v1.2.0 — Terraform lint reusable (tf-lint.yml)
New
tf-lint.yml — reusable Terraform lint gate for the five fleet repos carrying Terraform (solidago, kalmia, claytonia, drosera, .github). Four independently toggleable gates:
terraform fmt -check -recursiveterraform init -backend=false+terraform validate(credential-free by design — safe on fork PRs)tflint --recursivetrivy config(HIGH/CRITICAL IaC misconfigurations; Trivy over Checkov for one-tool fleet consistency with site-deploy.yml)
All inputs optional with defaults (working_directory: terraform, versions latest, all gates on). All third-party actions SHA-pinned. Header carries the required-check rule: no paths: filter on callers that intend to make this required.
Validated per RELEASING.md against a real caller before this tag: kalmia run 32063875705 — all four gates executed and passed against live Terraform.
Semver rationale
Minor: new workflow file, no changes to any existing workflow's caller-facing interface. Existing v1.1.1 callers are unaffected.