Terraform AWS docker image with the AWS CLI and tooling for development and CI/CD
7.8K
Welcome to my Terraform AWS Docker repo. This image extends the terraform image with AWS-specific tooling, built with Terraform development and CI/CD in mind. It bundles the AWS CLI and the AWS ruleset for TFLint on top of the base Terraform toolchain. Tool versions are pinned in the Dockerfile and kept current through dependency-update PRs; the image is rebuilt and published to Docker Hub weekly (Mondays) to pick up base-image security patches.
This image builds on hansohn/terraform, which provides:
On top of that base, this image adds:
tflint --init required)# Pull and run the latest version
docker pull hansohn/terraform-aws:latest
docker run -it --rm hansohn/terraform-aws:latest terraform version
# Run with your Terraform code mounted
docker run -it --rm -v $(pwd):/workspace -w /workspace hansohn/terraform-aws:latest terraform plan
Docker images are tagged based on the pinned version of Terraform they include (inherited from the base image). A single Terraform version is published at a time, and it receives the full set of tags below:
# tag formats (for a pinned Terraform version of e.g. 1.15.7)
hansohn/terraform-aws:latest the currently published release
hansohn/terraform-aws:1 the 1.x.x line
hansohn/terraform-aws:1.15 the 1.15.x line
hansohn/terraform-aws:1.15.7 the exact version
For reproducibility, pin by digest (hansohn/terraform-aws@sha256:...); every
image ships provenance attestations and an SBOM bound to that digest.
This image supports multiple platforms:
linux/amd64 (x86_64)linux/arm64 (ARM64/Apple Silicon)Docker will automatically pull the correct architecture for your system.
Published images can be run using the following syntax:
# run latest published version
docker run -it --rm hansohn/terraform-aws:latest /bin/bash
Local images can be built and run using the following syntax:
# build and run local image
make
Additionally, a Makefile has been included in this repo to assist with common development-related functions. I've included the following make targets for convenience:
Available targets:
clean Clean everything
dev Initialize development environment
docker/build Docker build image
docker/check Check if Docker daemon is running
docker/clean Docker clean build images
docker/lint Lint Dockerfile
docker/push Docker push image
docker/run Docker run image
help Help screen
help/all Display help for all targets
help/short This help short screen
docker run -it --rm -v $(pwd):/workspace -w /workspace \
hansohn/terraform-aws:latest terraform init
docker run -it --rm -v $HOME/.aws:/root/.aws \
hansohn/terraform-aws:latest aws sts get-caller-identity
docker run -it --rm -v $(pwd):/src -w /src \
hansohn/terraform-aws:latest tflint
docker run -it --rm -v $(pwd):/docs -w /docs \
hansohn/terraform-aws:latest terraform-docs markdown . > README.md
docker run -it --rm -v $(pwd):/src -w /src \
hansohn/terraform-aws:latest trivy config .
Utility versions are pinned in the Dockerfile and kept current through automated dependency-update PRs. For a local build you can override any of them on the command line to target a specific version:
hansohn/terraform image tag)# build against a specific AWS CLI version
AWSCLI_VERSION=2.35.0 make docker/build
Note: Builds require BuildKit (the default in modern Docker). The Dockerfile uses BuildKit cache mounts, so
DOCKER_BUILDKIT=0is not supported.
Images are automatically:
main (multi-platform, without publishing)main so merged dependency updates and base-image security patches reach Docker Hub — two hours after the hansohn/terraform base image refreshes, so this image picks it up the same morningPushes to main are built for verification but not published. Merged
dependency updates ship on the next weekly refresh, or immediately if you cut
a release tag.
This image is one of a family of infrastructure-tooling images built from
the same Makefile, workflow and Renovate pattern. terraform-docker and
cloudformation-docker each build directly from Debian; the four
cloud-specific Terraform images layer on top of hansohn/terraform.
Contributions are welcome! Please see our Contributing Guide for details.
This project is licensed under the terms specified in LICENSE.
Content type
Image
Digest
sha256:305539f12…
Size
295.6 MB
Last updated
4 days ago
docker pull hansohn/terraform-aws