#atlantis (2021-01)
Discuss the Atlantis (<http://runatlantis.io | runatlantis.io>) |
**Archive: ** https://archive.sweetops.com/atlantis/
2021-01-07
data:image/s3,"s3://crabby-images/1f112/1f1120d7c318c548190b06c33109a6e54d94c908" alt="Igor avatar"
Has anybody had issues with the new TF0.14 dependency lock files and Atlantis?
data:image/s3,"s3://crabby-images/1f112/1f1120d7c318c548190b06c33109a6e54d94c908" alt="Igor avatar"
Getting “Error: Failed to install provider from shared cache” when committing the lock files
2021-01-08
data:image/s3,"s3://crabby-images/1f112/1f1120d7c318c548190b06c33109a6e54d94c908" alt="Igor avatar"
Looks like the hashes are different depending on the platform that the init is run
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
I have not seen an error like that in 0.13.5 I have not used 0.14 yet
data:image/s3,"s3://crabby-images/1f112/1f1120d7c318c548190b06c33109a6e54d94c908" alt="Igor avatar"
If you use exclusively Atlantis, you won’t see lock files at all, since they won’t ever be committed
data:image/s3,"s3://crabby-images/1f112/1f1120d7c318c548190b06c33109a6e54d94c908" alt="Igor avatar"
Maybe a future use case for Atlantis to commit these lock files
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
It could be
2021-01-13
data:image/s3,"s3://crabby-images/ed9f5/ed9f521f1b2f13668f5d19b8be587c914d69aa73" alt="Joan Porta avatar"
Any recommendation on how to use Atlantis to have a previous step to analyze security
in terraform code? I mean, opened Sec Groups, IAM resources wide open…? Or if there is a better tool I would thank you.
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
Here is a feature that will be merged soon that enables opa policy checks in Atlantis natively
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
any idea when this is coming?
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
It should come on the next release that is a bit late
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
Nice man can’t wait for this, any chance you could ping over the PR for reference please?
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
yes one sec
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
This PR adds policy check workflow into atlantis. It uses conftest to execute policies. At the moment you can only define policies locally and configure them in the server side config. How it works…
data:image/s3,"s3://crabby-images/fcdc0/fcdc082ca5c426ae7a83f63c34dd4cae258c8b47" alt="Steve Wade (swade1987) avatar"
2021-01-14
data:image/s3,"s3://crabby-images/afcda/afcdaf6c850e24589d88452e0bf9448a38682f9c" alt="jose.amengual avatar"
https://github.com/runatlantis/atlantis/pull/1340 @Erik Osterman (Cloud Posse) related to our conversation in OfficeHours
This change introduces a no-op Locker implementation that when enabled effectively disables the locking of projects and workspace This is another possible solution to #1212, my initial change just …
2021-01-21
data:image/s3,"s3://crabby-images/c026c/c026c40f70a7f82cb6d39db55ade6f8b7e803e7e" alt="cytopia avatar"
Currently trying to use yaml anchors in atlantis.yaml (repo-side) to save some code. No matter how I write it, I always get a parsing atlantis.yaml: yaml: line XXX: did not find expected key
Anyone knows if anchors are supported by their yaml parser at all?
data:image/s3,"s3://crabby-images/0704f/0704fa2c4de34bfc92a8ecd50096a4fa8404549a" alt="joshmyers avatar"
version: 3
automerge: true
projects:
# Project Definitions
- &terraform_project
name: "ecr"
dir: "terraform/coreeng/global/us-east-1/ecr"
workflow: "terragrunt"
workspace: "default"
apply_requirements:
- "approved"
- "mergeable"
autoplan:
enabled: true
when_modified:
- "*.tf"
- "*.hcl"
- <<: *terraform_project
name: "dev/us-east-1/badgers-service"
dir: "terraform/test/dev/us-east-1/badgers-service"
autoplan:
enabled: true
when_modified:
- "../../badgers-service.hcl"
- "*.tf"
- "*.hcl"
data:image/s3,"s3://crabby-images/c026c/c026c40f70a7f82cb6d39db55ade6f8b7e803e7e" alt="cytopia avatar"
Trying this in the workflow definition (with no luck) as such:
workflows:
terraform-playground:
envs: &envs
- env:
name: AWS_SECRET_JSON
command: aws sts assume-role --role-arn arn:aws:iam::123456789:role/ATLANTIS"
- env:
name: AWS_ACCESS_KEY_ID
command: echo "${AWS_SECRET_JSON}" | grep AccessKeyId | awk -F'"' '{print $4}'
- env:
name: AWS_SECRET_ACCESS_KEY
command: echo "${AWS_SECRET_JSON}" | grep SecretAccessKey | awk -F'"' '{print $4}'
- env:
name: AWS_SESSION_TOKEN
command: echo "${AWS_SECRET_JSON}" | grep SessionToken | awk -F'"' '{print $4}'
plan:
steps:
*envs
- run: terraform init
- run: terraform plan -no-color -out $PLANFILE
apply:
steps:
*envs
- run: terraform apply -no-color $PLANFILE