tofu

package
v0.48.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 22 Imported by: 0

Documentation

Overview

Package tofu provides OpenTofu execution capabilities.

Index

Constants

View Source
const (
	ProvidersDirEnv             = "STACKKIT_TOFU_PROVIDERS_DIR"
	ProvidersDirName            = "providers"
	ProviderRegistryHost        = "registry.opentofu.org"
	PinnedLocalProviderVersion  = "2.5.3"
	PinnedKomodoProviderVersion = "0.12.0"
	ProviderManifestFile        = "stackkit-provider-manifest.json"
	ProviderLockFile            = "stackkit-provider-lock.hcl"
)

Variables

View Source
var (
	ErrProviderMirrorMissing  = errors.New("packaged OpenTofu provider mirror is missing")
	ErrProviderClosureInvalid = errors.New("packaged OpenTofu provider closure is invalid")
)
View Source
var OfflineInheritedEnv = []string{
	"TF_PLUGIN_CACHE_DIR", "TF_PLUGIN_CACHE_MAY_BREAK_DEPENDENCY_LOCK_FILE",
	"TF_CLI_CONFIG_FILE", "TF_CLI_ARGS", "TF_CLI_ARGS_init", "TF_CLI_ARGS_plan", "TF_CLI_ARGS_apply",
	"TF_DATA_DIR", "TF_ENCRYPTION", "TF_WORKSPACE", "TOFU_CLI_CONFIG_FILE",
}

Functions

func BinaryName

func BinaryName() string

BinaryName returns the OpenTofu executable name for the current platform.

func CanonicalLockForConfiguration added in v0.47.7

func CanonicalLockForConfiguration(config []byte) ([]byte, error)

CanonicalLockForConfiguration supplies the exact root lock for a signed legacy checkpoint that predates lock capture.

func CanonicalProviderManifest added in v0.47.7

func CanonicalProviderManifest() []byte

func DefaultBinary

func DefaultBinary() string

DefaultBinary resolves the OpenTofu binary used by regular execution. It intentionally avoids PATH fallback so a host-installed OpenTofu cannot make StackKit appear release-ready when the package is missing its own copy.

func EnsureStateDir

func EnsureStateDir(baseDir string) error

EnsureStateDir ensures the state directory exists

func HasTerraformFiles

func HasTerraformFiles(dir string) (bool, error)

HasTerraformFiles checks if directory contains .tf files

func IsTimeoutError

func IsTimeoutError(err error) bool

IsTimeoutError checks if an error is a timeout error

func OfflineCLIConfig added in v0.46.5

func OfflineCLIConfig(providersDir string) []byte

OfflineCLIConfig declares only the filesystem mirror, leaving no direct installer method with which OpenTofu could contact a registry.

func PackagedBinaryPath

func PackagedBinaryPath() (string, bool)

PackagedBinaryPath returns the StackKit-packaged OpenTofu binary path. It intentionally does not fall back to PATH: product and release tests must prove that OpenTofu ships with StackKit, not that the host happens to have it.

func PackagedProvidersDir added in v0.46.5

func PackagedProvidersDir() (string, bool)

func PrepareProviderClosure added in v0.47.7

func PrepareProviderClosure(dir, targetOS, targetArch string, archives map[string]string) error

PrepareProviderClosure is the release packaging boundary. It admits only the committed manifest, verifies every upstream archive and unpacked package, and writes the deterministic lock shipped in the same provider directory.

func RequireLocalProviderMirror added in v0.46.5

func RequireLocalProviderMirror(dir string) error

func StateEncryptionConfig added in v0.47.7

func StateEncryptionConfig(key []byte, migration bool) string

StateEncryptionConfig supplies the common owner-bound state and plan policy. Plaintext fallback is permitted only for the isolated legacy migration.

func ValidateWorkDir

func ValidateWorkDir(dir string) error

ValidateWorkDir validates the working directory

Types

type Executor

type Executor struct {
	// contains filtered or unexported fields
}

Executor handles OpenTofu command execution

func NewExecutor

func NewExecutor(opts ...ExecutorOption) *Executor

NewExecutor creates a new OpenTofu executor

func (*Executor) Apply

func (e *Executor) Apply(ctx context.Context, planFile string) (*Result, error)

Apply runs tofu apply

func (*Executor) Destroy

func (e *Executor) Destroy(ctx context.Context) (*Result, error)

Destroy runs tofu destroy

func (*Executor) Format

func (e *Executor) Format(ctx context.Context) (*Result, error)

Format runs tofu fmt to format configuration files

func (*Executor) GetWorkDir

func (e *Executor) GetWorkDir() string

GetWorkDir returns the working directory

func (*Executor) Graph

func (e *Executor) Graph(ctx context.Context) (*Result, error)

Graph generates a visual graph of resources

func (*Executor) Import

func (e *Executor) Import(ctx context.Context, address, id string) (*Result, error)

Import imports an existing resource into state

func (*Executor) Init

func (e *Executor) Init(ctx context.Context) (*Result, error)

Init runs tofu init

func (*Executor) InitReadonly added in v0.47.7

func (e *Executor) InitReadonly(ctx context.Context) (*Result, error)

