Versions
The GCP Baseline, release 1.0.0, pins every tool, provider, GitHub Action and image to an exact version: OpenTofu 1.12.6, Terragrunt 1.1.6, and the hashicorp/google and hashicorp/google-beta providers at ~> 8.5. The same versions run on engineers' machines and in CI, so a plan means the same thing everywhere.
Where the pins live
root.hcl is the only place OpenTofu and the Google providers are pinned. It constrains the tool versions and writes the provider requirements into every unit Terragrunt generates:
# ─── Version Constraints ─────────────────────────────────────────────────────
terraform_version_constraint = ">= 1.12.6, < 2.0.0"
terragrunt_version_constraint = ">= 1.1.6"
generate "versions" {
path = "versions.tf"
if_exists = "skip"
contents = <<-EOF
terraform {
required_version = ">= 1.12.6"
required_providers {
google = {
source = "hashicorp/google"
version = "~> 8.5"
}
google-beta = {
source = "hashicorp/google-beta"
version = "~> 8.5"
}
}
}
EOF
}
The generated versions.tf is written with if_exists = "skip", so a module that ships its own version file replaces it. A module may do that only when it needs something root.hcl cannot know: a provider alias it declares in configuration_aliases, or a provider root.hcl does not pin. Three modules do, and each repeats the central pins exactly:
| Module | Why it has its own versions.tf |
|---|---|
github-runners | hashicorp/helm ~> 3.3, and the google.host and google.artifacts aliases |
log-alerts | The google.security alias: the alert policies live in core-security with the notification channel |
shared-vpc-service | The google.host alias: the Shared VPC attachment is made on the host project |
The guard script scripts/check-module-versions.py enforces the rule in pre-commit and CI: a module without aliases or extra providers must not have a version file, and one that has it must use the same required_version and the same constraint for every provider root.hcl pins.
Tools and providers
| Component | Version | Where it is pinned |
|---|---|---|
| OpenTofu | 1.12.6 | root.hcl constraint >= 1.12.6, < 2.0.0; exact version in every workflow |
| Terragrunt | 1.1.6 | root.hcl constraint >= 1.1.6; exact, checksum-verified download in every workflow |
hashicorp/google | ~> 8.5 | Generated by root.hcl into every unit |
hashicorp/google-beta | ~> 8.5 | Generated by root.hcl into every unit |
hashicorp/helm | ~> 3.3 | modules/github-runners/versions.tf only |
| tflint | v0.64.0 | The plan workflow |
tflint-ruleset-google | 0.40.0 | .tflint.hcl |
| Checkov | 3.3.19 | .pre-commit-config.yaml; the plan workflow runs checkov-action v12.3128.0 |
| Google Cloud CLI | >= 540 with gke-gcloud-auth-plugin | Engineers' machines (repository README) |
| sops | 3.13.3 | Engineers' machines (repository README) |
| Python | 3.12 with pyyaml and pre-commit | The guard scripts and pre-commit |
Every module in the Baseline is custom and lives in the repository; no registry module is used, so there are no module versions to track.
GitHub Actions
| Action | Version | Workflows |
|---|---|---|
actions/checkout | v7.0.1 | Plan, apply, drift detection, both image builds |
google-github-actions/auth | v3.0.0 | Plan, apply, drift detection, both image builds |
opentofu/setup-opentofu | v2.0.2 | Plan, apply, drift detection |
actions/upload-artifact | v7.0.1 | Plan, apply (run reports) |
actions/github-script | v9.0.0 | Plan (pull request comment), drift detection (issue) |
bridgecrewio/checkov-action | v12.3128.0 | Plan |
Each is referenced by its full commit SHA with the version in a trailing comment, so a moved tag cannot run different code.
Pre-commit hooks
| Hook repository | Revision |
|---|---|
pre-commit/pre-commit-hooks | v6.0.0 |
tofuutils/pre-commit-opentofu | v2.4.2 |
antonbabenko/pre-commit-terraform | v1.109.1 |
bridgecrewio/checkov | 3.3.19 |
The repository's six guard scripts run as local hooks beside these.
Optional components
The two optional components that run code of their own pin their versions too:
| Component | Versions |
|---|---|
| Self-hosted runners | Actions Runner Controller charts 0.15.0; runner image from actions-runner 2.337.0 by digest, with OpenTofu 1.12.6, Terragrunt 1.1.6, Helm 3.22.0, kubectl 1.35.9 and Google Cloud CLI 587.0.0, each checksum-verified or from Google's signed repository |
| SCC notifier | python:3.13-slim by digest, Flask 3.1.3, gunicorn 26.2.0, google-cloud-storage 3.16.0 |
How versions change
A version upgrade is its own change, reviewed as a plan before it merges. A provider upgrade changes root.hcl and the three module version files in the same pull request, and the tflint Google ruleset moves with the provider pin. The policy and the risk level per kind of change are on the versioning policy page, and the concepts behind the two tools are in OpenTofu and Terraform and Terragrunt units and stacks. Every Google Cloud service these versions drive is listed in the service inventory.