Skip to main content

Versions

The GCP Baseline, release 1.0.0, pins every tool, provider, GitHub Action and image to an exact version: OpenTofu 1.12.6, Terragrunt 1.1.6, and the hashicorp/google and hashicorp/google-beta providers at ~> 8.5. The same versions run on engineers' machines and in CI, so a plan means the same thing everywhere.

Where the pins live​

root.hcl is the only place OpenTofu and the Google providers are pinned. It constrains the tool versions and writes the provider requirements into every unit Terragrunt generates:

root.hcl
# ─── Version Constraints ─────────────────────────────────────────────────────
terraform_version_constraint = ">= 1.12.6, < 2.0.0"
terragrunt_version_constraint = ">= 1.1.6"
root.hcl
generate "versions" {
path = "versions.tf"
if_exists = "skip"
contents = <<-EOF
terraform {
required_version = ">= 1.12.6"
required_providers {
google = {
source = "hashicorp/google"
version = "~> 8.5"
}
google-beta = {
source = "hashicorp/google-beta"
version = "~> 8.5"
}
}
}
EOF
}

The generated versions.tf is written with if_exists = "skip", so a module that ships its own version file replaces it. A module may do that only when it needs something root.hcl cannot know: a provider alias it declares in configuration_aliases, or a provider root.hcl does not pin. Three modules do, and each repeats the central pins exactly:

ModuleWhy it has its own versions.tf
github-runnershashicorp/helm ~> 3.3, and the google.host and google.artifacts aliases
log-alertsThe google.security alias: the alert policies live in core-security with the notification channel
shared-vpc-serviceThe google.host alias: the Shared VPC attachment is made on the host project

The guard script scripts/check-module-versions.py enforces the rule in pre-commit and CI: a module without aliases or extra providers must not have a version file, and one that has it must use the same required_version and the same constraint for every provider root.hcl pins.

Tools and providers​

ComponentVersionWhere it is pinned
OpenTofu1.12.6root.hcl constraint >= 1.12.6, < 2.0.0; exact version in every workflow
Terragrunt1.1.6root.hcl constraint >= 1.1.6; exact, checksum-verified download in every workflow
hashicorp/google~> 8.5Generated by root.hcl into every unit
hashicorp/google-beta~> 8.5Generated by root.hcl into every unit
hashicorp/helm~> 3.3modules/github-runners/versions.tf only
tflintv0.64.0The plan workflow
tflint-ruleset-google0.40.0.tflint.hcl
Checkov3.3.19.pre-commit-config.yaml; the plan workflow runs checkov-action v12.3128.0
Google Cloud CLI>= 540 with gke-gcloud-auth-pluginEngineers' machines (repository README)
sops3.13.3Engineers' machines (repository README)
Python3.12 with pyyaml and pre-commitThe guard scripts and pre-commit

Every module in the Baseline is custom and lives in the repository; no registry module is used, so there are no module versions to track.

GitHub Actions​

ActionVersionWorkflows
actions/checkoutv7.0.1Plan, apply, drift detection, both image builds
google-github-actions/authv3.0.0Plan, apply, drift detection, both image builds
opentofu/setup-opentofuv2.0.2Plan, apply, drift detection
actions/upload-artifactv7.0.1Plan, apply (run reports)
actions/github-scriptv9.0.0Plan (pull request comment), drift detection (issue)
bridgecrewio/checkov-actionv12.3128.0Plan

Each is referenced by its full commit SHA with the version in a trailing comment, so a moved tag cannot run different code.

Pre-commit hooks​

Hook repositoryRevision
pre-commit/pre-commit-hooksv6.0.0
tofuutils/pre-commit-opentofuv2.4.2
antonbabenko/pre-commit-terraformv1.109.1
bridgecrewio/checkov3.3.19

The repository's six guard scripts run as local hooks beside these.

Optional components​

The two optional components that run code of their own pin their versions too:

ComponentVersions
Self-hosted runnersActions Runner Controller charts 0.15.0; runner image from actions-runner 2.337.0 by digest, with OpenTofu 1.12.6, Terragrunt 1.1.6, Helm 3.22.0, kubectl 1.35.9 and Google Cloud CLI 587.0.0, each checksum-verified or from Google's signed repository
SCC notifierpython:3.13-slim by digest, Flask 3.1.3, gunicorn 26.2.0, google-cloud-storage 3.16.0

How versions change​

A version upgrade is its own change, reviewed as a plan before it merges. A provider upgrade changes root.hcl and the three module version files in the same pull request, and the tflint Google ruleset moves with the provider pin. The policy and the risk level per kind of change are on the versioning policy page, and the concepts behind the two tools are in OpenTofu and Terraform and Terragrunt units and stacks. Every Google Cloud service these versions drive is listed in the service inventory.