Versions
The Web App Blueprint pins OpenTofu 1.12.6, Terragrunt 1.1.6 and the Google provider ~> 8.5, follows the GKE Regular release channel from a minimum of Kubernetes 1.35, and runs Valkey 8.0. Every Helm chart, Python library, base image and GitHub Action is pinned to an exact version in the code, so a plan or a build means the same thing on every machine.
Where the pins live
root.hcl generates the version file of every unit:
generate "versions" {
path = "versions.tf"
if_exists = "skip"
contents = <<-EOF
terraform {
required_version = ">= 1.12.6"
required_providers {
google = {
source = "hashicorp/google"
version = "~> 8.5"
}
}
}
EOF
}
A module ships its own versions.tf only when it needs a provider alias (google.dns, google.host, google.auto) or the Helm and Kubernetes providers, and then repeats the same Google pin. scripts/check-module-versions.py fails pre-commit and the plan workflow when the pins differ. No module needs google-beta, so it is neither pinned nor generated.
Tools and providers
| Component | Version |
|---|---|
| OpenTofu | 1.12.6 (root.hcl accepts >= 1.12.6, < 2.0.0) |
| Terragrunt | 1.1.6, checksum-verified in the workflows |
| Google provider | ~> 8.5 |
| Helm provider | ~> 3.3 |
| Kubernetes provider | ~> 3.2 |
| tflint | 0.64.0, with tflint-ruleset-google 0.40.0 |
| Checkov | 3.3.19 in pre-commit; bridgecrewio/checkov-action v12.3128.0 in the plan workflow |
Platform versions
| Component | Version |
|---|---|
| Kubernetes on GKE | Regular release channel; minimum control-plane version 1.35 at creation, kept current by the channel |
| Node image | Container-Optimized OS with containerd (COS_CONTAINERD) |
| Gateway API | Standard channel |
| Memorystore for Valkey | VALKEY_8_0 |
| Firestore | Enterprise edition with MongoDB compatibility |
Helm charts
| Chart | Version | Repository |
|---|---|---|
external-secrets | 2.11.0 | charts.external-secrets.io |
external-dns | 1.23.0 | kubernetes-sigs.github.io/external-dns |
cert-manager | v1.21.2 | charts.jetstack.io |
argo-cd | 10.9.6 | argoproj.github.io/argo-helm |
blueprint-app (the application chart) | 0.1.0, app version 1.0.0 | The GitOps repository |
cert-manager stays on its v1.21 line, which supports Kubernetes 1.33 to 1.36.
Application runtime
| Component | Version |
|---|---|
| API base image | python:3.12.15-slim-trixie |
| Front end build image | node:22.23.3-alpine3.24 |
| Front end runtime image | nginxinc/nginx-unprivileged:1.30.5-alpine3.24 |
| Python libraries (exact pins) | Flask 3.1.3, flask-cors 6.0.5, Gunicorn 26.2.0, PyMongo 4.18.2, redis 8.1.0, google-auth 2.59.1, requests 2.34.2 |
| Front end | React ^19.2.7, React Router ^7.17.0, axios ^1.17.0, Vite ^8.0.16, TypeScript ^6.0.3, installed from package-lock.json |
| CI tools | Python 3.12, Node.js 22, Ruff 0.16.10, pytest 9.1.1 |
The Python libraries are exact pins because each image is built once per merge and promoted unchanged, so every build of a commit resolves the same set.
GitHub Actions
| Action | Version |
|---|---|
actions/checkout | v7.0.1 |
actions/setup-python | v7.0.0 |
actions/setup-node | v7.0.0 |
actions/create-github-app-token | v3.2.0 |
actions/upload-artifact | v7.0.1 |
actions/github-script | v9.0.0 |
google-github-actions/auth | v3.0.0 |
google-github-actions/setup-gcloud | v3.0.1 |
docker/setup-buildx-action | v4.4.1 |
docker/build-push-action | v7.4.0 |
aquasecurity/trivy-action | v0.36.0 |
opentofu/setup-opentofu | v2.0.2 |
bridgecrewio/checkov-action | v12.3128.0 |
Each is referenced by its full commit SHA with the version in a comment, so a moved tag cannot change what runs.
How versions change
A version change is its own pull request. For the infrastructure it is planned against all three stages before it merges; for the application it goes through the normal build and promotion path. The GKE control plane and nodes follow the release channel inside the maintenance window, so the minimum version in units/gke/terragrunt.hcl matters only when a cluster is created. The policy is on the versioning policy page, the services these versions belong to are on the service inventory, and the versions across all BuiltForProd repositories are in the release notes.