Skip to content

v1.2.0 — Terraform lint reusable (tf-lint.yml)

Choose a tag to compare

@cpitzi cpitzi released this 17 Aug 20:06
· 5 commits to main since this release
24c6168

New

tf-lint.yml — reusable Terraform lint gate for the five fleet repos carrying Terraform (solidago, kalmia, claytonia, drosera, .github). Four independently toggleable gates:

  1. terraform fmt -check -recursive
  2. terraform init -backend=false + terraform validate (credential-free by design — safe on fork PRs)
  3. tflint --recursive
  4. trivy config (HIGH/CRITICAL IaC misconfigurations; Trivy over Checkov for one-tool fleet consistency with site-deploy.yml)

All inputs optional with defaults (working_directory: terraform, versions latest, all gates on). All third-party actions SHA-pinned. Header carries the required-check rule: no paths: filter on callers that intend to make this required.

Validated per RELEASING.md against a real caller before this tag: kalmia run 32063875705 — all four gates executed and passed against live Terraform.

Semver rationale

Minor: new workflow file, no changes to any existing workflow's caller-facing interface. Existing v1.1.1 callers are unaffected.

Closes the release phase of #41 (R18). Refs: #50.