deps: update setup-ok tool versions - #186
Open
kjoremiljo-renovate[bot] wants to merge 1 commit into
Open
Conversation
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
from
January 8, 2026 16:16
aaf46c4 to
8a1f7e8
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
5 times, most recently
from
January 16, 2026 08:18
5ddb2d1 to
63286e3
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
6 times, most recently
from
February 2, 2026 23:17
39c5709 to
49c409d
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
4 times, most recently
from
February 9, 2026 00:44
187b7ae to
31f2dcc
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
4 times, most recently
from
February 18, 2026 16:32
83e9d6a to
159d03b
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
5 times, most recently
from
February 27, 2026 13:37
aeac82b to
a8f80a7
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
3 times, most recently
from
March 3, 2026 21:20
1453478 to
bc78ade
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
7 times, most recently
from
April 1, 2026 08:41
972f32a to
a5cbedf
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
3 times, most recently
from
April 6, 2026 18:32
0b93e7b to
dd45c77
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
3 times, most recently
from
April 17, 2026 11:33
b15cbce to
05ed531
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
3 times, most recently
from
April 24, 2026 07:49
1e9b887 to
719765e
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
3 times, most recently
from
April 24, 2026 08:29
f345339 to
6ea494a
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
from
April 24, 2026 08:37
6ea494a to
0aaffac
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
2 times, most recently
from
April 24, 2026 08:57
c46a4cd to
047d378
Compare
kjoremiljo-renovate
Bot
force-pushed
the
ok-renovate/setup-ok-tool-versions
branch
3 times, most recently
from
April 27, 2026 19:37
7308221 to
699b23e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.10.1→v0.16.0v0.96.1→v1.1.21.14.3→1.15.8v4.50.1→v4.53.3v5.15.3→v5.20.1v5.21.0(+1)v1.13.0→v1.19.0Release Notes
gruntwork-io/boilerplate (gruntwork-io/boilerplate)
v0.16.0Compare Source
What's Changed
New Contributors
Full Changelog: gruntwork-io/boilerplate@v0.15.0...v0.16.0
v0.15.0Compare Source
🐛 Bug Fixes
Handling ancestor dependencies
Added support for recursive dependencies to the manifest to ensure that nested and ancestor dependencies are properly processed and resolved. Additional testing has also been included to verify this behavior.
Note that although this isn't a breaking change, this does require an update to the manifest schema, and as such you'll want to ensure that your manifest parsing isn't impacted. Due to the fact that a field has only been added, this risk is minimal if you use a modern YAML/JSON parser.
What's Changed
Full Changelog: gruntwork-io/boilerplate@v0.14.0...v0.15.0
v0.14.0Compare Source
🛠️ Breaking Changes
Dependencies Now Generate Concurrently
Dependencies in templates now generate concurrently by default, with the option to run sequentially or with different concurrency limits using the
--parallelismflag.This will be a breaking change for any templates that relied on dependencies generating in the exact order in which they are defined in templates (e.g. if multiple dependencies generate the same file, expecting later dependencies to overwrite earlier ones).
For more information read the
for_eachdocumentation.What's Changed
Full Changelog: gruntwork-io/boilerplate@v0.13.0...v0.14.0
v0.13.0Compare Source
✨ New Features
Manifest File Generation
Boilerplate can now produce a manifest file that records every file generated during a run, along with SHA256 checksums. Enable it with the new --manifest flag:
boilerplate \ --template-url ./templates/service \ --output-folder ./output \ --non-interactive \ --manifestThis creates a boilerplate-manifest.yaml in the output directory containing:
The manifest format is auto-detected from the file extension:
.jsonproduces JSON, everything else produces YAML. To write to a custom path, use--manifest-file:boilerplate \ --template-url ./templates/service \ --output-folder ./output \ --non-interactive \ --manifest-file ./reports/manifest.jsonThis is useful for auditing which files came from a template, drift detection by comparing checksums after the fact, and CI/CD pipelines that need to programmatically consume the list of generated files in downstream steps.
See https://boilerplate.gruntwork.io/advanced/manifest/ for details.
Exported validation Package
The validation package is now exported directly, so consumers of Boilerplate as a library can import validation instead of relying on the re-export through the variables package.