InitReadonly initializes a materialized StackKit root without allowing OpenTofu to create or mutate its packaged dependency lock.

func (*Executor) IsInstalled

func (e *Executor) IsInstalled() bool

IsInstalled checks if tofu is installed

func (*Executor) Output

func (e *Executor) Output(ctx context.Context) (*Result, error)

Output runs tofu output and returns the outputs

func (*Executor) Plan

func (e *Executor) Plan(ctx context.Context, outFile string, destroy bool) (*Result, error)

Plan runs tofu plan

func (*Executor) Providers

func (e *Executor) Providers(ctx context.Context) (*Result, error)

Providers shows required providers

func (*Executor) Refresh

func (e *Executor) Refresh(ctx context.Context) (*Result, error)

Refresh runs tofu refresh to sync state with real infrastructure

func (*Executor) SetAutoApprove

func (e *Executor) SetAutoApprove(autoApprove bool)

SetAutoApprove sets the auto-approve flag dynamically

func (*Executor) SetWorkDir

func (e *Executor) SetWorkDir(dir string)

SetWorkDir sets the working directory

func (*Executor) Show

func (e *Executor) Show(ctx context.Context, planFile string) (*Result, error)

Show runs tofu show on a plan file

func (*Executor) State

func (e *Executor) State(ctx context.Context) (*Result, error)

State returns the current state

func (*Executor) StatePush added in v0.47.7

func (e *Executor) StatePush(ctx context.Context, state io.Reader) (*Result, error)

StatePush imports plaintext state from memory and lets the configured backend persist it. Callers use this to migrate a local state atomically without ever staging the plaintext payload in a file.

func (*Executor) Taint

func (e *Executor) Taint(ctx context.Context, address string) (*Result, error)

Taint marks a resource for recreation

func (*Executor) Untaint

func (e *Executor) Untaint(ctx context.Context, address string) (*Result, error)

Untaint removes the taint from a resource

func (*Executor) Validate

func (e *Executor) Validate(ctx context.Context) (*Result, error)

Validate runs tofu validate

func (*Executor) Version

func (e *Executor) Version(ctx context.Context) (string, error)

Version returns the tofu version

type ExecutorOption

type ExecutorOption func(*Executor)

ExecutorOption configures the Executor

func WithAutoApprove

func WithAutoApprove(autoApprove bool) ExecutorOption

WithAutoApprove enables auto-approve for apply/destroy

func WithBinary

func WithBinary(binary string) ExecutorOption

WithBinary sets the tofu binary path

func WithEnv

func WithEnv(values ...string) ExecutorOption

WithEnv appends environment values for OpenTofu commands.

func WithTimeout

func WithTimeout(timeout time.Duration) ExecutorOption

WithTimeout sets the execution timeout

func WithWorkDir

func WithWorkDir(dir string) ExecutorOption

WithWorkDir sets the working directory

func WithoutEnvPrefix added in v0.47.7

func WithoutEnvPrefix(prefixes ...string) ExecutorOption

WithoutEnvPrefix prevents diagnostic controls from persisting secret-bearing process data. It filters both inherited and explicitly supplied variables.

func WithoutInheritedEnv added in v0.46.5

func WithoutInheritedEnv(names ...string) ExecutorOption

WithoutInheritedEnv drops the named variables from the inherited process environment before WithEnv values are appended. It lets a caller guarantee, for example, that no host plugin cache or CLI argument override reaches an offline OpenTofu run.

type PlanChanges

type PlanChanges struct {
	Add     int
	Change  int
	Destroy int
}

PlanChanges represents changes detected by plan

func ParsePlanOutput

func ParsePlanOutput(output string) *PlanChanges

ParsePlanOutput parses plan output to extract changes

type ProviderClosure added in v0.47.7

type ProviderClosure struct {
	// contains filtered or unexported fields
}

ProviderClosure is a validated packaged provider mirror and dependency lock. Its fields stay private so callers cannot construct authority without first validating the bundle metadata and current-platform package.

func LoadProviderClosure added in v0.47.7

func LoadProviderClosure(dir string) (*ProviderClosure, error)

LoadProviderClosure validates the manifest, lock, and every package for the running platform before a tofu process can execute. Release archive trust authenticates the manifest; this closes its hashes over installed bytes.

func (*ProviderClosure) Directory added in v0.47.7

func (c *ProviderClosure) Directory() string

func (*ProviderClosure) LockForConfiguration added in v0.47.7

func (c *ProviderClosure) LockForConfiguration(config []byte) ([]byte, error)

LockForConfiguration selects only the providers declared by this root. Provider-free terraform_data roots receive an empty lock.

type Result

type Result struct {
	Success  bool
	ExitCode int
	Stdout   string
	Stderr   string
	Duration time.Duration
}

Result represents the result of a tofu command

type TimeoutError

type TimeoutError struct {
	Command  string
	Duration time.Duration
}

TimeoutError represents a command timeout

func (*TimeoutError) Error

func (e *TimeoutError) Error() string

Directories

Path Synopsis
cmd
providerclosure command

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL