Skip to content

GitHub Action linting Terraform files

Actions

About

GitHub Action that will run TFlint on Terraform files
v1.0.5
Latest
StarΒ (18)

πŸš€ GitHub Action linting Terraform files

GitHub Action that will run TFlint on Terraform files.

πŸ“¦ Available on

✨ Features

  • Main use will be everywhere where Terraform is used and is great for statically or actively checking modules' sources.
  • Using wata727's TFLint.

πŸ“Š Badges

GitHub repo GitHub last commit GitHub code size in bytes GitHub license
DockerHub Docker version Image size Docker Pulls

🏷️ Version Tags: vX, vX.Y, vX.Y.Z

This action supports three tag levels for flexible versioning:

  • vX: latest patch of the major version (e.g., v1).
  • vX.Y: latest patch of the minor version (e.g., v1.2).
  • vX.Y.Z: fixed to a specific release (e.g., v1.2.3).

πŸ“– API Reference

    - name: Run the Action
      uses: devops-infra/action-tflint@v1.0.5
      with:
        dir_filter: modules

πŸ”§ Input Parameters

Input Variable Required Default Description
dir_filter No * Prefixes or sub-directories to search for Terraform modules. Use comma as separator.
fail_on_changes No true Whether TFLint should fail whole action.
tflint_config No .tflint.hcl Location from repository root to TFLint config file. Disables tflint_params.
tflint_params No `` Parameters passed to TFLint binary. See TFLint for details.
run_init No true Whether the action should run terraform init. Defaults to true.

πŸ’» Usage Examples

πŸ“ Basic Example

By default fail if lint errors found in any subdirectory. Run the Action via GitHub.

name: Check TFLint
on:
  push:
    branches:
      - "**"
jobs:
  format-hcl:
    runs-on: ubuntu-latest
    steps:
    - name: Checkout
      uses: actions/checkout@v6

    - name: Check linting of Terraform files
      uses: devops-infra/action-tflint@v1.0.5

πŸ”€ Advanced Example

Use different location for TFLint config file and parse only aws* and gcp* modules in modules/ directory. Run the Action via GitHub.

name: Check TFLint with custom config
on:
  push:
    branches:
      - "**"
jobs:
  format-hcl:
    runs-on: ubuntu-latest
    steps:
    - name: Checkout
      uses: actions/checkout@v6

    - name: Check linting of Terraform modules
      uses: devops-infra/action-tflint@v1.0.5
      with:
        tflint_config: modules/.tflint.hcl
        dir_filter: modules/aws,modules/gcp

πŸ”€ Advanced Example

Use deep check (need cloud credentials) and treat all directories under modules as Terraform modules. Run the Action via DockerHub.

name: Check TFLint with custom config
on:
  push:
    branches:
      - "**"
jobs:
  format-hcl:
    runs-on: ubuntu-latest
    steps:
    - name: Checkout
      uses: actions/checkout@v6

    - name: Check linting of Terraform modules
      uses: devops-infra/action-tflint@v1.0.5
      with:
        tflint_params: "--module --deep"
        dir_filter: modules

🎯 Use specific version

Pick the tag level based on your stability needs:

  • vX.Y.Z: exact immutable release (most predictable)
  • vX.Y: latest patch within one minor line
  • vX: latest patch within one major line
name: Use pinned action version
on: [push]
jobs:
  tflint:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v6

      - uses: devops-infra/action-tflint@v1.0.5
        id: pin-patch

      - uses: devops-infra/action-tflint@v1.0
        id: pin-minor

      - uses: devops-infra/action-tflint@v1
        id: pin-major

🀝 Contributing

Contributions are welcome! See CONTRIBUTING. This project is licensed under the MIT License - see the LICENSE file for details.

πŸ“„ License

This project is licensed under the MIT License - see the LICENSE file for details.

πŸ’¬ Support

If you have any questions or need help, please:

  • πŸ“ Create an issue
  • 🌟 Star this repository if you find it useful!

πŸ§ͺ End-to-End Validation

Use the manual workflow .github/workflows/manual-e2e-validate.yml to validate this action against the centralized E2E repository.

  • mode=image validates a published image tag (recommended for -test and -rc release checks).
  • mode=ref validates ref-oriented E2E paths against stable pinned action refs.

CI/CD automation also runs these E2E checks automatically:

  • Pull requests: E2E validation runs through reusable org workflows.
  • Release branch prepare: E2E validation runs against release candidate artifacts (-rc).
  • Release create: E2E validation runs against production release artifacts.

Example trigger inputs:

mode=ref
mode=image
image_tag=v1.2.3-test

Forking

To publish images from a fork, set these variables so Task uses your registry identities: DOCKER_USERNAME, DOCKER_ORG_NAME, GITHUB_USERNAME, GITHUB_ORG_NAME.

Two supported options (environment variables take precedence over .env):

# .env (local only, not committed)
DOCKER_USERNAME=your-dockerhub-user
DOCKER_ORG_NAME=your-dockerhub-org
GITHUB_USERNAME=your-github-user
GITHUB_ORG_NAME=your-github-org
# Shell override
DOCKER_USERNAME=your-dockerhub-user \
DOCKER_ORG_NAME=your-dockerhub-org \
GITHUB_USERNAME=your-github-user \
GITHUB_ORG_NAME=your-github-org \
task docker:build

Recommended setup:

  • Local development: use a .env file.
  • GitHub Actions: set repo variables for the four values above, and secrets for DOCKER_TOKEN and GITHUB_TOKEN.

Publish images without a release:

  • Run the (Manual) Release Create workflow with build_only: true to build and push images without tagging a release.

GitHub Action linting Terraform files is not certified by GitHub. It is provided by a third-party and is governed by separate terms of service, privacy policy, and support documentation.

About

GitHub Action that will run TFlint on Terraform files
v1.0.5
Latest

GitHub Action linting Terraform files is not certified by GitHub. It is provided by a third-party and is governed by separate terms of service, privacy policy, and support documentation.