-
Notifications
You must be signed in to change notification settings - Fork 3
Expand file tree
/
Copy path.pre-commit-config.yaml
More file actions
264 lines (247 loc) · 10.4 KB
/
Copy path.pre-commit-config.yaml
File metadata and controls
264 lines (247 loc) · 10.4 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
# Pre-commit configuration for screening-terraform-modules-aws
#
# Prerequisites (install via mise or brew):
# terraform, tflint, terraform-docs, vale, jq, shellcheck, markdownlint-cli,
# editorconfig-checker, terraform-config-inspect
#
# Usage:
# pre-commit install --install-hooks
# pre-commit install --hook-type commit-msg
# pre-commit run --all-files
#
# See: https://github.com/antonbabenko/pre-commit-terraform
default_install_hook_types:
- pre-commit
- commit-msg
repos:
# --------------------------------------------------------------------------
# Local: generate aliased providers for terraform_validate compatibility
# --------------------------------------------------------------------------
# Generates provider block definitions for modules using provider configuration_aliases.
# This solves the Terraform 0.15+ known issue where terraform validate fails on modules
# with provider aliases. See: https://github.com/hashicorp/terraform/issues/28490
#
# Generates:
# - infrastructure/modules/*/aliased-providers.tf (per-module for validate)
# Files are auto-gitignored and should never be committed.
- repo: local
hooks:
- id: generate-terraform-providers
name: generate-terraform-providers
require_serial: true
entry: ./scripts/githooks/generate-terraform-providers.sh
language: script
files: \.tf(vars)?$
pass_filenames: false
stages: [pre-commit]
# --------------------------------------------------------------------------
# Local: regenerate Dependabot configuration for Terraform modules
# --------------------------------------------------------------------------
# Automatically regenerates .github/dependabot.yaml whenever modules are
# added/removed. This ensures Dependabot watches all Terraform modules.
# Fails if the generated config differs from the committed version,
# forcing users to update the config and commit the result.
#
# Generates:
# - .github/dependabot.yaml (complete Dependabot configuration)
- repo: local
hooks:
- id: regenerate-dependabot-config
name: regenerate-dependabot-config
require_serial: true
entry: ./scripts/githooks/check-dependabot-config.sh
language: script
files: infrastructure/modules/.*/versions\.tf$
pass_filenames: false
stages: [pre-commit]
# --------------------------------------------------------------------------
# Local: regenerate Available modules section in README.md
# --------------------------------------------------------------------------
# Automatically regenerates the Available modules table in README.md whenever
# modules are added/removed or module READMEs are updated. This ensures the
# documentation stays in sync with the actual modules available.
# Fails if the generated section differs from the committed version,
# forcing users to review and commit the updated documentation.
#
# Generates:
# - README.md (Available modules table, between markers)
- repo: local
hooks:
- id: check-available-modules
name: check-available-modules
require_serial: true
entry: ./scripts/githooks/check-available-modules.sh
language: script
files: (infrastructure/modules/.*/README\.md|README\.md)$
pass_filenames: false
stages: [pre-commit]
# --------------------------------------------------------------------------
# Terraform hooks (format, lint, validate, docs, lock)
# --------------------------------------------------------------------------
- repo: https://github.com/antonbabenko/pre-commit-terraform
rev: d61ded22bf9aa0f757303ebcbb0d6d71c4b54015 # v1.106.0
hooks:
- id: terraform_fmt
args:
- --args=-no-color
- --args=-diff
- --args=-recursive
stages: [pre-commit]
- id: terraform_providers_lock
args:
- --args=-platform=linux_arm64
- --args=-platform=linux_amd64
- --args=-platform=darwin_arm64
- --args=-platform=darwin_amd64
- --args=-platform=windows_amd64
- --hook-config=--mode=regenerate-lockfile-if-some-platform-missed
stages: [pre-commit]
- id: terraform_validate
args:
- --args=-json
- --args=-no-color
- --env-vars=AWS_DEFAULT_REGION=eu-west-2
- --hook-config=--retry-once-with-cleanup=true
stages: [pre-commit]
- id: terraform_tflint
# exclude: ^infrastructure/modules/(aws-backup-destination|aws-backup-source)/
args:
- '--args=--config=__GIT_WORKING_DIR__/scripts/config/.tflint.hcl'
stages: [pre-commit]
- id: terraform_docs
args:
- '--args=--lockfile=true'
- --hook-config=--path-to-file=README.md
- --hook-config=--add-to-existing-file=true
- --hook-config=--create-file-if-not-exist=false
- '--hook-config=--custom-marker-begin=<!-- vale off -->\n<!-- markdownlint-disable -->\n<!-- BEGIN_TF_DOCS -->'
