-
Notifications
You must be signed in to change notification settings - Fork 0
72 lines (61 loc) · 2.23 KB
/
continuous-integration-terraform.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
name: Terraform
on:
push:
branches: main
paths:
- 'terraform/**.tf'
pull_request:
paths:
- 'terraform/**.tf'
jobs:
terraform-validate:
name: Validate
runs-on: ubuntu-latest
steps:
- name: Check out code
uses: actions/checkout@v3
- name: Check for terraform version mismatch
run: |
DOTFILE_VERSION=$(cat terraform/.terraform-version)
TERRAFORM_IMAGE_REFERENCES=$(grep "uses: docker://hashicorp/terraform" .github/workflows/continuous-integration-terraform.yml | grep -v TERRAFORM_IMAGE_REFERENCES | wc -l | tr -d ' ')
if [ "$(grep "docker://hashicorp/terraform:${DOTFILE_VERSION}" .github/workflows/continuous-integration-terraform.yml | wc -l | tr -d ' ')" != "$TERRAFORM_IMAGE_REFERENCES" ]
then
echo -e "\033[1;31mError: terraform version in .terraform-version file does not match docker://hashicorp/terraform versions in .github/workflows/continuous-integration-terraform.yml"
exit 1
fi
- name: Validate Terraform docs
uses: terraform-docs/[email protected]
with:
working-dir: terraform
config-file: .terraform-docs.yml
output-file: README.md
output-method: inject
fail-on-diff: true
- name: Remove azure backend
run: rm ./terraform/backend.tf
- name: Run a Terraform init
uses: docker://hashicorp/terraform:1.5.7
with:
entrypoint: terraform
args: -chdir=terraform init
- name: Run a Terraform validate
uses: docker://hashicorp/terraform:1.5.7
with:
entrypoint: terraform
args: -chdir=terraform validate
- name: Run a Terraform format check
uses: docker://hashicorp/terraform:1.5.7
with:
entrypoint: terraform
args: -chdir=terraform fmt -check=true -diff=true
- name: Setup TFLint
uses: terraform-linters/setup-tflint@v4
with:
tflint_version: v0.44.1
- name: Run TFLint
working-directory: terraform
run: tflint -f compact
- name: Run TFSec
uses: aquasecurity/[email protected]
with:
github_token: ${{ github.token }}