📖 Documentation Updates
🧹 Chores
What's Changed
validationby @yhakbar in #287Full Changelog: gruntwork-io/boilerplate@v0.12.1...v0.13.0
v0.12.1Compare Source
What's Changed
Full Changelog: gruntwork-io/boilerplate@v0.12.0...v0.12.1
v0.12.0Compare Source
🛠️ Breaking Changes
Default variables no longer prompt for values by default in interactive mode
Variables with default values no longer prompt users for interactive input unless using the new
confirmattribute.This ensures that dynamically determined values for variables won't cause errors during interactive generation and reduces the number of prompts users encounter while generating from a template interactively.
Validation
lengthuses functional form nowThe
lengthvalidation now uses the functional formlength(min, max)instead of the previouslength-min-maxform.All validations with parameters will use this functional form going forward.
✨ New Features
New validation type
regex(pattern)supported.The validation type
regex(pattern)is now supported to validate variable values against regex patterns.e.g.
⚙️ Process Updates
WASM build target added
Releases now support JavaScript runtimes through compiled WASM build targets.
📖 Documentation Updates
Boilerplate website created
Boilerplate now has a dedicated website at https://boilerplate.gruntwork.io to document the behavior of Boilerplate.
What's Changed
Full Changelog: gruntwork-io/boilerplate@v0.11.1...v0.12.0
v0.11.1Compare Source
What's Changed
Full Changelog: gruntwork-io/boilerplate@v0.11.0...v0.11.1
v0.11.0Compare Source
❌ No Release Assets
Use release v0.11.1 instead which fixes the deploy pipeline to create release assets.
🛠️ Breaking Changes
ProcessTemplate and ProcessTemplateWithContext now take variables.Dependency as a pointer.
What's Changed
New Contributors
Full Changelog: gruntwork-io/boilerplate@v0.10.1...v0.11.0
gruntwork-io/terragrunt (gruntwork-io/terragrunt)
v1.1.2Compare Source
✨ New Features
Scaffold straight from the catalog README view with
ctrl+dIn the
terragrunt catalogTUI, pressingctrl+dwhile reading a component's README now scaffolds it immediately, skipping the interactive form. Module and template inputs are written as# TODOplaceholders, and unit/stack copies get a fully placeholderterragrunt.values.hcl. The hint bar at the bottom of the README view advertises the new key.🏎️ Performance Improvements
Fewer filesystem checks when resolving
find_in_parent_folders()find_in_parent_folders()walks up from a unit toward the filesystem root, checking each directory for the configuration file it was asked to find. Even when the call named a file, as infind_in_parent_folders("root.hcl"), each directory along the way was also checked for the default configuration filenames. Units sharing a parent chain then repeated every check their siblings had already made.Terragrunt now checks only the filename the call names, and reuses what it already learned about a directory for the rest of the command. Deeply nested estates benefit most, since every level between a unit and its root configuration used to be re-checked once per unit.
In micro-benchmarks, resolving the root configuration for 100 units nested eight directories deep went from 4.8ms to 0.49ms. Across the benchmarked shapes the lookups run between 7x and 10x faster, and the time saved grows with both the number of units and how deeply they sit below their root configuration.
🐛 Bug Fixes
Fixed roles assuming themselves for backend operations
A regression in v1.1.1 broke setups that provide static AWS credentials and configure a role via the
iam_roleattribute, the--iam-assume-roleflag, orTG_IAM_ASSUME_ROLE.In those setups, Terragrunt assumes the role once at the start of a run, and every later AWS call uses that role session. In v1.1.1, backend operations like bootstrapping the state bucket started performing an extra role assumption of their own. Since the run was already using the role session at that point, the role tried to assume itself, and AWS rejected the call with an
AccessDeniederror unless the role's trust policy happened to include the role itself.Backend operations now reuse the role session from the start of the run, as they did before v1.1.1.
