diff --git a/terraform/README.md b/terraform/README.md index 1c97c9bf..1f436b17 100644 --- a/terraform/README.md +++ b/terraform/README.md @@ -252,6 +252,16 @@ npm run test:infra # CDK build, template tests, synth in both m but never contacts HCP state or plans against AWS. Only HCP runs plan against the account. +The lock file must carry `h1:` hashes for every platform that runs the gate +(CI and HCP are `linux_amd64`, laptops are `darwin_*`). After changing the +provider version, refresh them with: + +```bash +terraform -chdir=terraform/live/dev providers lock \ + -platform=linux_amd64 -platform=linux_arm64 \ + -platform=darwin_amd64 -platform=darwin_arm64 +``` + ## Import plan safety Import mode requires exactly the canonical 13 addresses and AWS types, valid diff --git a/terraform/live/dev/.terraform.lock.hcl b/terraform/live/dev/.terraform.lock.hcl index b3827528..7f171232 100644 --- a/terraform/live/dev/.terraform.lock.hcl +++ b/terraform/live/dev/.terraform.lock.hcl @@ -5,8 +5,11 @@ provider "registry.terraform.io/hashicorp/aws" { version = "6.62.0" constraints = "~> 6.57" hashes = [ + "h1:4qcuRkosNKYxV2y69uJ6zAfTEO1Op04L4KUuWBrUvBo=", "h1:OthB9UeoBgmy348EpDjs5GDGk6p6UxAMQD5cXn7u9Ho=", + "h1:lTKd2c1EunGxt2XROLgEeSXA2Jk+WiiG9BTcp+L/0xY=", "h1:nWSI/kgPk9aieiY01TEKOGXRX3+L889GSkEq0SMCL6E=", + "h1:yOSEz5G8b/n5uhFCZ0gbEsKkAQATtVuhXJEXR3OM5qs=", "zh:35a9e4bc6fd622c5a99561b882025f2745f1256bbf1a8da8d6b39319b75ae0b5", "zh:405927d470ff16201e40aa0fa2d0ab1de477360a0926d20719cd029179682ecd", "zh:4ab7866593a90bcf18f066b0092a209b9f42852acd783b504031ae74cb6f7010",