input/default | warning | cluster, machine, machinepool | a contract input the controller always sets to a non-null value nonetheless carries a default, which would mask a controller mistake. |
input/required | error | cluster, machine, machinepool | a contract input is not declared as a variable. |
input/reserved | error | cluster, machine, machinepool | a variable uses the reserved captf_ prefix but is not itself a contract input. |
input/sensitive | warning | cluster, machine, machinepool | bootstrap_data is declared but not sensitive = true, though it carries the bootstrap payload. |
input/tags-declared | error | cluster, machine, machinepool | the module does not declare captf_tags, the mandatory common input every module must accept. |
input/tags-unused | warning | cluster, machine, machinepool | captf_tags is declared but never referenced, directly or forwarded into a nested local module that references it. |
input/type | error | cluster, machine, machinepool | a contract input’s declared type does not accept what the generated root passes, is missing, or could not be read. |
input/user-variable-default | warning | cluster, machine, machinepool | a variable outside the contract (a user variable) has no default, so an object that does not set it in spec.variables or variablesFrom fails to apply. |
module/backend | error | cluster, machine, machinepool | the root or a nested module declares a terraform { backend } block; the generated root owns the backend. |
module/cloud | error | cluster, machine, machinepool | the root or a nested module declares a terraform { cloud } block; the generated root owns it, the same as module/backend. |
module/provider-config | warning | cluster, machine, machinepool | the root or a nested module declares its own provider configuration; the generated root owns provider configuration. |
module/tofu-shadow | warning | cluster, machine, machinepool | a .tofu file shadows a .tf file, and the declarations OpenTofu loads from it differ from Terraform’s. |
module/version | info | cluster, machine, machinepool | informational; reports the module’s declared required_version constraint, or its absence. |
output/endpoint-never-set | warning | cluster | the control_plane_endpoint output is a literal null, so a KubeadmControlPlane cluster with no user-set endpoint would wait forever. |
output/health | error | cluster, machine, machinepool | the health output is declared with the wrong shape for the contract’s health check. |
output/provider-id-list-shape | error (the output is missing or not a list), warning (the expression is not sorted and deduplicated) | machinepool | the machinepool role’s provider_id_list output is missing, or its expression does not look like it forwards one ID per instance. |
output/required | error | cluster, machine, machinepool | a contract output is not declared. |
output/reserved | warning | cluster, machine, machinepool | an output uses a name reserved for a future contract output. |
pool/autoscaling-ignore-changes | warning | machinepool | the module uses var.autoscaling but no resource ignores changes to its desired capacity, so every apply resets the cloud autoscaler’s decision. |