Skip to main content

Versions

The Web App Blueprint pins OpenTofu 1.12.6, Terragrunt 1.1.6 and the Google provider ~> 8.5, follows the GKE Regular release channel from a minimum of Kubernetes 1.35, and runs Valkey 8.0. Every Helm chart, Python library, base image and GitHub Action is pinned to an exact version in the code, so a plan or a build means the same thing on every machine.

Where the pins live​

root.hcl generates the version file of every unit:

root.hcl
generate "versions" {
path = "versions.tf"
if_exists = "skip"
contents = <<-EOF
terraform {
required_version = ">= 1.12.6"
required_providers {
google = {
source = "hashicorp/google"
version = "~> 8.5"
}
}
}
EOF
}

A module ships its own versions.tf only when it needs a provider alias (google.dns, google.host, google.auto) or the Helm and Kubernetes providers, and then repeats the same Google pin. scripts/check-module-versions.py fails pre-commit and the plan workflow when the pins differ. No module needs google-beta, so it is neither pinned nor generated.

Tools and providers​

ComponentVersion
OpenTofu1.12.6 (root.hcl accepts >= 1.12.6, < 2.0.0)
Terragrunt1.1.6, checksum-verified in the workflows
Google provider~> 8.5
Helm provider~> 3.3
Kubernetes provider~> 3.2
tflint0.64.0, with tflint-ruleset-google 0.40.0
Checkov3.3.19 in pre-commit; bridgecrewio/checkov-action v12.3128.0 in the plan workflow

Platform versions​

ComponentVersion
Kubernetes on GKERegular release channel; minimum control-plane version 1.35 at creation, kept current by the channel
Node imageContainer-Optimized OS with containerd (COS_CONTAINERD)
Gateway APIStandard channel
Memorystore for ValkeyVALKEY_8_0
FirestoreEnterprise edition with MongoDB compatibility

Helm charts​

ChartVersionRepository
external-secrets2.11.0charts.external-secrets.io
external-dns1.23.0kubernetes-sigs.github.io/external-dns
cert-managerv1.21.2charts.jetstack.io
argo-cd10.9.6argoproj.github.io/argo-helm
blueprint-app (the application chart)0.1.0, app version 1.0.0The GitOps repository

cert-manager stays on its v1.21 line, which supports Kubernetes 1.33 to 1.36.

Application runtime​

ComponentVersion
API base imagepython:3.12.15-slim-trixie
Front end build imagenode:22.23.3-alpine3.24
Front end runtime imagenginxinc/nginx-unprivileged:1.30.5-alpine3.24
Python libraries (exact pins)Flask 3.1.3, flask-cors 6.0.5, Gunicorn 26.2.0, PyMongo 4.18.2, redis 8.1.0, google-auth 2.59.1, requests 2.34.2
Front endReact ^19.2.7, React Router ^7.17.0, axios ^1.17.0, Vite ^8.0.16, TypeScript ^6.0.3, installed from package-lock.json
CI toolsPython 3.12, Node.js 22, Ruff 0.16.10, pytest 9.1.1

The Python libraries are exact pins because each image is built once per merge and promoted unchanged, so every build of a commit resolves the same set.

GitHub Actions​

ActionVersion
actions/checkoutv7.0.1
actions/setup-pythonv7.0.0
actions/setup-nodev7.0.0
actions/create-github-app-tokenv3.2.0
actions/upload-artifactv7.0.1
actions/github-scriptv9.0.0
google-github-actions/authv3.0.0
google-github-actions/setup-gcloudv3.0.1
docker/setup-buildx-actionv4.4.1
docker/build-push-actionv7.4.0
aquasecurity/trivy-actionv0.36.0
opentofu/setup-opentofuv2.0.2
bridgecrewio/checkov-actionv12.3128.0

Each is referenced by its full commit SHA with the version in a comment, so a moved tag cannot change what runs.

How versions change​

A version change is its own pull request. For the infrastructure it is planned against all three stages before it merges; for the application it goes through the normal build and promotion path. The GKE control plane and nodes follow the release channel inside the maintenance window, so the minimum version in units/gke/terragrunt.hcl matters only when a cluster is created. The policy is on the versioning policy page, the services these versions belong to are on the service inventory, and the versions across all BuiltForProd repositories are in the release notes.