Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
39 changes: 39 additions & 0 deletions .github/actions/terraform.tflint/action.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,14 @@ inputs:
required: false
default: ./
description: "(Optional) The directory to lint. Defaults to `./`."
mode:
required: false
default: module
description: "(Optional) What kind of Terraform directory is being linted. `module` lints the configuration as written. `workspace` lints it as a named Terraform workspace, which is needed when the configuration references `terraform.workspace` (e.g. to locate `<workspace>/config.yaml`) — `tflint` evaluates that expression as `default` unless it is told otherwise. Valid values are `module` or `workspace`. Defaults to `module`."
workspace:
required: false
default: default
description: "(Optional) The Terraform workspace name to lint as, exported as `TF_WORKSPACE`. Only used when `mode` is `workspace`, and an empty value falls back to the default. Defaults to Terraform's `default` workspace."
config_file:
required: false
default: .tflint.hcl
Expand Down Expand Up @@ -61,9 +69,30 @@ runs:
shell: bash
env:
TARGET_DIR: ${{ inputs.target_dir }}
MODE: ${{ inputs.mode }}
WORKSPACE: ${{ inputs.workspace }}
CONFIG_FILE: ${{ inputs.config_file }}
RECURSIVE: ${{ inputs.recursive }}
run: |
# `tflint` reads the configuration and its input variables, but never the state or the backend. The one
# thing it cannot infer is the workspace: `terraform.workspace` evaluates to `default` unless
# `TF_WORKSPACE` is set. Resolving it here keeps every `tflint` call below on the same workspace.
case "$MODE" in
module)
workspace=""
;;
workspace)
# The caller may pass an empty workspace (e.g. a matrix entry for a single-workspace project),
# which the action input default does not cover.
workspace="${WORKSPACE:-default}"
;;
*)
echo "::error::Invalid mode: $MODE. Valid values are module or workspace."
exit 1
;;
esac
echo "workspace=$workspace" >> "$GITHUB_OUTPUT"

# A trailing slash (e.g. `./`) makes `--recursive` silently skip every subdirectory, so strip it.
target_dir="${TARGET_DIR%/}"
target_dir="${target_dir:-.}"
Expand Down Expand Up @@ -132,12 +161,17 @@ runs:
uses: tedilabs/github-actions/.github/actions/shell.run@main
env:
TARGET_DIR: ${{ steps.target.outputs.target_dir }}
WORKSPACE: ${{ steps.target.outputs.workspace }}
CONFIG: ${{ steps.target.outputs.config }}
RECURSIVE: ${{ inputs.recursive }}
MINIMUM_FAILURE_SEVERITY: ${{ inputs.minimum_failure_severity }}
FORMAT: ${{ inputs.format }}
with:
run: |
if [ -n "$WORKSPACE" ]; then
export TF_WORKSPACE="$WORKSPACE"
fi

args=(--chdir "$TARGET_DIR")
if [ -n "$CONFIG" ]; then
args+=(--config "$CONFIG")
Expand All @@ -158,9 +192,14 @@ runs:
shell: bash
env:
TARGET_DIR: ${{ steps.target.outputs.target_dir }}
WORKSPACE: ${{ steps.target.outputs.workspace }}
CONFIG: ${{ steps.target.outputs.config }}
RECURSIVE: ${{ inputs.recursive }}
run: |
if [ -n "$WORKSPACE" ]; then
export TF_WORKSPACE="$WORKSPACE"
fi

args=(--chdir "$TARGET_DIR")
if [ -n "$CONFIG" ]; then
args+=(--config "$CONFIG")
Expand Down
1 change: 1 addition & 0 deletions .github/workflows/terraform.modules.integration.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -188,6 +188,7 @@ jobs:
uses: tedilabs/github-actions/.github/actions/terraform.tflint@main
with:
target_dir: ${{ matrix.path }}
mode: module
config_file: ${{ inputs.tflint_config_file }}
minimum_failure_severity: ${{ inputs.tflint_minimum_failure_severity }}
recursive: ${{ inputs.tflint_recursive }}
Expand Down
2 changes: 2 additions & 0 deletions .github/workflows/terraform.workspaces.integration.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -197,6 +197,8 @@ jobs:
uses: tedilabs/github-actions/.github/actions/terraform.tflint@main
with:
target_dir: ${{ matrix.project }}
mode: workspace
workspace: ${{ matrix.workspace }}
config_file: ${{ inputs.tflint_config_file }}
minimum_failure_severity: ${{ inputs.tflint_minimum_failure_severity }}
recursive: ${{ inputs.tflint_recursive }}
Expand Down
Loading