Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
96 commits
Select commit Hold shift + click to select a range
8d07ed2
fix(azure/aks_route_table): stable trigger instead of timestamp() (#4…
gdrojas Aug 11, 2026
36f4540
fix(azure): make the internal gateway LB subnet configurable and gran…
gdrojas Aug 11, 2026
e322e09
ci: temporary dual release line (package -> 7.x, resto -> 6.x) (#498)
sebastiancorrea81 Aug 11, 2026
895385e
fix(ci): correct release-please target-branch resolution for the dual…
sebastiancorrea81 Aug 11, 2026
d927286
chore(6.x): release 6.11.3
github-actions[bot] Aug 11, 2026
ddd1019
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 11, 2026
a01d16e
chore(6.x): release 6.11.3 (#506)
sebastiancorrea81 Aug 11, 2026
1168479
ci: verify a branch actually forked from its declared base line (#507)
sebastiancorrea81 Aug 11, 2026
a7b3a0a
feat(eks): add traffic_manager_port variable (#509)
fedemaleh Aug 12, 2026
d749dd4
chore(6.x): release 6.12.0 (#510)
github-actions[bot] Aug 12, 2026
ee4ec16
chore(nullplatform): refresh provider lockfiles for the >= 0.0.99 con…
jcastiarena Aug 12, 2026
6dd5021
feat(aks): support disabling local accounts with an Entra ID authoriz…
jcastiarena Aug 13, 2026
53efd56
chore(6.x): release 6.13.0 (#516)
github-actions[bot] Aug 14, 2026
7a50067
fix(gcp/security): handle full resource path in cluster subnetwork lo…
sebastiancorrea81 Aug 14, 2026
97d10f9
chore(6.x): release 6.13.1 (#517)
github-actions[bot] Aug 14, 2026
a1992af
feat(nullplatform/agent): require ingress templates for non-aws cloud…
sebastiancorrea81 Aug 14, 2026
cee7a97
chore(6.x): release 6.14.0
github-actions[bot] Aug 14, 2026
5e6e1b2
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 14, 2026
c9904fc
chore(6.x): release 6.14.0 (#518)
release-application[bot] Aug 14, 2026
552adf1
feat(gcp/artifact-registry): optional static service account key (#514)
sebastiancorrea81 Aug 14, 2026
bd7eacc
chore(6.x): release 6.15.0
github-actions[bot] Aug 14, 2026
579fafd
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 14, 2026
4105184
feat(gcp/gke): support Autopilot mode and flexible/spot node pools (#…
sebastiancorrea81 Aug 14, 2026
1f3bc24
chore(6.x): release 6.15.0 (#521)
release-application[bot] Aug 14, 2026
c15e195
feat(gcp/backend): add GCS terraform state bucket module (#511)
sebastiancorrea81 Aug 14, 2026
3307bee
chore(6.x): release 6.16.0
github-actions[bot] Aug 14, 2026
df3b480
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 14, 2026
1ffaf35
chore(6.x): release 6.16.0 (#522)
release-application[bot] Aug 14, 2026
ded6214
fix(gcp/security): resolve the subnetwork in its own project and regi…
gdrojas Aug 14, 2026
f9dcb81
chore(6.x): release 6.16.1
github-actions[bot] Aug 14, 2026
f48399b
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 14, 2026
5c8662d
chore(6.x): release 6.16.1 (#524)
release-application[bot] Aug 14, 2026
f1d8505
feat(base): make logs controller and control plane agent image tags c…
sebastiancorrea81 Aug 19, 2026
d8bb475
chore(6.x): release 6.17.0
github-actions[bot] Aug 19, 2026
a56f698
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 19, 2026
9fdd843
chore(6.x): release 6.17.0 (#528)
release-application[bot] Aug 19, 2026
c5e65d6
feat(istio): expose istio_ingressgateway_replicas to guarantee HA for…
fedemaleh Aug 19, 2026
98dfcff
chore(6.x): release 6.18.0
github-actions[bot] Aug 19, 2026
6708003
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 19, 2026
b728180
chore(6.x): release 6.18.0 (#529)
release-application[bot] Aug 19, 2026
b8dd7cf
feat(external_dns): add google provider support (#532)
sebastiancorrea81 Aug 21, 2026
4629ab6
chore(6.x): release 6.19.0
github-actions[bot] Aug 21, 2026
7ea83d5
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 21, 2026
8263b6f
chore(6.x): release 6.19.0 (#533)
release-application[bot] Aug 21, 2026
f712605
fix(base): bump default nullplatform_base_helm_version to 2.44.0 (#534)
sebastiancorrea81 Aug 21, 2026
0e9737b
chore(6.x): release 6.19.1
github-actions[bot] Aug 21, 2026
31f9828
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 21, 2026
7c4d7fb
chore(6.x): release 6.19.1 (#535)
release-application[bot] Aug 21, 2026
8598b82
ci: reject new moving version defaults, and document what to pin (#539)
gdrojas Aug 27, 2026
1489874
feat: require an explicit version for everything the modules deploy (…
gdrojas Aug 28, 2026
71f5b2b
chore(6.x): release 6.20.0
github-actions[bot] Aug 28, 2026
78220fd
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 28, 2026
2528579
chore(6.x): release 6.20.0 (#541)
release-application[bot] Aug 28, 2026
dcdeae4
feat(api_key): add base type (#538)
gdrojas Aug 28, 2026
e446dd8
chore(6.x): release 6.21.0
github-actions[bot] Aug 28, 2026
8efeef9
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Aug 28, 2026
e3fb379
chore(6.x): release 6.21.0 (#542)
release-application[bot] Aug 28, 2026
944d683
feat(istio): remove legacy istio-ingressgateway helm release (#543)
agustincelentano Sep 1, 2026
bdcb48c
chore(6.x): release 6.22.0
github-actions[bot] Sep 1, 2026
e6aded6
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Sep 1, 2026
b6e30eb
chore(6.x): release 6.22.0 (#545)
release-application[bot] Sep 1, 2026
1339632
fix(base): expose gateway_api_crd_ref, default to v1.3.0 for Istio 1.…
sebastiancorrea81 Sep 1, 2026
ac69960
chore(6.x): release 6.22.1
github-actions[bot] Sep 1, 2026
7d269bd
docs: regenerate READMEs for changed modules and update versions
github-actions[bot] Sep 1, 2026
b87bdba
chore(6.x): release 6.22.1 (#546)
release-application[bot] Sep 1, 2026
f85ab13
chore: merge 6.x into main to unify release lines
Sep 1, 2026
f15ba3c
fix(asset): remove unused dimensions variable across ecr/s3/docker_se…
Sep 1, 2026
2b29c87
feat(agent)!: move deploy/DNS env vars from the agent pod to the worker
Sep 1, 2026
290e203
fix(agent): drop worker_service_account_name, require real defaults
Sep 1, 2026
1d759de
refactor(agent): fold worker into the single agent values document
Sep 1, 2026
a371be6
fix(agent): drop unused cluster_name variable
Sep 1, 2026
511f364
fix(agent): default worker allowedRegistries to the nullplatform ECR org
Sep 1, 2026
98d4c9c
feat(scope_definition): default the oci_image package artifact to the…
Sep 1, 2026
71eeff7
feat(agent): add TRAFFIC_CONTAINER_IMAGE to the worker's env
Sep 1, 2026
89f4aad
fix(agent): give worker_env the same cloud_config/extra_envs layering…
Sep 1, 2026
23cffc1
refactor(agent): dedupe the traffic-manager image expression
Sep 1, 2026
fc4bfc3
fix(agent): give the agent the deploy/DNS vars too, share one config map
Sep 1, 2026
5ff136e
Revert "fix(agent): give the agent the deploy/DNS vars too, share one…
Sep 2, 2026
eefb213
refactor(agent): split agent-pod env from worker env into two maps
Sep 2, 2026
336ef5e
fix(agent): restore a minimal agent_repo escape hatch, tidy formatting
Sep 2, 2026
ae0f6a3
feat(agent): agent_repo accepts a list, joined into AGENT_REPO
Sep 2, 2026
5e83faa
fix(gcp/backend): self-provision a log bucket when log_bucket is unset
Sep 2, 2026
e16da9d
fix(gcp/backend): enable versioning on the self-provisioned log bucket
Sep 2, 2026
789a13e
feat(service_definition): default package artifact name/type to impl/…
Sep 2, 2026
8cef343
docs(scope_definition,service_definition): digest/reference are type-…
Sep 2, 2026
1e03c43
fix(service_definition_agent_association): correct base_clone_path de…
Sep 2, 2026
62a9485
fix(agent): join --command-executor-git-command-repos with = like eve…
Sep 2, 2026
c9228ba
feat(scope_definition,service_definition): make package oci_image met…
Sep 2, 2026
b518373
feat(service_definition_agent_association): add worker_orchestrator s…
Sep 2, 2026
67ec6e4
fix(agent): worker serviceAccountName patch was hardcoded to the cont…
Sep 2, 2026
6c970bf
fix(service_definition_agent_association): drop legacy-exec-only requ…
Sep 2, 2026
020e338
fix(agent): worker memory limit was also hardcoded to the containers …
Sep 2, 2026
cfa5948
fix(agent): port the safe parts of 6.x's #519 (helm reliability + dep…
Sep 3, 2026
2302ecc
feat(api_key): add the internal option (port from 6.x #547)
Sep 3, 2026
8bb4d77
fix(agent): drop the nrn/private_domain deprecated no-ops
Sep 3, 2026
3431ae9
Merge branch 'main' into chore/merge-6x-into-main
sebastiancorrea81 Sep 3, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 14 additions & 2 deletions .github/workflows/tflint-unused.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
name: tflint-unused-declarations
name: terraform-lint

on:
pull_request:
Expand All @@ -7,7 +7,7 @@ on:

jobs:
check:
name: Check for unused declarations
name: Lint changed Terraform
runs-on: ubuntu-24.04
steps:
- name: Checkout repository
Expand Down Expand Up @@ -52,3 +52,15 @@ jobs:
echo "::error::tflint found unused declarations in one or more changed modules (see groups above)."
exit 1
fi

# CI backstop for the local pre-commit hook.
- name: Check version pinning
if: steps.changed.outputs.dirs != ''
env:
BASE_SHA: ${{ github.event.pull_request.base.sha }}
HEAD_SHA: ${{ github.event.pull_request.head.sha }}
run: |
files="$(git diff --name-only "$BASE_SHA" "$HEAD_SHA" -- '*.tf' || true)"
[ -z "$files" ] && exit 0
# shellcheck disable=SC2086
./scripts/check-version-pinning.sh $files
6 changes: 3 additions & 3 deletions .github/workflows/tofu-test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:
test-commons-modules:
uses: nullplatform/actions-nullplatform/.github/workflows/tofu-test.yml@main
with:
modules: '["infrastructure/commons/cert_manager", "infrastructure/commons/external_dns", "infrastructure/commons/istio"]'
modules: '["infrastructure/commons/cert_manager", "infrastructure/commons/external_dns", "infrastructure/commons/istio", "infrastructure/commons/prometheus"]'

test-aws-modules:
uses: nullplatform/actions-nullplatform/.github/workflows/tofu-test.yml@main
Expand All @@ -25,12 +25,12 @@ jobs:
test-gcp-modules:
uses: nullplatform/actions-nullplatform/.github/workflows/tofu-test.yml@main
with:
modules: '["infrastructure/gcp/artifact-registry", "infrastructure/gcp/cloud-dns", "infrastructure/gcp/cloud-nat", "infrastructure/gcp/iam", "infrastructure/gcp/vpc"]'
modules: '["infrastructure/gcp/artifact-registry", "infrastructure/gcp/cloud-dns", "infrastructure/gcp/cloud-nat", "infrastructure/gcp/gke", "infrastructure/gcp/iam", "infrastructure/gcp/security", "infrastructure/gcp/vpc"]'

