CloudFormation tooling Docker image — aws-cli, cfn-lint, rain, and cfn-guard (multi-arch).
1.8K
A small, multi-arch Docker image with the tooling needed to lint, validate, and
deploy AWS CloudFormation — the CloudFormation counterpart to
terraform-aws. Use it for local development (make dev) and
in CI (e.g. the aws-account-bootstrap seed repo).
| Tool | Purpose |
|---|---|
| AWS CLI v2 | Deploy stacks/StackSets, validate-template |
| cfn-lint | Lint CloudFormation templates |
| rain | CloudFormation CLI + formatter (rain fmt, rain deploy) |
| cfn-guard | Policy-as-code validation (cfn-guard validate) |
git, jq, bash, vim | Everyday tooling for scripts and CI |
The AWS CLI is PGP-verified against the AWS CLI Team key at build time; the
image version tracks the pinned AWS CLI release. cfn-guard is arch-guarded —
bundled on amd64/arm64 and skipped on architectures without a published
binary so multi-arch builds stay green.
Image tags follow the pinned AWSCLI_VERSION in the Dockerfile. The other
bundled tools (cfn-lint, rain, cfn-guard) are pinned independently, so a
bump to one of those does not move the version — it republishes the existing
tags with the newer tool inside.
# tag formats (for a pinned AWS CLI version of e.g. 2.36.31)
hansohn/cloudformation:latest the currently published release
hansohn/cloudformation:2 the 2.x.x line
hansohn/cloudformation:2.36 the 2.36.x line
hansohn/cloudformation:2.36.31 the exact version
For reproducibility, pin by digest (hansohn/cloudformation@sha256:...); every
image ships provenance attestations and an SBOM bound to that digest.
# lint a template
docker run --rm -v "$(pwd)":/w -w /w hansohn/cloudformation:latest \
cfn-lint templates/*.yaml
# validate against the CloudFormation API (needs creds)
docker run --rm -v "$(pwd)":/w -w /w -v ~/.aws:/root/.aws \
hansohn/cloudformation:latest \
aws cloudformation validate-template --template-body file://templates/account-seed.yaml
# interactive shell
docker run -it --rm -v "$(pwd)":/w -w /w hansohn/cloudformation:latest bash
Versions default to the pins in the Dockerfile (managed by Renovate); override
on the command line for ad-hoc builds.
make docker/build # build for the local platform
make docker/run # build then drop into a shell
CFN_LINT_VERSION=1.20.0 make docker/build
DOCKER_PLATFORMS=linux/amd64,linux/arm64 make docker/build
Run make help for all targets.
Images are automatically:
main (multi-platform, without publishing)main so merged dependency updates and base-image security patches reach Docker HubPushes to main are built for verification but not published. Merged
dependency updates ship on the next weekly refresh, or immediately if you cut
a release tag.
Additional CloudFormation tooling can be layered in the Dockerfile following
the same pinned-ARG + Renovate pattern — e.g. cfn-nag (security
linting).
This image is one of a family of infrastructure-tooling images built from
the same Makefile, workflow and Renovate pattern. terraform-docker and
cloudformation-docker each build directly from Debian; the four
cloud-specific Terraform images layer on top of hansohn/terraform.
Apache 2.0 — see LICENSE.
Content type
Image
Digest
sha256:563639417…
Size
211.5 MB
Last updated
4 days ago
docker pull hansohn/cloudformation