Skip to content

hcl_path_absent

Assert a JSONPath query over the document matches nothing; one file-level violation if present.

Semantics:

  • The query must select zero nodes. Any match fires exactly one violation for the file — never per-match, so a $[?…] filter that fans out over every top-level key still yields a single violation.
  • The existence sibling of the value-checking kinds; mirrors file_absent for a path. equals / matches / if_present don’t apply.
  • Useful for forbidding a key: a postinstall script in package.json, a [patch] table in Cargo.toml, or write-all permissions in a workflow.
OptionTypeRequiredDefaultDescription
pathstringyesJSONPath expression rooted at $. The rule fires one violation per file if the query matches any node (the path must be absent).

Plus the common paths, level, id, and when fields. This table is generated from the JSON Schema; option types and defaults are authoritative.

A Terraform provider with a hardcoded credential

Section titled “A Terraform provider with a hardcoded credential”

The rule fires on this repository:

main.tf
main.tf
provider "aws" {
region = "us-east-1"
access_key = "AKIAIOSFODNN7EXAMPLE"
}

With this .alint.yml:

version: 1
rules:
- id: no-hardcoded-key
kind: hcl_path_absent
paths: "main.tf"
path: "$.provider.aws.access_key"
level: error
message: >-
A hardcoded access_key is in a .tf file; use a variable or the provider chain.

alint check reports:

Terminal window
--- main.tf --------------------------------------------------------------------
x error no-hardcoded-key
A hardcoded access_key is in a .tf file; use a variable or the
provider chain.
Summary (1 violation):
x 1 error
0 passing * 1 failing

A Terraform provider with no hardcoded credential

Section titled “A Terraform provider with no hardcoded credential”

This repository is compliant:

main.tf
main.tf
provider "aws" {
region = "us-east-1"
}

With this .alint.yml:

version: 1
rules:
- id: no-hardcoded-key
kind: hcl_path_absent
paths: "main.tf"
path: "$.provider.aws.access_key"
level: error

alint check reports:

Terminal window
v All 1 rule(s) passed.