Bump configure-aws-credentials to v6 and dflook/terraform-* to v3 in the Terraform workflows
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 2/5
- 预计耗时
- 1-3 小时
- 新手友好度
- 76/100
- Issue 类型
- 重构
- 描述清晰度
- 描述清楚
- 活跃度
- 活跃
- 技术栈
- github-actions, terraform
- 领域
- ci-cd, cloud, devops, infrastructure
调研方向
首先阅读 .github/workflows/terraform-plan.yaml 和 .github/workflows/terraform-apply.yaml,通过定位相关的 uses: 行而不是依赖行号。编辑前检查路径过滤器,并与相关的 OIDC 和 checkout 工作协调。完成的标准是只有指定 action 的 pin 发生变化,无操作的 .tf 更改会生成空 plan,并且合并后的 apply 成功且没有 Node.js 20 弃用注释。
由索引模型根据 Issue 内容生成。
描述
Overview
We need to bump aws-actions/configure-aws-credentials from @v4 to @v6 and dflook/terraform-plan/dflook/terraform-apply from @v1 to @v3 in both Terraform workflows, because configure-aws-credentials@v4 runs on the deprecated Node 20 and the dflook pins are four releases behind, including a fix for terraform-apply wrongly aborting on a plan that contains both imports and warnings.
Action Items
aws-actions/configure-aws-credentials — @v4 to @v6, 2 lines:
-
.github/workflows/terraform-plan.yaml:25and.github/workflows/terraform-apply.yaml:25. - Go to v6, not v4-for-parity and not v5. Reading
action.ymlat each tag: v3 = node16, v4 = node20, v5 = node20, v6 = node24. Only v6 clears the Node 20 deprecation. This repo was previously described as the "good" state that incubator's@v3should be brought up to — that was wrong,@v4here is deprecated too. - Note this is the opposite call from
actions/checkoutin hackforla/devops#183, which deliberately stops at v5 rather than going current. The two look inconsistent and are not: forcheckoutan intermediate version already reaches Node 24, and for this action nothing below v6 does.
dflook/terraform-plan and dflook/terraform-apply — @v1 to @v3, 2 lines:
-
terraform-plan.yaml:32(dflook/terraform-plan@v1) andterraform-apply.yaml:32(dflook/terraform-apply@v1). -
@v1is a floating tag, so this is less stale than it looks — it resolves to v1.49.0 (2025-05-29), not the 2021 release. Latest is v3.0.0 (2026-07-18). The honest framing is four missed releases, not "two majors behind". - The Node 20 deprecation does not apply to these two. Both are Docker actions (
runs: using: docker), so no JS runtime is involved. That is why going straight to current is fine here. - Checked before this ticket was written, so you do not have to: the only input removed across both majors is the deprecated
var:input (v2.0.0), and neither workflow uses it — they pass onlypath,backend_config_fileandauto_approve, all still present at v3.0.0. The real risk is the debian 11 → 12 → 13 base-image bump.
Out of scope — do not change these here:
-
actions/checkout@v4at line 23 of both files belongs to hackforla/devops#183. Leave it alone. If hackforla/devops#183's devops-security PR has already merged, rebase; if it has not, whoever merges second rebases. Same two files, adjacent lines.
Verification — read this before opening the PR, it is the awkward part:
- Both workflows filter on
paths: ['**/*.tf']only, so a PR that changes only.github/workflows/*.yamltriggers neither plan nor apply and shows no checks at all. That is expected, not a failure — and it means this change is not self-testing the way the equivalent incubator work (hackforla/incubator#158, hackforla/incubator#159) was. - To exercise the plan job in the same PR, include a no-op change to a
.tffile (a comment line). Treat an empty plan as a hard gate: if the plan shows any resource change, stop and raise it rather than merging. - After the PR merges,
terraform-apply.yamlruns a realterraform applyagainst AWS on push tomain. Confirm that run succeeds and carries no "Node.js 20 is deprecated" annotation. This cannot be checked from the branch.
Resources/Instructions
- Files (default branch is
main):.github/workflows/terraform-plan.yaml,.github/workflows/terraform-apply.yaml - Line numbers accurate 2026-08-27 and will drift — locate each pin by its
uses:line rather than by position. - Coordination with the OIDC work. There is an unticketed plan to move both workflows off static AWS credentials onto OIDC role assumption, which rewrites
configure-aws-credentials— the very line this ticket bumps. If that work starts before this is picked up, fold this in and close this issue as covered rather than editing the same lines twice. - Related: hackforla/devops#183 (
actions/checkoutin the same files), hackforla/incubator#158 (sameconfigure-aws-credentialsbump, already ticketed), hackforla/incubator#159 (samedflookbump, already ticketed).
- 主要语言
- HCL
- 星标
- 1
- 派生
- 14
- 平均合并
- 3 小时 36 分钟
- 30 天内合并 PR
- 14
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
hackforla/devops-security 的其他 Issue
-
complexity: small feature: security role: DevOps Engineer size: 2pt
难度 2/5 1-3 小时 新手友好度 75/100
hackforla/devops-security#203 ·
维护者通常 1 天内回复
-
complexity: small feature: security good first issue role: DevOps Engineer size: 0.5pt
难度 2/5 1-3 小时 新手友好度 75/100
hackforla/devops-security#202 ·
维护者通常 1 天内回复
-
complexity: medium feature: maintenance role: DevOps Engineer size: 3pt
难度 4/5 3-5 天 新手友好度 52/100
hackforla/devops-security#208 ·
维护者通常 1 天内回复
-
New user for mike waggoner可能已有人在做 @here 于 4 天前认领。 未关闭complexity: small feature: AWS user request role: DevOps Engineer size: 1pt
hackforla/devops-security#205 · 2 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
-
Pre-work Checklist: DevOps-Security-Member: here mike waggoner可能已有人在做 @here 于 4 天前认领。 未关闭complexity: prework Feature: Onboarding/Contributing.md role: DevOps Engineer size: 1pt
hackforla/devops-security#204 · 3 条评论 · 已指派 1 人 ·
维护者通常 1 天内回复
查看 hackforla/devops-security 的全部 Issue
相似的 Issue
-
bug customer-reported
难度 2/5 1-3 小时 新手友好度 82/100
MagnaCapax/PMSS#1011 ·
维护者通常 5 天内回复
-
[CI] Core CI doesn't run for changes to amoro-format-lance (and amoro-web)可能已有人在做 @MarkAlex1234 今天认领。 未关闭
难度 1/5 1 小时以内 新手友好度 88/100
维护者通常 2 天内回复
-
area/infra theme/ci-dx
难度 2/5 1-3 小时 新手友好度 78/100
维护者通常 1 天内回复
-
tech debt
难度 2/5 1-3 小时 新手友好度 74/100
TAMULib/fw-registry#543 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 72/100
code-yeongyu/senpi#2782 · 1 条评论 ·
维护者通常 1 天内回复