• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

pantsbuild / pants / 25441711719

06 May 2026 02:31PM UTC coverage: 92.915%. Remained the same
25441711719

push

github

web-flow
use sha pin (with comment) format for generated actions (#23312)

Per the GitHub Action best practices we recently enabled at #23249, we
should pin each action to a SHA so that the reference is actually
immutable.

This will -- I hope -- knock out a large chunk of the 421 alerts we
currently get from zizmor. The next followup would then be upgrades and
harmonizing the generated and none-generated pins.

Notice: This idea was suggested by Claude while going over pinact output
and I was surprised to see that post processing the yaml wasn't too
gross.

92206 of 99237 relevant lines covered (92.91%)

4.04 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

97.06
/src/python/pants/backend/terraform/dependency_inference.py
1
# Copyright 2021 Pants project contributors (see CONTRIBUTORS.md).
2
# Licensed under the Apache License, Version 2.0 (see LICENSE).
3
from __future__ import annotations
6✔
4

5
from collections.abc import Iterable, Sequence
6✔
6
from dataclasses import dataclass
6✔
7
from pathlib import PurePath
6✔
8

9
from pants.backend.python.subsystems.python_tool_base import PythonToolRequirementsBase
6✔
10
from pants.backend.python.target_types import EntryPoint
6✔
11
from pants.backend.python.util_rules.pex import (
6✔
12
    VenvPex,
13
    VenvPexProcess,
14
    create_venv_pex,
15
    setup_venv_pex_process,
16
)
17
from pants.backend.python.util_rules.pex import rules as pex_rules
6✔
18
from pants.backend.terraform.target_types import (
6✔
19
    TerraformBackendTarget,
20
    TerraformDependenciesField,
21
    TerraformDeploymentFieldSet,
22
    TerraformLockfileTarget,
23
    TerraformModuleSourcesField,
24
    TerraformVarFileTarget,
25
)
26
from pants.base.glob_match_error_behavior import GlobMatchErrorBehavior
6✔
27
from pants.base.specs import DirGlobSpec, DirLiteralSpec, RawSpecs
6✔
28
from pants.core.target_types import LockfileTarget
6✔
29
from pants.engine.addresses import Addresses
6✔
30
from pants.engine.fs import CreateDigest, Digest, FileContent
6✔
31
from pants.engine.internals.build_files import resolve_address
6✔
32
from pants.engine.internals.graph import (
6✔
33
    determine_explicitly_provided_dependencies,
34
    hydrate_sources,
35
    resolve_targets,
36
)
37
from pants.engine.internals.native_engine import Address, AddressInput
6✔
38
from pants.engine.internals.selectors import concurrently
6✔
39
from pants.engine.intrinsics import create_digest
6✔
40
from pants.engine.process import Process, execute_process_or_raise
6✔
41
from pants.engine.rules import collect_rules, implicitly, rule
6✔
42
from pants.engine.target import (
6✔
43
    DependenciesRequest,
44
    FieldSet,
45
    HydrateSourcesRequest,
46
    InferDependenciesRequest,
47
    InferredDependencies,
48
    Target,
49
)
50
from pants.engine.unions import UnionRule
6✔
51
from pants.util.dirutil import group_by_dir
6✔
52
from pants.util.logging import LogLevel
6✔
53
from pants.util.ordered_set import OrderedSet
6✔
54
from pants.util.resources import read_resource
6✔
55
from pants.util.strutil import bullet_list, softwrap
6✔
56

57
# pants: infer-dep(hcl2.lock*)
58

59

60
class TerraformHcl2Parser(PythonToolRequirementsBase):
6✔
61
    options_scope = "terraform-hcl2-parser"
6✔
62
    help_short = "Used to parse Terraform modules to infer their dependencies."
6✔
63

64
    # versions 4.3.2+ have parsing issues; bump once resolved
65
    default_requirements = ["python-hcl2>=3.0.5,<=4.3.0"]
6✔
66

67
    register_interpreter_constraints = True
6✔
68

69
    default_lockfile_resource = ("pants.backend.terraform", "hcl2.lock")
6✔
70

71

72
@dataclass(frozen=True)
6✔
73
class ParserSetup:
6✔
74
    pex: VenvPex
6✔
75

76

77
@rule
6✔
78
async def setup_parser(hcl2_parser: TerraformHcl2Parser) -> ParserSetup:
6✔
79
    parser_script_content = read_resource("pants.backend.terraform", "hcl2_parser.py")
6✔
80
    if not parser_script_content:
6✔
81
        raise ValueError("Unable to find source to hcl2_parser.py wrapper script.")
×
82

83
    parser_content = FileContent(
6✔
84
        path="__pants_tf_parser.py", content=parser_script_content, is_executable=True
85
    )
86
    parser_digest = await create_digest(CreateDigest([parser_content]))
6✔
87

88
    parser_pex = await create_venv_pex(
6✔
89
        **implicitly(
90
            hcl2_parser.to_pex_request(
91
                main=EntryPoint(PurePath(parser_content.path).stem), sources=parser_digest
92
            )
93
        )
94
    )
95
    return ParserSetup(parser_pex)
6✔
96