- '--hook-config=--custom-marker-end=<!-- END_TF_DOCS -->\n<!-- markdownlint-restore -->\n<!-- vale on -->'
stages: [pre-commit]
# --------------------------------------------------------------------------
# General file hygiene
# --------------------------------------------------------------------------
- repo: https://github.com/pre-commit/pre-commit-hooks
rev: 3e8a8703264a2f4a69428a0aa4dcb512790b2c8c # frozen: v6.0.0
hooks:
# Git style
- id: check-added-large-files
stages: [pre-commit]
- id: check-merge-conflict
stages: [pre-commit]
- id: check-vcs-permalinks
stages: [pre-commit]
- id: forbid-new-submodules
stages: [pre-commit]
- id: no-commit-to-branch
stages: [pre-commit]
# Common errors
- id: end-of-file-fixer
stages: [pre-commit]
- id: trailing-whitespace
args: [--markdown-linebreak-ext=md]
exclude: CHANGELOG.md
stages: [pre-commit]
- id: check-yaml
stages: [pre-commit]
- id: check-executables-have-shebangs
stages: [pre-commit]
# Cross platform
- id: check-case-conflict
stages: [pre-commit]
- id: mixed-line-ending
args: [--fix=lf]
stages: [pre-commit]
# Security
- id: detect-aws-credentials
args: [--allow-missing-credentials]
stages: [pre-commit]
- id: detect-private-key
stages: [pre-commit]
# --------------------------------------------------------------------------
# Shell script linting (uses scripts/shellscript-linter.sh; runs natively if
# shellcheck is on PATH, otherwise falls back to koalaman/shellcheck Docker
# image. Local and CI follow the same logic so behaviour is consistent.)
#
# NOTE: require_serial=true prevents pre-commit from running this hook in
# parallel with other hooks. This is critical because when the Docker fallback
# is used, concurrent container spawning can exhaust available memory (exit 137).
# Sequential execution ensures Docker containers are cleaned up between files.
# --------------------------------------------------------------------------
- repo: local
hooks:
- id: shellcheck
name: shellcheck
entry: bash -c 'for f in "$@"; do SHELLCHECK_OPTS="--severity=warning" file="$f" bash scripts/shellscript-linter.sh || exit 1; done' --
language: system
types: [shell]
require_serial: true
stages: [pre-commit]
# --------------------------------------------------------------------------
# Repository githook wrappers (native tool if available, Docker fallback)
# --------------------------------------------------------------------------
# TODO: Keep this file as the single source of truth for checks and tune CI by
# sharding pre-commit hook execution in a matrix (instead of duplicating checks
# across standalone workflows). Keep terraform_validate and terraform_docs in the
# same shard because docs generation relies on init/validation context.
- repo: local
hooks:
- id: check-file-format
name: check-file-format
entry: bash -c 'check=all ./scripts/githooks/check-file-format.sh'
language: system
pass_filenames: false
stages: [pre-commit]
- id: check-markdown-format
name: check-markdown-format
entry: bash -c 'check=all ./scripts/githooks/check-markdown-format.sh'
language: system
files: \.md$
pass_filenames: false
stages: [pre-commit]
- id: check-english-usage
name: check-english-usage
entry: bash -c 'check=all ./scripts/githooks/check-english-usage.sh'
language: system
files: \.md$
pass_filenames: false
stages: [pre-commit]
- id: check-terraform-format
name: check-terraform-format
entry: bash -c 'check_only=true ./scripts/githooks/check-terraform-format.sh'
language: system
files: \.tf(vars)?$
pass_filenames: false
stages: [pre-commit]
- id: scan-secrets-staged-changes
name: scan-secrets-staged-changes
entry: bash -c 'check=staged-changes ./scripts/githooks/scan-secrets.sh'
language: system
pass_filenames: false
stages: [pre-commit]
- id: scan-secrets-whole-history
name: scan-secrets-whole-history
entry: bash -c 'check=whole-history ./scripts/githooks/scan-secrets.sh'
language: system
pass_filenames: false
stages: [manual]
# --------------------------------------------------------------------------
# Conventional Commits (commit message format)
# --------------------------------------------------------------------------
# Replaced external compilerla/conventional-pre-commit with native bash validator
# to avoid external dependencies. Uses scripts/githooks/validate-conventional-commit.sh
# instead.
#
# Original:
# - repo: https://github.com/compilerla/conventional-pre-commit
# rev: 91ab4bf57e58b32adf1a122681f6ebe164d081c8 # v4.4.0
# hooks:
# - id: conventional-pre-commit
# stages: [commit-msg]
# args: [--strict, feat, fix, docs, style, refactor, perf, test, build, ci, chore, revert]
- repo: local
hooks:
- id: conventional-commit
name: Conventional Commit format check
entry: scripts/githooks/validate-conventional-commit.sh
language: script
stages: [commit-msg]