hcl_path_matches
Same shape as the *_equals variants, but the asserted value is a regex matched against string values. Non-string matches produce a clear “value is not a string” violation.
Options
Section titled “Options”| Option | Type | Required | Default | Description |
|---|---|---|---|---|
if_present | boolean | false | When true, a query returning zero matches is silently OK - only real matches that fail the op produce violations. | |
matches | string | yes | Rust-regex pattern to match against the value at path. | |
path | string | yes | JSONPath expression rooted at $. |
Plus the common paths, level, id, and when fields. This table is generated from the JSON Schema; option types and defaults are authoritative.
Example
Section titled “Example”A Terraform required_version without a pessimistic constraint
Section titled “A Terraform required_version without a pessimistic constraint”The rule fires on this repository:
main.tfterraform { required_version = "1.0.0"}With this .alint.yml:
version: 1rules: - id: pin-terraform kind: hcl_path_matches paths: "main.tf" path: "$.terraform.required_version" matches: "^~>" level: erroralint check reports:
--- main.tf -------------------------------------------------------------------- x error pin-terraform value at path "1.0.0" does not match regex ^~>
Summary (1 violation): x 1 error 0 passing * 1 failingA Terraform required_version with a pessimistic constraint
Section titled “A Terraform required_version with a pessimistic constraint”This repository is compliant:
main.tfterraform { required_version = "~> 1.0"}With this .alint.yml:
version: 1rules: - id: pin-terraform kind: hcl_path_matches paths: "main.tf" path: "$.terraform.required_version" matches: "^~>" level: erroralint check reports:
v All 1 rule(s) passed.