Documentation
¶
Overview ¶
Package tofu provides OpenTofu execution capabilities.
Index ¶
- Constants
- Variables
- func BinaryName() string
- func CanonicalLockForConfiguration(config []byte) ([]byte, error)
- func CanonicalProviderManifest() []byte
- func DefaultBinary() string
- func EnsureStateDir(baseDir string) error
- func HasTerraformFiles(dir string) (bool, error)
- func IsTimeoutError(err error) bool
- func OfflineCLIConfig(providersDir string) []byte
- func PackagedBinaryPath() (string, bool)
- func PackagedProvidersDir() (string, bool)
- func PrepareProviderClosure(dir, targetOS, targetArch, archive string) error
- func RequireLocalProviderMirror(dir string) error
- func StateEncryptionConfig(key []byte, migration bool) string
- func ValidateWorkDir(dir string) error
- type Executor
- func (e *Executor) Apply(ctx context.Context, planFile string) (*Result, error)
- func (e *Executor) Destroy(ctx context.Context) (*Result, error)
- func (e *Executor) Format(ctx context.Context) (*Result, error)
- func (e *Executor) GetWorkDir() string
- func (e *Executor) Graph(ctx context.Context) (*Result, error)
- func (e *Executor) Import(ctx context.Context, address, id string) (*Result, error)
- func (e *Executor) Init(ctx context.Context) (*Result, error)
- func (e *Executor) InitReadonly(ctx context.Context) (*Result, error)
- func (e *Executor) IsInstalled() bool
- func (e *Executor) Output(ctx context.Context) (*Result, error)
- func (e *Executor) Plan(ctx context.Context, outFile string, destroy bool) (*Result, error)
- func (e *Executor) Providers(ctx context.Context) (*Result, error)
- func (e *Executor) Refresh(ctx context.Context) (*Result, error)
- func (e *Executor) SetAutoApprove(autoApprove bool)
- func (e *Executor) SetWorkDir(dir string)
- func (e *Executor) Show(ctx context.Context, planFile string) (*Result, error)
- func (e *Executor) State(ctx context.Context) (*Result, error)
- func (e *Executor) StatePush(ctx context.Context, state io.Reader) (*Result, error)
- func (e *Executor) Taint(ctx context.Context, address string) (*Result, error)
- func (e *Executor) Untaint(ctx context.Context, address string) (*Result, error)
- func (e *Executor) Validate(ctx context.Context) (*Result, error)
- func (e *Executor) Version(ctx context.Context) (string, error)
- type ExecutorOption
- func WithAutoApprove(autoApprove bool) ExecutorOption
- func WithBinary(binary string) ExecutorOption
- func WithEnv(values ...string) ExecutorOption
- func WithTimeout(timeout time.Duration) ExecutorOption
- func WithWorkDir(dir string) ExecutorOption
- func WithoutEnvPrefix(prefixes ...string) ExecutorOption
- func WithoutInheritedEnv(names ...string) ExecutorOption
- type PlanChanges
- type ProviderClosure
- type Result
- type TimeoutError
Constants ¶
const ( ProvidersDirEnv = "STACKKIT_TOFU_PROVIDERS_DIR" ProvidersDirName = "providers" ProviderRegistryHost = "registry.opentofu.org" PinnedLocalProviderVersion = "2.5.3" ProviderManifestFile = "stackkit-provider-manifest.json" ProviderLockFile = "stackkit-provider-lock.hcl" )
Variables ¶
var ( ErrProviderMirrorMissing = errors.New("packaged OpenTofu provider mirror is missing") ErrProviderClosureInvalid = errors.New("packaged OpenTofu provider closure is invalid") )
var OfflineInheritedEnv = []string{
"TF_PLUGIN_CACHE_DIR", "TF_PLUGIN_CACHE_MAY_BREAK_DEPENDENCY_LOCK_FILE",
"TF_CLI_CONFIG_FILE", "TF_CLI_ARGS", "TF_CLI_ARGS_init", "TF_CLI_ARGS_plan", "TF_CLI_ARGS_apply",
"TF_DATA_DIR", "TF_ENCRYPTION", "TF_WORKSPACE", "TOFU_CLI_CONFIG_FILE",
}
Functions ¶
func BinaryName ¶
func BinaryName() string
BinaryName returns the OpenTofu executable name for the current platform.
func CanonicalLockForConfiguration ¶ added in v0.47.7
CanonicalLockForConfiguration supplies the exact root lock for a signed legacy checkpoint that predates lock capture.
func CanonicalProviderManifest ¶ added in v0.47.7
func CanonicalProviderManifest() []byte
func DefaultBinary ¶
func DefaultBinary() string
DefaultBinary resolves the OpenTofu binary used by regular execution. It intentionally avoids PATH fallback so a host-installed OpenTofu cannot make StackKit appear release-ready when the package is missing its own copy.