97

98
@dataclass(frozen=True)
6✔
99
class ParseTerraformModuleSources:
6✔
100
    sources_digest: Digest
6✔
101
    paths: tuple[str, ...]
6✔
102

103

104
@rule
6✔
105
async def setup_process_for_parse_terraform_module_sources(
6✔
106
    request: ParseTerraformModuleSources, parser: ParserSetup
107
) -> Process:
108
    dir_paths = ", ".join(sorted(group_by_dir(request.paths).keys()))
6✔
109

110
    process = await setup_venv_pex_process(
6✔
111
        VenvPexProcess(
112
            parser.pex,
113
            argv=request.paths,
114
            input_digest=request.sources_digest,
115
            description=f"Parse Terraform module sources: {dir_paths}",
116
            level=LogLevel.DEBUG,
117
        ),
118
        **implicitly(),
119
    )
120
    return process
6✔
121

122

123
@dataclass(frozen=True)
6✔
124
class TerraformModuleDependenciesInferenceFieldSet(FieldSet):
6✔
125
    required_fields = (TerraformModuleSourcesField, TerraformDependenciesField)
6✔
126

127
    sources: TerraformModuleSourcesField
6✔
128
    dependencies: TerraformDependenciesField
6✔
129

130

131
class InferTerraformModuleDependenciesRequest(InferDependenciesRequest):
6✔
132
    infer_from = TerraformModuleDependenciesInferenceFieldSet
6✔
133

134

135
@dataclass(frozen=True)
6✔
136
class TerraformDeploymentDependenciesInferenceFieldSet(TerraformDeploymentFieldSet):
6✔
137
    pass
6✔
138

139

140
class InferTerraformDeploymentDependenciesRequest(InferDependenciesRequest):
6✔
141
    infer_from = TerraformDeploymentDependenciesInferenceFieldSet
6✔
142

143

144
def find_targets_of_type(tgts, of_type) -> tuple:
6✔
145
    if tgts:
4✔
146
        return tuple(e for e in tgts if isinstance(e, of_type))
4✔
147
    else:
148
        return ()
4✔
149

150

151
@dataclass(frozen=True)
6✔
152
class TerraformDeploymentInvocationFilesRequest:
6✔
153
    """TODO: is there a way to convert between FS? We could convert the inference FS to the deployment FS itself"""
154

155
    address: Address
6✔
156
    dependencies: TerraformDependenciesField
6✔
157

158

159
@dataclass(frozen=True)
6✔
160
class TerraformDeploymentInvocationFiles:
6✔
161
    """The files passed in to the invocation of `terraform`"""
162

163
    backend_configs: tuple[TerraformBackendTarget, ...]
6✔
164
    vars_files: tuple[TerraformVarFileTarget, ...]
6✔
165
    lockfile: LockfileTarget | None
6✔
166

167

168
@rule
6✔
169
async def get_terraform_backend_and_vars(
6✔
170
    field_set: TerraformDeploymentInvocationFilesRequest,
171
) -> TerraformDeploymentInvocationFiles:
172
    this_address = field_set.address
4✔
173

174
    explicit_deps = await determine_explicitly_provided_dependencies(
4✔
175
        **implicitly(DependenciesRequest(field_set.dependencies))
176
    )
177
    tgts_in_dir, explicit_deps_tgt = await concurrently(
4✔
178
        resolve_targets(
179
            **implicitly(
180
                RawSpecs(
181
                    description_of_origin="terraform infer deployment dependencies",
182
                    dir_literals=(DirLiteralSpec(this_address.spec_path),),
183
                )
184
            )
185
        ),
186
        resolve_targets(**implicitly(Addresses(explicit_deps.includes))),
187
    )
188
    return identify_terraform_backend_and_vars(explicit_deps_tgt, tgts_in_dir)
4✔
189

190

191
class InvalidLockfileException(Exception):
6✔
192
    @classmethod
6✔
193
    def too_many_lockfiles(
6✔
194
        cls, lockfiles: Iterable[TerraformLockfileTarget]
195
    ) -> InvalidLockfileException:
196
        addresses = sorted(tgt.address.spec for tgt in lockfiles)
×
197
        return cls(
×
198
            softwrap(
199
                f"""\
200
                A Terraform deployment has {len(addresses)} lockfiles supplied:
201
                {bullet_list(addresses)}
202
                Terraform requires at most 1 lockfile; it must be called `.terraform.lock.hcl`;
203
                and it must be in the same directory as the root module.
204

205
                Pants generates targets for Terraform lockfiles automatically.
206
                If you manually added `{TerraformLockfileTarget.alias}` targets, removing them should resolve this error.
207
                If you have not, please report this as a bug.
208
                """
209
            )
210
        )
211

212

213
def identify_terraform_backend_and_vars(
6✔
214
    explicit_deps: Sequence[Target], tgts_in_dir: Sequence[Target]
215
) -> TerraformDeploymentInvocationFiles:
216
    has_explicit_backend = find_targets_of_type(explicit_deps, TerraformBackendTarget)
4✔
217
    if not has_explicit_backend:
4✔
218
        # Note: Terraform does not support multiple backends, but dep inference isn't the place to enforce that
219
        backend_targets = find_targets_of_type(tgts_in_dir, TerraformBackendTarget)
4✔
220
    else:
221
        backend_targets = has_explicit_backend
2✔
222

223
    has_explicit_var = find_targets_of_type(explicit_deps, TerraformVarFileTarget)
4✔
224
    if not has_explicit_var:
4✔
225
        vars_targets = find_targets_of_type(tgts_in_dir, TerraformVarFileTarget)
4✔
226
    else:
227
        vars_targets = has_explicit_var
2✔
228

229
    lockfiles = find_targets_of_type(tgts_in_dir, TerraformLockfileTarget)
4✔
230
    if len(lockfiles) == 1:
4✔
231
        lockfile = lockfiles[0]
3✔
232
    elif len(lockfiles) > 1:
4✔
233
        # Unlikely, since we generate them based on a constant filename.
234
        # Indicates manual specification of targets
235
        raise InvalidLockfileException.too_many_lockfiles(lockfiles)
×
236
    else:
237
        lockfile = None
4✔
238

239
    return TerraformDeploymentInvocationFiles(backend_targets, vars_targets, lockfile)
4✔
240

241

242
async def _infer_dependencies_from_sources(
6✔
243
    request: InferTerraformModuleDependenciesRequest,
244
) -> list[Address]:
245
    """Parse the source code for references to other modules."""
246
    hydrated_sources = await hydrate_sources(
4✔
247
        HydrateSourcesRequest(request.field_set.sources), **implicitly()
248
    )
249
    paths = OrderedSet(
4✔
250
        filename for filename in hydrated_sources.snapshot.files if filename.endswith(".tf")
251
    )
252
    result = await execute_process_or_raise(
4✔
253
        **implicitly(
254
            ParseTerraformModuleSources(
255
                sources_digest=hydrated_sources.snapshot.digest,
256
                paths=tuple(paths),
257
            )
258
        )
259
    )
260
    candidate_spec_paths = [line for line in result.stdout.decode("utf-8").split("\n") if line]
4✔
261
    # For each path, see if there is a `terraform_module` target at the specified spec_path.
262
    candidate_targets = await resolve_targets(
4✔
263
        **implicitly(
264
            RawSpecs(
265
                dir_globs=tuple(DirGlobSpec(path) for path in candidate_spec_paths),
266
                unmatched_glob_behavior=GlobMatchErrorBehavior.ignore,
267
                description_of_origin="the `terraform_module` dependency inference rule",
268
            )
269
        )
270
    )
271
    # TODO: Need to either implement the standard ambiguous dependency logic or ban >1 terraform_module
272
    # per directory.
273
    terraform_module_addresses = [
4✔
274
        tgt.address for tgt in candidate_targets if tgt.has_field(TerraformModuleSourcesField)
275
    ]
276
    return terraform_module_addresses
4✔
277

278

279
async def _infer_lockfile(request: InferTerraformModuleDependenciesRequest) -> list[Address]:
6✔
280
    """Pull in the lockfile for a Terraform module.
281

282
    This is necessary for `terraform validate`.
283
    """
284
    invocation_files = await get_terraform_backend_and_vars(
4✔
285
        TerraformDeploymentInvocationFilesRequest(
286
            request.field_set.address, request.field_set.dependencies
287
        )
288
    )
289
    if invocation_files.lockfile:
4✔
290
        return [invocation_files.lockfile.address]
3✔
291
    else:
292
        return []
4✔
293

294

295
@rule
6✔
296
async def infer_terraform_module_dependencies(
6✔
297
    request: InferTerraformModuleDependenciesRequest,
298
) -> InferredDependencies:
299
    terraform_module_addresses = await _infer_dependencies_from_sources(request)
4✔
300
    lockfile_address = await _infer_lockfile(request)
4✔
301

302
    return InferredDependencies([*terraform_module_addresses, *lockfile_address])
4✔
303

304

305
@rule
6✔
306
async def infer_terraform_deployment_dependencies(
6✔
307
    request: InferTerraformDeploymentDependenciesRequest,
308
) -> InferredDependencies:
309
    root_module_address_input = request.field_set.root_module.to_address_input()
2✔
310
    root_module = await resolve_address(**implicitly({root_module_address_input: AddressInput}))
2✔
311
    deps = [root_module]
2✔
312

313
    invocation_files = await get_terraform_backend_and_vars(
2✔
314
        TerraformDeploymentInvocationFilesRequest(
315
            request.field_set.address, request.field_set.dependencies
316
        )
317
    )
318
    deps.extend(e.address for e in invocation_files.backend_configs)
2✔
319
    deps.extend(e.address for e in invocation_files.vars_files)
2✔
320
    # lockfile is attached to the module itself
321

322
    return InferredDependencies(deps)
2✔
323

324

325
def rules():
6✔
326
    return [
6✔
327
        *collect_rules(),
328
        *pex_rules(),
329
        UnionRule(InferDependenciesRequest, InferTerraformModuleDependenciesRequest),
330
        UnionRule(InferDependenciesRequest, InferTerraformDeploymentDependenciesRequest),
331
    ]
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc