variable scanning procedure of tflint

Viewed 164

I'm newbie to tflint and other scanning tools. I'm trying to understand the scanning procedure.

In my example, I have variable.tf file where i'm passing variable names like azure storage account name, account tier etc.

my variable.tf file has which i gave intentionally.

variable "storage_account_name"{
type = string
default = "test-sa-123"


}

and in main.tf, i'm using as var.storage_account_name.

if I do tflint, normally it should throw error as storage account name should not have special characters but it is not throwing any errors.

So I want to understand whether tflint is capable to take that variable from variables.tf file and throw error in main.tf?

I tried checkov also but it is not throwing error for this mistake. Is there any other tool which can scan the variables.tf and throw error in main.tf? Or do we need write our own rule for this in tflint?

thanks, Santosh

1 Answers

Underscores in Terraform variables are valid. Tflint won't identify that as far as I know.

It won't throw an error with this. Even if the variable is passed through to the provider and references a storage account I wouldn't expect that to throw an error.

There are plugins as rulsets like this azure one for tflint which might increase what it catches but I still wouldn't rely on it for this purpose.

The way I'd handle this would be through Terraform variable validation.

The rules around storage accounts seem to be (source):

length: 3-24
type: Lowercase letters and numbers.

To identify that as a regex value you could use: ^[a-z0-9]*$

See tests

Here's a a very rough example:

variable "storage_account_name" {
  type = string

  validation {
    condition = (
      length(var.storage_account_name) > 3 && length(var.storage_account_name) < 25
    )
      error_message = "The storage_account_name value must be between 3 and 24 characters."
  }

  validation {
    condition = (
      regex('/^[a-z0-9]*$/g', var.storage_account_name)
    )
      error_message = "The storage account name must be only lowercase letters and numbers."
  }
}
Related