Skip to content

Feature/enforced provisioner#13591

Draft
hariom-hashicorp wants to merge 8 commits intomainfrom
feature/enforcedProvisioner
Draft

Feature/enforced provisioner#13591
hariom-hashicorp wants to merge 8 commits intomainfrom
feature/enforcedProvisioner

Conversation

@hariom-hashicorp
Copy link
Copy Markdown

@hariom-hashicorp hariom-hashicorp commented Mar 31, 2026

Add HCP enforced provisioners to local Packer builds: fetch enforced blocks from HCP and inject their provisioners into matching builds.

Why
Ensure baseline security/compliance provisioning is applied consistently without relying on template authors.

What changed

Fetch and parse enforced blocks during build
Inject provisioners respecting only/except
Clear errors for invalid block content
--skip-enforcement to bypass injection
Impact
No change when no enforced blocks exist; otherwise enforced provisioners apply automatically unless skipped.


Description

What code changed, and why?

Resolved Issues

If your PR resolves any open issue(s), please indicate them like this so they
will be closed when your PR is merged:
Closes #xxx
Closes #xxx

Rollback Plan

If a change needs to be reverted, we will roll out an update to the code within
7 days.

Changes to Security Controls

Are there any changes to security controls (access controls, encryption, logging)
in this pull request? If so, explain.

Madhav008 and others added 8 commits March 11, 2026 11:50
- Updated ParseProvisionerBlocks to handle both HCL and JSON syntax, including legacy JSON format.

- Added comprehensive test cases for JSON provisioner parsing.

- Improved ExtractBuildProvisionerHCL to merge inline commands from shell provisioners.

- Enhanced logging for enforced block operations in HCP Packer.
- Update error handling in FetchEnforcedBlocks to return detailed errors instead of warnings.
- Modify GetCoreBuildProvisionerFromBlock to accept build name for overrides.
- Add tests for FetchEnforcedBlocks to ensure correct behavior and error handling.
- Implement diagnostics for unsupported legacy JSON templates.
- Introduced a new package `enforcedparser` to handle parsing of enforced provisioner blocks from HCL and JSON formats.

- Refactored existing code to utilize the new `ParseProvisionerBlocks` function from the `enforcedparser` package.

- Updated `GetCoreBuildProvisionerFromEnforcedBlock` method to convert enforced provisioner blocks into core build provisioners.

- Enhanced error handling and logging during the parsing process.

- Added tests for the new parsing functionality and ensured existing tests were updated to reflect changes.

- Modified `InjectEnforcedProvisioners` method in JSON registry to utilize the new parsing logic.
@hashicorp-cla-app
Copy link
Copy Markdown

CLA assistant check

Thank you for your submission! We require that all contributors sign our Contributor License Agreement ("CLA") before we can accept the contribution. Read and sign the agreement

Learn more about why HashiCorp requires a CLA and what the CLA includes


0 out of 2 committers have signed the CLA.

  • hariom-hashicorp
  • Madhav008

Have you signed the CLA already but the status is still pending? Recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants