Skip to main content

Versions

The Azure Baseline, release 1.0.0, pins every tool, provider, GitHub Action and pre-commit hook: OpenTofu 1.12.6, Terragrunt 1.1.6, hashicorp/azurerm ~> 5.7, hashicorp/azuread ~> 3.10 and Azure/azapi ~> 2.13. Engineers' machines, the CI workflows and the self-hosted runner image use the same versions, so a plan means the same thing everywhere.

Where the pins live​

root.hcl is the only place OpenTofu, Terragrunt and the three Azure providers are pinned. It generates the provider requirements into every unit:

root.hcl
generate "versions" {
path = "versions.tf"
if_exists = "skip"
contents = <<-EOF
terraform {
required_version = ">= 1.12.6"
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 5.7"
}
azuread = {
source = "hashicorp/azuread"
version = "~> 3.10"
}
azapi = {
source = "Azure/azapi"
version = "~> 2.13"
}
}
}
EOF
}

A module ships its own versions.tf only when it needs something root.hcl cannot know, and then repeats the three pins exactly. Two modules declare the azurerm.hub provider alias (vnet-peering, private-dns-links). Four use hashicorp/time ~> 0.13 to wait for role assignments to propagate before the first data-plane write (key-vault, platform-key-vault, storage-account, container-apps-runners). A guard script checks the rule in pre-commit and CI. The reasons are recorded in tooling and version pinning.

Tools and providers​

ComponentVersionWhere it is pinned
OpenTofu1.12.6root.hcl constraint >= 1.12.6, < 2.0.0; exact version in the plan, apply and drift-detection workflows and the runner image
Terragrunt1.1.6root.hcl constraint >= 1.1.6; exact, checksum-verified download in the same three workflows and the runner image
hashicorp/azurerm~> 5.7Generated by root.hcl into every unit
hashicorp/azuread~> 3.10Generated by root.hcl into every unit
Azure/azapi~> 2.13Generated by root.hcl into every unit
hashicorp/time~> 0.13The versions.tf of the four modules that wait for role propagation
tflintv0.64.0The plan workflow, checksum-verified
tflint-ruleset-azurerm0.32.0.tflint.hcl
Python3.12The guard scripts, with pyyaml
Azure CLI>= 2.75Operations from a workstation; 2.90.0 exactly in the runner image

Runner image​

The self-hosted runners start from runner-image/Dockerfile. Its base is ghcr.io/actions/actions-runner:2.337.0, pinned by tag and image digest together. The Azure CLI is one pinned release from Microsoft's signed package repository, and every other tool download is pinned by version and verified against its release SHA-256 checksum before it is installed:

ToolVersion
Azure CLI2.90.0
OpenTofu1.12.6
Terragrunt1.1.6
kubectlv1.36.5
kubeloginv0.2.20
Helmv3.22.0
sops3.13.3
yqv4.47.1

The build ends with a smoke test that runs every binary, so a broken download fails the image build rather than the first pipeline.

GitHub Actions​

ActionVersionWorkflows
actions/checkoutv7.0.1Plan, apply, drift detection, runner image
azure/loginv3.1.0Plan, apply, drift detection, runner image
opentofu/setup-opentofuv2.0.2Plan, apply, drift detection
actions/upload-artifactv7.0.1Plan, apply (run reports)
actions/github-scriptv9.0.0Plan (pull request comment), drift detection (issue)
bridgecrewio/checkov-actionv12.3128.0Plan
aquasecurity/trivy-actionv0.36.0Plan
infracost/actions/setupv4.2.0Plan (installs the Infracost CLI)
infracost/actions/commentv4.2.0Plan (posts the cost comment)

Each is referenced by its full commit SHA with the release tag in a trailing comment, so a moved tag cannot run different code. Terragrunt and tflint are not installed through an action: the workflows download the release binary and verify its checksum.

Pre-commit hooks​

Hook repositoryRevision
pre-commit/pre-commit-hooksv6.0.0
tofuutils/pre-commit-opentofuv2.4.2
antonbabenko/pre-commit-terraformv1.109.1
bridgecrewio/checkov3.3.19

The repository's six guard scripts run as local hooks beside these, and again in the plan workflow.

How versions change​

A version upgrade is its own pull request, reviewed as a plan before it merges. A provider upgrade changes root.hcl and every module versions.tf that repeats the pin in the same change. An OpenTofu or Terragrunt upgrade changes root.hcl, the plan, apply and drift-detection workflows, and the runner image's version and checksum together. The policy for each kind of change is on the versioning policy page, and the reasons for OpenTofu are in OpenTofu and Terraform.