fix(docker): install OpenTofu >= 1.10 instead of alpine's 1.7.2 - #38
Merged
Conversation
The lambda scope inits its S3 backend with use_lockfile=true (lambda/scope/tofu/provider/aws/setup), which requires OpenTofu 1.10+. alpine 3.20's apk package is 1.7.2, so create-scope would fail at tofu init. Pull the official static tofu binary (pinned 1.10.6, per build arch) instead. Restores parity with the mise-based test image (.mise.toml opentofu=latest).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
The lambda scope inits its S3 backend with
use_lockfile=true(lambda/scope/tofu/provider/aws/setup), which requires OpenTofu ≥ 1.10. The previous Dockerfile installedopentofufrom alpine 3.20's apk, which is 1.7.2 — socreate-scopewould fail attofu initwith an unsupported-argument error. This regressed the mise-based test image (.mise.toml→opentofu = latest, which was 1.10.x).Fix
Drop
opentofufrom the apk line; pull the official statictofubinary instead, pinned to 1.10.6, per build arch (TARGETARCH). Verified locally:Follow-up
The TF package pin (
implementation-aws/.../scope_definition.tf) must point at the digest of the image built from this fix — not the currentv0.3.0(tofu 1.7.2). It'll get a new digest once this merges + releases (or a manual rebuild).