sarj-iac-lint
Custom Terraform / IaC lint rules — stdlib only, line/block based, pre-commit-friendly. Mined from recurring infra review comments across the org.
uv tool install sarj-iac-lint
Rules
| Code | Rule | What it flags |
|---|---|---|
| SARJ201 | require-deletion-protection |
A stateful resource (Cloud SQL, GKE, BigQuery, Spanner, AlloyDB, Bigtable, RDS, DynamoDB, ElastiCache, DocumentDB, Neptune, Azure databases, Cosmos DB, ...) without deletion_protection = true. |
| SARJ202 | no-comment-cruft |
Commented-out Terraform/HCL and section-banner / divider comments. |
| SARJ203 | require-prevent-destroy-on-irreplaceable |
A bucket, Secret Manager secret, or artifact registry — which expose no deletion_protection argument at all — without lifecycle { prevent_destroy = true }. |
Terraform safety rules scan .tf files; comment hygiene also scans .hcl and .tfvars. .yaml/.yml
(Helm/k8s/Compose) are scanned by no-comment-cruft for banners only.
Pre-commit
- repo: https://github.com/sarj-ai/standards
rev: iac-v0.6.0
hooks:
- id: sarj-require-deletion-protection
- id: sarj-no-comment-cruft-iac
- id: sarj-require-prevent-destroy-on-irreplaceable
CLI
sarj-iac-lint check --rule require-deletion-protection iac/
sarj-iac-lint list-rules
Diagnostic format is path:line:col: CODE message — Ruff-compatible.
--exit-zero reports without failing (warn mode).
Adoption
All four rules are designed for hard (blocking) adoption; inspect existing findings before enabling them repository-wide.
Variable/expression-gated protection is not proof of protection:
deletion_protection must be a literal
true, or lifecycle { prevent_destroy = true } must be present. Protection
must sit on the resource itself: a flag nested in settings { ... } is the
API-side switch and does not stop terraform destroy.
require-prevent-destroy-on-irreplaceable covers the stores SARJ201 cannot,
because they have no protection argument to check. It exempts only resources
explicitly declared disposable with literal force_destroy = true.
Suppression
Inline # sarj-noqa: SARJ201 — <reason> on the reported line. SARJ201 and
SARJ203 report the resource line.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distributions
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file sarj_iac_lint-0.6.0-py3-none-any.whl.
File metadata
- Download URL: sarj_iac_lint-0.6.0-py3-none-any.whl
- Upload date:
- Size: 16.3 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/7.0.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
917c498653b3ab6ccc6dd7937cc8dc40971f4e5e66a517271f9d53f886fb4d1e
|
|
| MD5 |
08d0882d0cbc0ca28c1f2810d46f2d1a
|
|
| BLAKE2b-256 |
6837db172c52ea1543a385ae4d30e6d0805ec3e305ac3d878a70062bc516118a
|
Provenance
The following attestation bundles were made for sarj_iac_lint-0.6.0-py3-none-any.whl:
Publisher:
release.yml on sarj-ai/standards
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
sarj_iac_lint-0.6.0-py3-none-any.whl -
Subject digest:
917c498653b3ab6ccc6dd7937cc8dc40971f4e5e66a517271f9d53f886fb4d1e - Sigstore transparency entry: 2353709088
- Sigstore integration time:
-
Permalink:
sarj-ai/standards@ac9c23767226a954da1c1c5e5a5d8de23d665833 -
Branch / Tag:
refs/heads/main - Owner: https://github.com/sarj-ai
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@ac9c23767226a954da1c1c5e5a5d8de23d665833 -
Trigger Event:
push
-
Statement type: