Sign inSign up

hansohn/cloudformation

By hansohn

•Updated 4 days ago

CloudFormation tooling Docker image — aws-cli, cfn-lint, rain, and cfn-guard (multi-arch).

Image
0

1.8K

hansohn/cloudformation repository overview

⁠cloudformation-docker

CloudFormation tooling Docker image

⁠Description

A small, multi-arch Docker image with the tooling needed to lint, validate, and deploy AWS CloudFormation — the CloudFormation counterpart to terraform-aws⁠. Use it for local development (make dev) and in CI (e.g. the aws-account-bootstrap seed repo).

⁠What's Included

ToolPurpose
AWS CLI v2⁠Deploy stacks/StackSets, validate-template
cfn-lint⁠Lint CloudFormation templates
rain⁠CloudFormation CLI + formatter (rain fmt, rain deploy)
cfn-guard⁠Policy-as-code validation (cfn-guard validate)
git, jq, bash, vimEveryday tooling for scripts and CI

The AWS CLI is PGP-verified against the AWS CLI Team key at build time; the image version tracks the pinned AWS CLI release. cfn-guard is arch-guarded — bundled on amd64/arm64 and skipped on architectures without a published binary so multi-arch builds stay green.

⁠Tags

Image tags follow the pinned AWSCLI_VERSION in the Dockerfile. The other bundled tools (cfn-lint, rain, cfn-guard) are pinned independently, so a bump to one of those does not move the version — it republishes the existing tags with the newer tool inside.

# tag formats (for a pinned AWS CLI version of e.g. 2.36.31)
hansohn/cloudformation:latest    the currently published release
hansohn/cloudformation:2         the 2.x.x line
hansohn/cloudformation:2.36      the 2.36.x line
hansohn/cloudformation:2.36.31   the exact version

For reproducibility, pin by digest (hansohn/cloudformation@sha256:...); every image ships provenance attestations and an SBOM bound to that digest.

⁠Usage

# lint a template
docker run --rm -v "$(pwd)":/w -w /w hansohn/cloudformation:latest \
  cfn-lint templates/*.yaml

# validate against the CloudFormation API (needs creds)
docker run --rm -v "$(pwd)":/w -w /w -v ~/.aws:/root/.aws \
  hansohn/cloudformation:latest \
  aws cloudformation validate-template --template-body file://templates/account-seed.yaml

# interactive shell
docker run -it --rm -v "$(pwd)":/w -w /w hansohn/cloudformation:latest bash

⁠Build

Versions default to the pins in the Dockerfile (managed by Renovate); override on the command line for ad-hoc builds.

make docker/build                       # build for the local platform
make docker/run                         # build then drop into a shell
CFN_LINT_VERSION=1.20.0 make docker/build
DOCKER_PLATFORMS=linux/amd64,linux/arm64 make docker/build

Run make help for all targets.

⁠Publishing

Images are automatically:

  • Built and linted on every push, including main (multi-platform, without publishing)
  • Published when a version tag is pushed
  • Refreshed every Monday at 7am UTC, rebuilding main so merged dependency updates and base-image security patches reach Docker Hub

Pushes to main are built for verification but not published. Merged dependency updates ship on the next weekly refresh, or immediately if you cut a release tag.

⁠Extending

Additional CloudFormation tooling can be layered in the Dockerfile following the same pinned-ARG + Renovate pattern — e.g. cfn-nag⁠ (security linting).

This image is one of a family of infrastructure-tooling images built from the same Makefile, workflow and Renovate pattern. terraform-docker and cloudformation-docker each build directly from Debian; the four cloud-specific Terraform images layer on top of hansohn/terraform.

⁠License

Apache 2.0 — see LICENSE⁠.

Tag summary

Content type

Image

Digest

sha256:563639417…

Size

211.5 MB

Last updated

4 days ago

docker pull hansohn/cloudformation