Skip to main content

Versions

The Data and ETL Blueprint pins the same tools as the GCP Enterprise Baseline (OpenTofu 1.12.6, Terragrunt 1.1.6, the google and google-beta providers at ~> 8.5), runs its Spark batches on the Dataproc Serverless 2.3 runtime (Spark 3.5, Python 3.11) and its trigger on Python 3.12. Every Python package, pre-commit hook and GitHub Action is pinned to an exact version in the code, so a plan or a build means the same thing on every machine.

Where the pins live​

root.hcl pins OpenTofu, Terragrunt and both Google providers for every unit:

root.hcl
# ─── Version Constraints ─────────────────────────────────────────────────────
terraform_version_constraint = ">= 1.12.6, < 2.0.0"
terragrunt_version_constraint = ">= 1.1.6"
root.hcl
generate "versions" {
path = "versions.tf"
if_exists = "skip"
contents = <<-EOF
terraform {
required_version = ">= 1.12.6"
required_providers {
google = {
source = "hashicorp/google"
version = "~> 8.5"
}
google-beta = {
source = "hashicorp/google-beta"
version = "~> 8.5"
}
}
}
EOF
}

No ETL module ships its own version file, so every unit uses exactly those pins. A module may add one only to declare provider aliases, and must then repeat the same pins: the guard script scripts/check-module-versions.py enforces it in pre-commit and in the plan workflow.

Tools and providers​

ComponentVersion
OpenTofu1.12.6 (up to, not including, 2.0.0)
Terragrunt1.1.6 or later
google provider~> 8.5
google-beta provider~> 8.5
tflint0.64.0
tflint Google ruleset0.40.0

The plan, apply and drift-detection workflows install exactly OpenTofu 1.12.6 and Terragrunt 1.1.6, with the Terragrunt and tflint binaries checked against their release checksums.

Platform versions​

ComponentVersionSet in
Dataproc Serverless runtime2.3 (Spark 3.5, Python 3.11), the same in every stagespark_runtime_version in each stage stack file
Trigger base imagepython:3.12-slim, non-root user 10001src/trigger/Dockerfile
Spark BigQuery connectorThe one bundled with the runtimeNot pinned separately; catalog mode uses writeMethod=direct

The runtime is a stage value, spark_runtime_version = "2.3", which the trigger passes to every batch it submits. Changing it is a change to the stage file, and the Spark test versions in ci.yml move with it.

Application runtime​

ComponentVersion
Trigger Python3.12 (image and CI)
Flask3.1.3
Gunicorn26.2.0
google-cloud-dataproc5.31.0
Spark script Python3.11 (the runtime's interpreter)
PySpark and Java for the Spark tests in CIPySpark 3.5.3, Java 17
requires-python>= 3.11 (pyproject.toml); code stays valid on both
Ruff0.16.10, target py311, line length 120
pytest9.1.1

The trigger's packages are pinned exactly in src/trigger/requirements.txt, because the image is built once per merge and promoted unchanged.

Pre-commit hooks​

Hook sourceVersionRepository
pre-commit/pre-commit-hooksv6.0.0Both
tofuutils/pre-commit-opentofuv2.4.2Infrastructure
antonbabenko/pre-commit-terraformv1.109.1Infrastructure
bridgecrewio/checkov3.3.19Infrastructure
bridgecrewio/checkov3.3.22Code
astral-sh/ruff-pre-commitv0.16.10Code
rhysd/actionlintv1.7.12Code
shellcheck-py/shellcheck-pyv0.11.0.1Code

The infrastructure repository adds four local hooks that run its guard scripts.

GitHub Actions​

ActionVersion
actions/checkoutv7.0.1
actions/setup-pythonv7.0.0
actions/setup-javav6.0.1
actions/upload-artifactv7.0.1
actions/github-scriptv9.0.0
google-github-actions/authv3.0.0
google-github-actions/setup-gcloudv3.0.1
docker/setup-buildx-actionv4.4.1
docker/build-push-actionv7.4.0
aquasecurity/trivy-actionv0.36.0
bridgecrewio/checkov-actionv12.3128.0
opentofu/setup-opentofuv2.0.2

Each is referenced by its full commit SHA with the version in a comment, so a moved tag cannot change what runs.

How versions change​

A version change is its own pull request. For the infrastructure it is planned against all three stages before it merges; for the code it goes through the normal build and release path. The policy is on the versioning policy page, the Baseline's own pins are on the Baseline versions page, and the version matrix lines up every repository's pins.