func EnsureStateDir ¶
EnsureStateDir ensures the state directory exists
func HasTerraformFiles ¶
HasTerraformFiles checks if directory contains .tf files
func IsTimeoutError ¶
IsTimeoutError checks if an error is a timeout error
func OfflineCLIConfig ¶ added in v0.46.5
OfflineCLIConfig declares only the filesystem mirror, leaving no direct installer method with which OpenTofu could contact a registry.
func PackagedBinaryPath ¶
PackagedBinaryPath returns the StackKit-packaged OpenTofu binary path. It intentionally does not fall back to PATH: product and release tests must prove that OpenTofu ships with StackKit, not that the host happens to have it.
func PackagedProvidersDir ¶ added in v0.46.5
func PrepareProviderClosure ¶ added in v0.47.7
PrepareProviderClosure is the release packaging boundary. It admits only the committed manifest, verifies the upstream archive plus unpacked package, and writes the deterministic lock shipped in the same provider directory.
func RequireLocalProviderMirror ¶ added in v0.46.5
func StateEncryptionConfig ¶ added in v0.47.7
StateEncryptionConfig supplies the common owner-bound state and plan policy. Plaintext fallback is permitted only for the isolated legacy migration.
func ValidateWorkDir ¶
ValidateWorkDir validates the working directory
Types ¶
type Executor ¶
type Executor struct {
// contains filtered or unexported fields
}
Executor handles OpenTofu command execution
func NewExecutor ¶
func NewExecutor(opts ...ExecutorOption) *Executor
NewExecutor creates a new OpenTofu executor
func (*Executor) GetWorkDir ¶
GetWorkDir returns the working directory
func (*Executor) InitReadonly ¶ added in v0.47.7
InitReadonly initializes a materialized StackKit root without allowing OpenTofu to create or mutate its packaged dependency lock.
func (*Executor) IsInstalled ¶
IsInstalled checks if tofu is installed
func (*Executor) SetAutoApprove ¶
SetAutoApprove sets the auto-approve flag dynamically
func (*Executor) SetWorkDir ¶
SetWorkDir sets the working directory
func (*Executor) StatePush ¶ added in v0.47.7
StatePush imports plaintext state from memory and lets the configured backend persist it. Callers use this to migrate a local state atomically without ever staging the plaintext payload in a file.
type ExecutorOption ¶
type ExecutorOption func(*Executor)
ExecutorOption configures the Executor
func WithAutoApprove ¶
func WithAutoApprove(autoApprove bool) ExecutorOption
WithAutoApprove enables auto-approve for apply/destroy
func WithBinary ¶
func WithBinary(binary string) ExecutorOption
WithBinary sets the tofu binary path
func WithEnv ¶
func WithEnv(values ...string) ExecutorOption
WithEnv appends environment values for OpenTofu commands.
func WithTimeout ¶
func WithTimeout(timeout time.Duration) ExecutorOption
WithTimeout sets the execution timeout
func WithWorkDir ¶
func WithWorkDir(dir string) ExecutorOption
WithWorkDir sets the working directory
func WithoutEnvPrefix ¶ added in v0.47.7
func WithoutEnvPrefix(prefixes ...string) ExecutorOption
WithoutEnvPrefix prevents diagnostic controls from persisting secret-bearing process data. It filters both inherited and explicitly supplied variables.
func WithoutInheritedEnv ¶ added in v0.46.5
func WithoutInheritedEnv(names ...string) ExecutorOption
WithoutInheritedEnv drops the named variables from the inherited process environment before WithEnv values are appended. It lets a caller guarantee, for example, that no host plugin cache or CLI argument override reaches an offline OpenTofu run.
type PlanChanges ¶
PlanChanges represents changes detected by plan
func ParsePlanOutput ¶
func ParsePlanOutput(output string) *PlanChanges
ParsePlanOutput parses plan output to extract changes
type ProviderClosure ¶ added in v0.47.7
type ProviderClosure struct {
// contains filtered or unexported fields
}
ProviderClosure is a validated packaged provider mirror and dependency lock. Its fields stay private so callers cannot construct authority without first validating the bundle metadata and current-platform package.
func LoadProviderClosure ¶ added in v0.47.7
func LoadProviderClosure(dir string) (*ProviderClosure, error)
LoadProviderClosure validates the manifest, lock, and every package for the running platform before a tofu process can execute. Release archive trust authenticates the manifest; this closes its hashes over installed bytes.
func (*ProviderClosure) Directory ¶ added in v0.47.7
func (c *ProviderClosure) Directory() string
func (*ProviderClosure) LockForConfiguration ¶ added in v0.47.7
func (c *ProviderClosure) LockForConfiguration(config []byte) ([]byte, error)
LockForConfiguration selects only the providers declared by this root. Provider-free terraform_data roots receive an empty lock.
type TimeoutError ¶
TimeoutError represents a command timeout
func (*TimeoutError) Error ¶
func (e *TimeoutError) Error() string