This does not affect the
assume_roleattribute of theremote_stateblock. Roles configured there are backend-specific and are still assumed on top of the supplied credentials, so the cross-account role assumption should continue to work as expected.Local sources no longer re-init when uncopied files change
For units with a local
source, Terragrunt decides whether the cached copy is stale by hashing the source directory. That hash previously covered every file in the directory, including hidden files andexclude_from_copymatches that are never copied into the cache. Creating or touching such a file (an editor swap file, a scratch note) changed the hash, forcing a needless re-copy and auto-init on the next run.The hash now covers only the files a copy would deliver, honoring the default hidden-file rule along with
include_in_copyandexclude_from_copy. Files that never reach the cache no longer trigger re-initialization.Fixed
widthtruncation of colored and multi-byte log contentThe
widthoption in a custom log format sizes a column to a fixed number of visible characters. When the content held color codes or multi-byte characters and was longer than the column, truncation cut the raw bytes: it could slice through the middle of a color code, leaving color bleeding into the rest of the line, or split a multi-byte character into invalid output, and it dropped more visible text than the configured width.widthnow measures and cuts by visible characters. Color codes are preserved intact, multi-byte characters are never split, and the column keeps exactly the requested number of visible characters.Provider cache downloads now require a secret URL
The Provider Cache Server now hardens the download endpoint that fetches provider archives on the caller's behalf. That endpoint attaches whatever registry credentials are configured for the upstream host, and it was the only one on the server that did not require the token generated for the run, so any other process on the machine could use a running cache server to pull artifacts from a private registry with the credentials of whoever started the run.
The download URLs handed to OpenTofu and Terraform now carry a secret path segment, generated fresh each time the cache server starts and redacted from the server's own logs. Requests that omit the segment get a 404.
Run report no longer mangles the names of paths that share a prefix with the working directory
When a run's path shared a string prefix with the working directory without being nested under it, the run report shortened its name by shearing off the prefix mid-segment. A working directory of
/repo/projectalongside a run at/repo/project-staging/unitproduced the name-staging/unit.The report now shortens a path only when it is genuinely nested under the working directory. Sibling paths keep their full name.
Feature flag defaults no longer leak between units in
run --allA
featureblock'sdefaultwas recorded once per run and shared by every unit. Duringrun --all, the first unit to be parsed set the value for a flag name, so a unit definingdefault = falsecould evaluatefeature.toggle.valueastruebecause a sibling unit was parsed first. Which unit won depended on parsing order, making the result vary between runs.Defaults are now resolved per unit, including defaults inherited through
include. Overrides passed with--featureorTG_FEATUREcontinue to apply to every unit in the run.Thanks to @dhotcolorado for reporting and fixing this!
Fixed S3 source downloads under EKS Pod Identity
Downloading unit sources from private S3 buckets (
s3::https://...) now works when EKS Pod Identity is the only credential source. Previously, the bundledaws-sdk-gov1 rejected the Pod Identity Agent endpoint (169.254.170.23) because it only allowed loopback hosts. Terragrunt now usesaws-sdk-gov1.55.6, which allows the EKS and ECS container credential endpoints.🧪 Experiments Added
otel-logsexperiment exports logs to OpenTelemetryTerragrunt previously emitted only traces and metrics, so there was no way to ship its log output to an OpenTelemetry backend or correlate log lines with the spans of a failed run.
Enable the new
otel-logsexperiment to add an OpenTelemetry logs signal, configured withTG_TELEMETRY_LOGS_EXPORTER:none- no log exporting, the default.console- write log records to the console as JSON.otlpHttp- export logs to an OpenTelemetry collector over HTTP.otlpGrpc- export logs to an OpenTelemetry collector over gRPC.The OTLP exporters read the endpoint from the standard
OTEL_EXPORTER_OTLP_ENDPOINTenvironment variable. SetTG_TELEMETRY_LOGS_EXPORTER_INSECURE_ENDPOINT=trueto disable TLS when collecting locally. Records emitted while a span is active carry its trace and span IDs, so a failed unit's logs link to its span in the backend. Without the experiment enabled, the logs exporter stays inert regardless ofTG_TELEMETRY_LOGS_EXPORTER.profilingexperiment adds pprof collection for Terragrunt runsEnable the new
profilingexperiment to collect CPU profiles, memory (heap) profiles, and goroutine profiles (stack traces of all goroutines) using CLI flags. Profiling is intended for debugging the performance of Terragrunt itself, and for exploring ways to optimize Terragrunt as an application; it will not help with improving the performance of the infrastructure Terragrunt manages.Example:
Use
--profile-dirto collect all profiles into a single directory with conventional names (terragrunt_cpu.prof,terragrunt_mem.prof,terragrunt_goroutine.prof):The same behavior is available via environment variables when the
profilingexperiment is enabled:TG_PROFILE_CPUTG_PROFILE_MEMTG_PROFILE_GOROUTINETG_PROFILE_DIRWhen using
--profile-dirorTG_PROFILE_DIR, Terragrunt also setsTOFU_CPU_PROFILEfor each unit so downstream OpenTofu processes (OpenTofu 1.11 or later) write their own CPU profiles into unit-specific subdirectories. An explicitly setTOFU_CPU_PROFILEis never overridden.🧪 Experiments Updated
azure-backendnow manages Azure Storage remote stateThe
azure-backendexperiment now enables functional Terragrunt support for the Azure Storage (azurerm) remote-state backend.When the experiment is enabled, Terragrunt can bootstrap the resource group, storage account, and blob container used by
remote_state { backend = "azurerm" }, detect whether the backend needs bootstrapping, converge blob versioning and soft-delete settings, delete state blobs or containers, and migrate state blobs within the same storage account.Terragrunt-only settings such as
location, the storage account SKU options, theskip_*flags,enable_soft_delete,soft_delete_retention_days, andmsi_resource_idare consumed by Terragrunt and removed before it runs OpenTofu/Terraform withinit -backend-config, so the underlyingazurermbackend receives only keys it understands.msi_resource_idis not bootstrap-only: it also selects the managed identity used for delete and migrate.This remains opt-in while the experiment is active:
Thanks to @omattsson for driving this support forward.
oci- Credential helpers for OCI module sourcesoci://module downloads now use the Docker credential helpers you already have configured, so registries like Amazon ECR authenticate automatically with no extra setup.oci- Content-addressable caching for OCI module sourcesoci://module sources now integrate with Content Addressable Storage. When theociexperiment is enabled, downloads are cached by their manifest digest, so a repeated fetch of the same tag or digest is served from the local store instead of re-downloaded from the registry.Mutable tags stay correct: every fetch re-resolves the tag to its current manifest digest at download time, so re-pushing a module under the same tag invalidates the cache and pulls the new content rather than serving a stale copy. A digest-pinned source (
?digest=sha256:...) skips registry resolution and keys the cache directly.oci- Downloading modules from OCI registriesThe
ociexperiment now downloads source code (including OpenTofu modules) from OCI Distribution registries. When enabled, Terragrunt acceptsoci://source URLs in Terragrunt configurations (includingterraform.sourceattributes). Specify eithertagordigest; omitting both selects thelatesttag.//subdirselectors are supported. Artifacts follow the same publishing contract OpenTofu 1.10 consumes natively.Authentication covers static credentials via interim
TG_TMP_OCI_*environment variables and read-only ambient discovery of Docker and containers auth files. Static credentials can be limited to one registry withTG_TMP_OCI_REGISTRY; without it, the configured token or username and password may be offered to any registry the process contacts. Credential helpers (such asecr-login) are not invoked yet, so registries that need per-run token minting only work while an externally obtained login is present in an ambient file.When the experiment is disabled,
oci://sources remain unsupported.For setup steps, see the experiment documentation.
Pull Requests
✨ Features
otel-logsexperiment by @yhakbar in #6279🐛 Bug Fixes
TF_TOKEN_*rendering by @yhakbar in #6509🏎️ Performance
find_in_parent_folders()by @yhakbar in #6545📖 Documentation
🧹 Chores
/reference/hcl/blocks/by @yhakbar in #6485versionattribute by @yhakbar in #6482fd -tf -e go -x golines -wto avoid run-on lines by @yhakbar in #6484versionattribute by @yhakbar in #6487cas.Venvby @yhakbar in #6488vsopsby @yhakbar in #6506v1.1.1Compare Source
🐛 Bug Fixes
Chained role assumption for the S3 backend
When AWS credentials were supplied through
--auth-provider-cmdor environment variables, Terragrunt ignored theassume_roleattribute of theremote_stateblock for its own backend operations, such as bootstrapping the state bucket. In cross-account setups this caused access errors, even though OpenTofu/Terraform itself assumed the role correctly during runs.Terragrunt now uses the supplied credentials as the source identity and assumes the configured role on top of them. The same applies to roles configured via the
iam_roleattribute or the--iam-assume-roleflag, and to fetching dependency outputs directly from S3 state.Safer temporary clone directories for
terragrunt catalogTerragrunt now creates a fresh temporary clone directory for each catalog load, rejects symlinked clone roots, and removes catalog clones when the TUI session exits.
Resolve
dependencyoutputs for units that reference a dependency in a hook,extra_arguments, orremote_stateblockResolving a unit's
dependencyoutputs for a downstream unit no longer fails when that unit references its own dependency in:before_hook,after_hook, orerror_hookextra_argumentsblockremote_stateblockPreviously these raised
There is no variable named "dependency"on the downstream unit, and aremote_statereference could crash Terragrunt.Limit IaC engine archive extraction
Terragrunt now protects developer machines and CI runners from engine archives that expand into unexpectedly large amounts of data. If an IaC engine package is unusually large or contains too many files, Terragrunt stops processing it before it can consume excessive disk space.
--filter-allow-destroywith...[]dependent-traversal filters no longer fails--filter-allow-destroy --filter '...[HEAD~1...HEAD]'failed with "Too many command line arguments" or hung when the deleted unit had dependents. Terragrunt now correctly plans and destroys deleted units regardless of whether dependents are included in the run.Fix
findandlistmissing units inside generated stacks for Git-based filtersterragrunt findandterragrunt listwith a Git-based filter (for example--filter '[HEAD^1...HEAD]') now detect units inside generated stacks. Previously they did not generate stacks in the worktrees they create for the comparison, so no unit nested in a generated stack was ever surfaced, whileterragrunt run --allwith the same filter targeted those units correctly.This affected every change that lands inside a generated stack, including a modified
terragrunt.stack.hcl, a change to a unit's own files, and a change to a file the stack reads viaread_terragrunt_configormark_glob_as_read.Stacks are generated only inside the comparison worktrees;
findandliststill do not generate stacks in your current working directory by default.Treat Git source
refvalues strictly as referencesTerragrunt now passes the
reffrom a Git module source to git strictly as a reference when downloading through content-addressable storage. Previously a source whoserefbegan with a git option (for example a value starting with--) could be interpreted by git as an option rather than a reference while fetching the source.Terragrunt now terminates git option parsing before the repository and reference arguments in its
fetch,clone, andls-remoteinvocations, so these values can only ever be read as the repository and reference they are meant to be. Normal refs, branches, tags, and commit SHAs continue to work unchanged.hcl validateresolvesget_original_terragrunt_dir()to the discovered unitterragrunt hcl validateandterragrunt hcl validate --inputsnow resolveget_original_terragrunt_dir()to each discovered unit's own directory instead of the directory the command was launched from. Previously, when the command ran from a parent directory that discovered units in subdirectories, anyread_terragrunt_config()call that built a path relative toget_original_terragrunt_dir()resolved against the wrong directory and failed with "You attempted to run terragrunt in a folder that does not contain a terragrunt.hcl file", even thoughplan,apply, andrun validateworked on the same configuration.Both commands now set the original config path per discovered unit before parsing, matching the behavior of
runandbackend bootstrap, so relative paths resolve against the unit that owns them.Respect
-lockfile=readonlyduring provider cachingWhen you pass
-lockfile=readonlytoinit, Terragrunt no longer generates or updates.terraform.lock.hclwhile warming the provider cache. Previously the cache step could write the lock file before OpenTofu/Terraform ran, so the read-only check always passed and silently defeated the flag.Terragrunt now leaves the lock file untouched and lets OpenTofu/Terraform enforce it, failing when the lock file is missing or incomplete. The flag is honored whether it is supplied on the command line or through the
TF_CLI_ARGSorTF_CLI_ARGS_initenvironment variables.run --allno longer crashes on dependency discovery with graph filtersRunning
run --allwith a filter that expands a git range through the dependency graph (for example[HEAD~1...HEAD]...) could fail during dependency discovery, reporting that a component "is missing its working directory". Whether it happened depended on the size and shape of the changed unit's dependency closure, so the same filter succeeded on smaller branches andfindwas unaffected.A dependency reached from several units at once could become visible to discovery before its working directory was set, so a concurrent traversal could read it before it was complete. Dependencies now have their working directory set before they become visible, so
run --allbehaves the same regardless of graph size.terraform_binaryrespected byrun --allwhen bothtofuandterraformare onPATHrun --allignored a unit'sterraform_binarysetting and fell back to the auto-detected default (OpenTofu when both binaries are onPATH). The per-unit options used to execute each unit are cloned from the stack options, whose binary path is the auto-detected default, and the configured value was never applied to them.Each unit now honors its own
terraform_binary, matching the behavior of a singlerun. Setting--tf-pathorTG_TF_PATHstill takes precedence over the config value.S3 bucket creation failures report the underlying error
When creating the state bucket failed during backend bootstrap, the reported error was a misleading
NoSuchBucketfrom a follow-up access check, hiding the actual cause. The original creation error, such asAccessDenied, is now part of the reported message.Allow empty
localsblocks interragrunt.stack.hclFixed a bug where an empty
locals {}block in a stack configuration could breakstack generate.Clear error when
terraform.sourcereferences a dependency outputA
terraform.sourcethat referencesdependency.<name>.outputs.<key>is now rejected with a message explaining that the module source must be resolvable before dependencies are evaluated.Terragrunt resolves the source while discovering units and building the run queue, before any dependency has run, so such a source can never be satisfied. Previously it surfaced a cryptic decode error.
🧪 Experiments Added
oci- Module sources from OCI registriesThe
ociexperiment has been added as the gate for downloading source code (including OpenTofu modules) from OCI Distribution registries usingoci://schema URLs in Terragrunt configurations (includingterraform.sourceattributes). This targets the same registries OpenTofu 1.10 supports natively, such as Amazon ECR, GitHub Container Registry, Azure Container Registry, Google Artifact Registry, and self-hosted or air-gapped registries.Enabling the experiment has no behavioral effect yet: the getter that will resolve
oci://sources is not wired into source downloading, sooci://sources still fail to download. Functional support will land in follow-up releases, gated by this experiment.For setup steps, see the experiment documentation.
version-attribute- Resolve registry modules from a version constraintThe
version-attributeexperiment has been added to gate a newversionattribute on theterraformblock. It holds a version constraint (such as~> 3.3or>= 1.0.0, < 2.0.0) for atfr://registry module, and Terragrunt resolves it to the highest published version that satisfies the constraint before downloading:This brings the
terraformblock to parity with theversionargument on OpenTofu and Terraformmoduleblocks. The attribute applies totfr://sources only, and cannot be combined with an inline?version=on the same source.Enable it with
--experiment version-attribute. For setup steps and the criteria for stabilization, see the experiment documentation.⚙️ Process Updates
Friendly panic reports
Terragrunt now writes a
terragrunt-crash-YYYYMMDDTHHMMSSZ-<pid>.logfile when it crashes.The report includes runtime details, the command line, the panic message, and the stack trace. You can conveniently share this file (after reviewing for sensitive information) to report panics if Terragrunt crashes.
Pull Requests
✨ Features
versionattribute on theterraformblock by @yhakbar in #6475🐛 Bug Fixes
-lockfile=readonlyby @yhakbar in #6358--filter-allow-destroywith graph + Git expression combo by @yhakbar in #6322find/listby @yhakbar in #6362terraform_binaryfrom being ignored inrun --allby @yhakbar in #6460stack generateby @yhakbar in #6470run --allwith graph expression throwing on missing working dir by @yhakbar in #6474📖 Documentation
version-attributeexperiment by @yhakbar in #6476🧹 Chores
versionattribute experiment by @yhakbar in #6463sourcefromversionattribute error by @yhakbar in #6480📝 Other Changes
v1.1.0Compare Source
✨ New Features
Stack dependencies
A stack generates a tree of units from a single
terragrunt.stack.hclfile. Wiring one of those units to another used to mean definConfiguration
📅 Schedule: (in timezone Europe/Oslo)
* * * * 1-5)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
ℹ️ Renovate runs on an hourly schedule, but you can manually trigger an immediate run by starting 👉 this workflow 👈