test-nullplatform-modules:
uses: nullplatform/actions-nullplatform/.github/workflows/tofu-test.yml@main
with:
modules: '["nullplatform/account", "nullplatform/api_key", "nullplatform/dimension", "nullplatform/dimension_value", "nullplatform/users", "nullplatform/metrics", "nullplatform/asset/docker_server", "nullplatform/cloud/azure/cloud", "nullplatform/cloud/gcp/cloud", "nullplatform/cloud/aws/cloud", "nullplatform/code_repository"]'
modules: '["nullplatform/account", "nullplatform/agent", "nullplatform/api_key", "nullplatform/dimension", "nullplatform/dimension_value", "nullplatform/users", "nullplatform/metrics", "nullplatform/asset/docker_server", "nullplatform/cloud/azure/cloud", "nullplatform/cloud/gcp/cloud", "nullplatform/cloud/aws/cloud", "nullplatform/code_repository", "nullplatform/base", "nullplatform/agent"]'

test-container-orchestration-modules:
uses: nullplatform/actions-nullplatform/.github/workflows/tofu-test.yml@main
Expand Down
7 changes: 7 additions & 0 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,13 @@ repos:
require_serial: true
exclude: '\.terraform/|\.terragrunt-cache/'

- id: check-version-pinning
name: check version pinning
entry: scripts/check-version-pinning.sh
language: script
files: '\.tf$'
exclude: '\.terraform/|\.terragrunt-cache/'

- id: block-superpowers-files
name: block superpowers files
entry: >-
Expand Down
114 changes: 114 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,47 @@
# Changelog

## [6.22.1](https://github.com/nullplatform/tofu-modules/compare/v6.22.0...v6.22.1) (2026-09-01)


### Bug Fixes

* **base:** expose gateway_api_crd_ref, default to v1.3.0 for Istio 1.27 ([#544](https://github.com/nullplatform/tofu-modules/issues/544)) ([4bf8323](https://github.com/nullplatform/tofu-modules/commit/4bf8323b32716944411b745e2f15aae8da1a64d2))

## [6.22.0](https://github.com/nullplatform/tofu-modules/compare/v6.21.0...v6.22.0) (2026-09-01)


### Features

* **istio:** remove legacy istio-ingressgateway helm release ([#543](https://github.com/nullplatform/tofu-modules/issues/543)) ([957dbc4](https://github.com/nullplatform/tofu-modules/commit/957dbc4b7f9ed1346511f49042fd939143d3831f))

## [6.21.0](https://github.com/nullplatform/tofu-modules/compare/v6.20.0...v6.21.0) (2026-08-28)


### Features

* **api_key:** add base type ([#538](https://github.com/nullplatform/tofu-modules/issues/538)) ([272cbd0](https://github.com/nullplatform/tofu-modules/commit/272cbd08410dd78183363e1642c8a79478266cbd))

## [6.20.0](https://github.com/nullplatform/tofu-modules/compare/v6.19.1...v6.20.0) (2026-08-28)


### Features

* require an explicit version for everything the modules deploy ([#540](https://github.com/nullplatform/tofu-modules/issues/540)) ([868ad98](https://github.com/nullplatform/tofu-modules/commit/868ad989663aa15e4dbdea98fa940e668e4994c2))

## [6.19.1](https://github.com/nullplatform/tofu-modules/compare/v6.19.0...v6.19.1) (2026-08-21)


### Bug Fixes

* **base:** bump default nullplatform_base_helm_version to 2.44.0 ([#534](https://github.com/nullplatform/tofu-modules/issues/534)) ([a7e91b7](https://github.com/nullplatform/tofu-modules/commit/a7e91b7ad613da19de3a653c497152480e33f15d))

## [6.19.0](https://github.com/nullplatform/tofu-modules/compare/v6.18.0...v6.19.0) (2026-08-21)


### Features

* **external_dns:** add google provider support ([#532](https://github.com/nullplatform/tofu-modules/issues/532)) ([222ff52](https://github.com/nullplatform/tofu-modules/commit/222ff522601d3b4f5c85cc016e79981fa58cd5c4))

## [7.1.0](https://github.com/nullplatform/tofu-modules/compare/v7.0.3...v7.1.0) (2026-08-19)


Expand All @@ -13,6 +55,69 @@

* **service_definition:** pin default (use_default_actions) actions into the package BOM ([c1493b5](https://github.com/nullplatform/tofu-modules/commit/c1493b5a1024094606a4a67cd6c05d5812daab90))

## [6.18.0](https://github.com/nullplatform/tofu-modules/compare/v6.17.0...v6.18.0) (2026-08-19)


### Features

* **istio:** expose istio_ingressgateway_replicas to guarantee HA for node drains ([#379](https://github.com/nullplatform/tofu-modules/issues/379)) ([058986c](https://github.com/nullplatform/tofu-modules/commit/058986c7c5aaf8a998bd25bcf021fc40c2fd0dce))

## [6.17.0](https://github.com/nullplatform/tofu-modules/compare/v6.16.1...v6.17.0) (2026-08-19)


### Features

* **base:** make logs controller and control plane agent image tags configurable ([#527](https://github.com/nullplatform/tofu-modules/issues/527)) ([1c892a5](https://github.com/nullplatform/tofu-modules/commit/1c892a566950b81a9201dc0d89e1c091dbbd6eb6))

## [6.16.1](https://github.com/nullplatform/tofu-modules/compare/v6.16.0...v6.16.1) (2026-08-14)


### Bug Fixes

* **gcp/security:** resolve the subnetwork in its own project and region ([#520](https://github.com/nullplatform/tofu-modules/issues/520)) ([0b8f322](https://github.com/nullplatform/tofu-modules/commit/0b8f322f600de9e80630bd09764a421cc5249c20))

## [6.16.0](https://github.com/nullplatform/tofu-modules/compare/v6.15.0...v6.16.0) (2026-08-14)


### Features

* **gcp/backend:** add GCS terraform state bucket module ([#511](https://github.com/nullplatform/tofu-modules/issues/511)) ([9355c6e](https://github.com/nullplatform/tofu-modules/commit/9355c6e4fcb6cb38be04f01fea264a54f7ac3c9c))

## [6.15.0](https://github.com/nullplatform/tofu-modules/compare/v6.14.0...v6.15.0) (2026-08-14)


### Features

* **gcp/artifact-registry:** optional static service account key ([#514](https://github.com/nullplatform/tofu-modules/issues/514)) ([aaa9674](https://github.com/nullplatform/tofu-modules/commit/aaa96740639412dccc74b4dce56ca55f03511de5))

## [6.14.0](https://github.com/nullplatform/tofu-modules/compare/v6.13.1...v6.14.0) (2026-08-14)


### Features

* **nullplatform/agent:** require ingress templates for non-aws clouds ([#515](https://github.com/nullplatform/tofu-modules/issues/515)) ([fbb4198](https://github.com/nullplatform/tofu-modules/commit/fbb4198d33b1da084e033e7b371d35d9509c6ed9))

## [6.13.1](https://github.com/nullplatform/tofu-modules/compare/v6.13.0...v6.13.1) (2026-08-14)


### Bug Fixes

* **gcp/security:** handle full resource path in cluster subnetwork lookup ([#512](https://github.com/nullplatform/tofu-modules/issues/512)) ([e790af4](https://github.com/nullplatform/tofu-modules/commit/e790af437e4358a1e1254f00c3dba226fbc51b31))

## [6.13.0](https://github.com/nullplatform/tofu-modules/compare/v6.12.0...v6.13.0) (2026-08-13)


### Features

* **aks:** support disabling local accounts with an Entra ID authorization path ([#461](https://github.com/nullplatform/tofu-modules/issues/461)) ([3e3c412](https://github.com/nullplatform/tofu-modules/commit/3e3c412b5a996241da6a904f9e86b3faf51c6487))

## [6.12.0](https://github.com/nullplatform/tofu-modules/compare/v6.11.3...v6.12.0) (2026-08-12)


### Features

* **eks:** add traffic_manager_port variable ([#509](https://github.com/nullplatform/tofu-modules/issues/509)) ([b2165b2](https://github.com/nullplatform/tofu-modules/commit/b2165b2e0cdd922922b4eb029c9f69512c8d0e62))

## [7.0.3](https://github.com/nullplatform/tofu-modules/compare/v7.0.2...v7.0.3) (2026-08-11)


Expand All @@ -34,6 +139,15 @@

* **azure/aks_route_table:** stable trigger instead of timestamp() ([#474](https://github.com/nullplatform/tofu-modules/issues/474)) ([#493](https://github.com/nullplatform/tofu-modules/issues/493)) ([dad52fa](https://github.com/nullplatform/tofu-modules/commit/dad52fad010915756586d05c1915b4d5bc1d1adf))

## [6.11.3](https://github.com/nullplatform/tofu-modules/compare/v6.11.2...v6.11.3) (2026-08-11)


### Bug Fixes

* **azure/aks_route_table:** stable trigger instead of timestamp() ([#474](https://github.com/nullplatform/tofu-modules/issues/474)) ([#493](https://github.com/nullplatform/tofu-modules/issues/493)) ([8d07ed2](https://github.com/nullplatform/tofu-modules/commit/8d07ed22635586a4e30baec79fcbbe994b78ddf3))
* **azure:** make the internal gateway LB subnet configurable and grantable ([#494](https://github.com/nullplatform/tofu-modules/issues/494)) ([36f4540](https://github.com/nullplatform/tofu-modules/commit/36f45406a7bde29126939739a19f7a9139f2d31a))
* **ci:** correct release-please target-branch resolution for the dual release line scheme ([#504](https://github.com/nullplatform/tofu-modules/issues/504)) ([895385e](https://github.com/nullplatform/tofu-modules/commit/895385ee0c76802b1773d07cf80ba5420d766ddf))

## [7.0.0](https://github.com/nullplatform/tofu-modules/compare/v6.11.2...v7.0.0) (2026-08-10)


Expand Down
7 changes: 6 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@ Reference any module via its Git source, pinned to a release tag:

```hcl
module "vpc" {
source = "git::https://github.com/nullplatform/tofu-modules.git//infrastructure/aws/vpc?ref=v6.11.0"
source = "git::https://github.com/nullplatform/tofu-modules.git//infrastructure/aws/vpc?ref=v6.19.1"

# module inputs ...
}
Expand All @@ -46,6 +46,11 @@ tofu apply

See the [latest releases](https://github.com/nullplatform/tofu-modules/releases) for available versions.

Several modules require you to pin a chart version, an image tag or a git ref, with no
default. **[VERSIONS.md](VERSIONS.md) lists every one of them with its current value and a
ready-to-paste block** — read it before your first apply rather than hunting the numbers down
one variable at a time.

## Versioning

Releases follow [Semantic Versioning](https://semver.org/) and are automated via [release-please](https://github.com/googleapis/release-please). See [CHANGELOG.md](CHANGELOG.md) for the full release history.
Expand Down
134 changes: 134 additions & 0 deletions VERSIONS.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,134 @@
# Pinned versions

Every version these modules deploy — Helm charts, container images, and the git refs the agent
clones — is listed here with the value to pin.

For the version of *these modules*, see the
[releases](https://github.com/nullplatform/tofu-modules/releases).

## Why it matters

`latest` and branch names resolve at deploy time, not at apply time. A pod restart can pull a
different build with no change on your side and no diff to review. Every default below names
a specific release, so an upgrade is something someone decides.

## What to pin

Verified 2026-08-27.

| Component | Current | Variable | Module |
| --- | --- | --- | --- |
| `nullplatform-base` chart | `2.44.0` | `nullplatform_base_helm_version` | `nullplatform/base` |
| `nullplatform-agent` chart | `2.37.0` | `nullplatform_agent_helm_version` | `nullplatform/agent` |
| `cert-manager` chart | `v1.21.1` | `cert_manager_version` | `infrastructure/commons/cert_manager` |
| `prometheus` chart | `29.27.0` | `prometheus_version` | `infrastructure/commons/prometheus` |
| `k8s-logs-controller` | `1.6.0` | `logging_controller_image_tag` | `nullplatform/base` |
| `controlplane-agent` | `0.9.2` | `control_plane_agent_image_tag` | `nullplatform/base` |
| `k8s-traffic-manager` | `1.8.0` | `agent_traffic_manager_tag` | `nullplatform/agent` |
| traffic manager (provider config) | `1.8.0` | `traffic_manager_version` | `container_orchestration/eks` |
| `scopes` repository | `v1.15.1` | `agent_repos_scope` | `nullplatform/agent` |

**Read your cluster before copying these.** The rule is to pin what you are already running,
so the change stays functionally inert. Four of these were previously unpinnable and resolved
at deploy time, so what you run may not match the table: `cert_manager_version`,
`prometheus_version`, `logging_controller_image_tag`, and `traffic_manager_version` on eks.

## Ready to paste

```hcl
module "base" {
nullplatform_base_helm_version = "2.44.0"
logging_controller_image_tag = "1.6.0"
control_plane_agent_image_tag = "0.9.2"
}

module "agent" {
nullplatform_agent_helm_version = "2.37.0"
image_tag = "0.9.2"
agent_repos_scope_tag = "v1.15.1"
agent_traffic_manager_tag = "1.8.0"

agent_repos_extra = [
"https://github.com/nullplatform/scopes-lambda.git#v0.3.1",
"https://github.com/nullplatform/scopes-static-files.git#v0.4.0",
]
}

# eks, aks and gke all take this
module "container_orchestration" {
traffic_manager_version = "1.8.0"
}

module "cert_manager" {
cert_manager_version = "v1.21.1"
}

module "prometheus" {
prometheus_version = "29.27.0"
}

module "service_definition" {
# No value listed: repository_org and repository_name are configurable, so which spec
# repository you read is your choice and so is its ref.
repository_branch = "..."
}
```

To find what an install is actually running before changing anything:

```bash
helm -n nullplatform-tools get values nullplatform-base
helm -n <ns> list -o json | jq -r '.[] | "\(.name)\t\(.chart)"'
kubectl -n nullplatform-tools get deploy \
-o jsonpath='{range .items[*]}{.metadata.name}{"\t"}{.spec.template.spec.containers[*].image}{"\n"}{end}'
```

The traffic manager image is assembled from `agent_traffic_manager_tag` and published to the
agent as `TRAFFIC_CONTAINER_IMAGE`. `extra_envs` still takes precedence over it, so a digest
or a mirrored registry path can be passed the way it was before the tag was exposed.

## Caveats

**The scopes ref steps back.** `agent_repos_scope` used to point at `scopes.git#main`, and
`main` has moved past `v1.15.1`. Pinning the tag is deliberate — it is the ref named in the
migration request — but it is not the same tree the branch tip pointed at.

**cert-manager and prometheus were not pinnable at all.** `cert_manager_version` existed but
was never wired to its `helm_release`, and `prometheus` had no version argument, so both
tracked whatever their chart repository served.

**Not everything is covered yet.** The scopes and service-spec repositories are read through
eleven other paths, in `scope_definition`, `scope_definition_agent_association`,
`parameter_storage_definition` and `service_definition`, and those still default to a moving
branch. Pinning `agent_repos_scope` does not cover them: the agent clones the ref while the
definition modules read the branch. They are listed in
`scripts/version-pinning-baseline.txt` with the reason.

**A name cannot prove immutability.** The checks below reject `latest`, `main`, `master` and
`HEAD`. A tag called `beta` or a branch called `develop` passes. Nothing distinguishes a
mutable ref from a fixed one by name alone.

## Keeping this current

There is no automation that bumps these numbers, on purpose. Bumping a documented version to
whatever is newest would put the drift back in documentation form, and it contradicts the rule
above about pinning what you already run. When a new version ships, someone decides and edits
this table.

What is automated is the opposite direction: `scripts/check-version-pinning.sh` rejects a *new*
moving default, a repository URL pinned to a branch, or a `helm_release` with no `version`. It
runs in pre-commit and again as a step in the `terraform-lint` workflow, so skipping the local
hook does not skip the check. Deliberately deferred violations live in
`scripts/version-pinning-baseline.txt` with the reason; that file should only ever shrink.

One trap worth knowing before bumping an image by hand: **`k8s-traffic-manager` publishes a
`v2.0.2` built 2026-02-09 while `1.8.0` was built 2026-07-29**, and `k8s-logs-controller` a
`v2.0.1` from that same February against a `1.6.0` from August. The higher version number is
the older build, from a line that was not continued. Compare build dates, not version numbers:

```bash
tag=1.8.0; repo=nullplatform/k8s-traffic-manager
t=$(curl -s "https://public.ecr.aws/token/?scope=repository:$repo:pull" | jq -r .token)
curl -s -H "Authorization: Bearer $t" "https://public.ecr.aws/v2/$repo/tags/list" | jq -r '.tags[]'
```

4 changes: 2 additions & 2 deletions infrastructure/aws/vpc/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -24,8 +24,8 @@ module "vpc" {
# }

public_subnet_tags = {
"kubernetes.io/role/elb" = 1
"nullplatform/subnet-type" = "public"
"kubernetes.io/role/elb" = 1
"nullplatform/subnet-type" = "public"
}

private_subnet_tags = {
Expand Down
4 changes: 3 additions & 1 deletion infrastructure/azure/aks/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -30,8 +30,10 @@ module "aks" {
# RBAC / AAD / OIDC / Workload Identity
############################################
role_based_access_control_enabled = true
rbac_aad_azure_rbac_enabled = false
rbac_aad_azure_rbac_enabled = var.azure_rbac_enabled
rbac_aad_admin_group_object_ids = var.admin_group_object_ids
rbac_aad_tenant_id = data.azurerm_client_config.current.tenant_id
local_account_disabled = var.local_account_disabled
workload_identity_enabled = true
oidc_issuer_enabled = true

Expand Down
9 changes: 9 additions & 0 deletions infrastructure/azure/aks/validations.tf
Original file line number Diff line number Diff line change
Expand Up @@ -9,5 +9,14 @@ resource "terraform_data" "validations" {
condition = var.attach_acr != true || var.acr_id != null
error_message = "acr_id is required when attach_acr is true. Leave attach_acr null (legacy) or set it false for clusters without an ACR."
}

# Disabling local accounts removes the certificate-based admin path, leaving Entra ID as the only
# way in. Without Azure RBAC or an admin group, no identity is authorized against the API server:
# the cluster stays reachable only through whatever admin kubeconfig was issued beforehand, and
# becomes unrecoverable from configuration once that credential stops working.
precondition {
condition = var.local_account_disabled != true || var.azure_rbac_enabled || try(length(var.admin_group_object_ids), 0) > 0
error_message = "local_account_disabled = true removes the only certificate-based path into the cluster. Set azure_rbac_enabled = true, or provide admin_group_object_ids, so at least one Entra ID identity stays authorized."
}
}
}
Loading
Loading