk:low state:open
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
l3montree-dev/devguard-documentation#315 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
cloudnative-pg/charts#1040 ·
Maintainers usually reply within 1 day
-
good first issue hacktoberfest
Difficulty 2/5 1-3 hours Newbie friendliness 92/100
elnachto/laya-triage#2 ·