variable "env_name" { type = string } variable "image_refs" { type = map(string) description = "service to image ref suffix (@sha256:digest or :tag); overrides the env default when set" default = {} # infra manager sends an unset input as an explicit null nullable = false validation { condition = alltrue([for ref in values(var.image_refs) : can(regex("^(:[^:@]+|@sha256:[0-9a-f]{64})$", ref))]) error_message = "image_refs values must be a ':tag' or '@sha256:' suffix; leave the map empty to use the env default." } }